DEPARTMENT
Information Security / Information Technology
REPORTS TO
Chief Technology Officer
FLSA STATUS
Exempt
EMPLOYMENT TYPE
Full-Time
WORK MODEL
Hybrid/Remote
LOCATION
Remote — must reside in FL, GA, or TX. Candidates local to the Tampa Bay area may be required to work onsite occasionally.
TRAVEL REQUIREMENT
Up to 10%
EDUCATION
Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent professional experience.
ABOUT SIGHTVIEW
Sightview Software LLC provides a suite of industry-leading software specifically geared toward ophthalmology and optometry practices — practice management, surgical, revenue cycle management (RCM), MIPS reporting, and more. Sightview is a one-stop shop for eye care specialists and their patients.
Integrity • Collaboration • Accountability • Resilience • Engagement
JOB SUMMARY
The VP, Information Security & IT Operations is the single accountable executive for Sightview's corporate technology infrastructure and its enterprise information security and privacy program. This role owns two interconnected mandates: (1) ensuring Sightview's internal IT systems, infrastructure, and operations run reliably, securely, and cost-effectively to support the business day-to-day, and (2) building, leading, and continuously maturing the company's cybersecurity, risk, and privacy program to protect the organization, its customers, and its data. The VP owns the security and privacy program, supported by a GRC Manager and Security Team Leads, and partners closely with DevOps, Engineering, and Product to embed security into how Sightview builds and operates.
ESSENTIAL DUTIES & RESPONSIBILITIES
- Corporate IT Operations & Infrastructure Leadership – 30%
- Lead day-to-day corporate IT discussions, priorities, and decision-making across infrastructure, end-user computing, and business systems.
- Own IT project plans and roadmaps, ensuring initiatives are scoped, resourced, sequenced, and delivered on schedule.
- Serve as the escalation point and approver for IT systems changes, purchase requests, and operational expenses.
- Oversee corporate network, systems, and infrastructure operations to ensure reliability, availability, and performance at an optimal level.
- Manage the IT budget: forecasting, vendor contracts, licensing, and expense approvals, ensuring cost-effective use of resources.
- Partner with department leaders across the business to translate operational needs into IT solutions and support requests.
- Evaluate, select, and manage relationships with IT vendors, managed service providers, and technology partners.
- Information Security & Privacy Program Leadership – 60%
- Own the enterprise cybersecurity program end-to-end, acting as the accountable owner of security and privacy outcomes, supported by the GRC Manager and Security Team Leads.
- Lead Sightview's SOC 2 Type II and HITRUST programs, including audit readiness, evidence collection, control testing, gap remediation, and ongoing certification maintenance.
- Develop, maintain, and continuously improve security policies, processes, and standard operating procedures (SOPs) aligned to industry frameworks (e.g., NIST, ISO 27001, HITRUST CSF).
- Collaborate cross-functionally with DevOps and Engineering/Development teams to embed secure-by-design principles, secure SDLC practices, and security tooling into the development and deployment pipeline.
- Own the enterprise risk management program: identify, assess, prioritize, track, and report on security and privacy risks to leadership.
- Lead the third-party and vendor security risk assessment program, ensuring vendors and partners meet Sightview's security and privacy requirements before and during engagement.
- Own budget decisions for security and privacy application/tooling services (e.g., SIEM, vulnerability management, WAF, endpoint/cloud security tooling, GRC platforms), prioritizing spend against risk and program maturity goals.
- Operate comfortably within Sightview's AWS infrastructure with deep, hands-on-level familiarity — reviewing CloudTrail logs, firewall rules, and WAF configurations, and asking the right technical questions of engineering/DevOps to confirm infrastructure integrity is maintained.
- Ensure security operation