- Location
- Austin, TX, TX
- Workplace
- Onsite
- Type
- Full-time
- Department
- IT
- Seniority
- Director
- Closing date
- Today
- Source
- ApplyToJob
Description
About Removery
Join us at Removery - the global leader in laser tattoo removal. We aim to normalize tattoo removal and empower people to feel comfortable in their skin. We provide the highest quality of service and care at every stage of our clients’ removal or fading journeys.
Removery was formed in 2019 through a merge of the four leading tattoo removal brands. Now, with more than 150 studios located in the United States, Canada, and Australia, and over 2 million successful treatments to date – we’ve raised the standard for the entire industry.
Using best-in-class innovative PicoWay® laser technology, we ensure safe and effective tattoo removal. The foundation is in place continue growing globally, as we are committed to making tattoo removal safe and accessible to as many people as we can.
Position Overview
We are seeking a Director of Infrastructure & Security to own our cloud infrastructure, security program, and disaster recovery planning end to end. This is a hands-on director role for someone who can set strategy and own a budget, but is just as comfortable being in the portal, in the terminal, and — when it counts — in the code.
We run a lean, modern technology organization supporting a growing, multi-site business. Our cloud estate, our corporate offices, and every one of our locations depend on infrastructure that is fast, available, and defensible. You will be the person who can say, with evidence, “here is our risk posture, here is what we are doing about it, and here is how long it would take us to recover.”
You will lead a dedicated, long-tenured nearshore pod rather than a rotating bench — real leadership without a large org chart, where your judgment is spent on architecture, risk, and sequencing rather than managing layers.
Key Responsibilities
Cloud Infrastructure
Own the architecture, cost, performance, and reliability of our cloud estate — primarily Azure, Entra ID, Microsoft 365, and Intune, with workloads and vendor dependencies touching AWS and GCP.
Drive infrastructure-as-code and repeatable deployments, reducing the number of things that exist only because someone clicked a button once.
Own cloud cost management: visibility, accountability by workload, and a credible plan to bend the curve.
Set the standards for networking, identity, secrets management, and environment separation.
Security
Own the security program across identity, endpoint, network, application, and data — for cloud workloads and for our physical office and site environments: segmentation, wireless, physical access systems, on-site hardware.
Run vulnerability and patch management, endpoint protection, email security, logging and SIEM, and alert triage through to closure.
Own third-party and vendor risk review, including inbound security questionnaires and partner security reviews.
Build and maintain the policy set — access control, acceptable use, data handling, incident response — and make it something people actually follow.
Lead security awareness: phishing simulation, onboarding and offboarding controls, and least-privilege enforcement that survives contact with real work.
Map our controls to the data protection obligations that apply to us — PII, PHI, and state and international privacy regimes — and close the gaps.
Disaster Recovery and Resilience
Own business continuity and disaster recovery planning. Define RTO and RPO per system with the business, then design to those numbers.
Test it: backup restores, failover drills, and tabletop exercises on a published cadence — not a binder nobody has opened.
Own incident response end to end: detection, escalation, communication to leadership, and blameless post-incident review.
Hands-On Engineering
Read and write code. When production is degraded and the application team is stretched or asleep, be comfortable opening the repository, getting oriented quickly with AI coding tools (we use Claude Code), and shipping either a safe fix or a credible mitigation.
Automate your own work: scripting, pipelines, runbooks as code, and monitoring you built and understand rather than monitoring you bought and forgot.
Working Across the Organization
Partner closely with the IT & Helpdesk Director on identity, endpoint, and site-standard decisions, so that what we secure centrally is what people actually experience day to day.
Partner with Engineering and Product on secure delivery, environment strategy, and production readiness.
Manage vendors, MSPs, contracts, and renewals. Own your budget and defend it with data.
Translate risk for a non-technical audience, including the executive team.
Position Requirements:
Ability to work in office 4+ days a week, in Austin, TX.
8+ years in infrastructure, cloud, and/or security engineering, including 3+ years leading a team, a program, or a function.
Deep Microsoft cloud experience: Azure IaaS and PaaS, Entra ID (conditional access, PIM), Microsoft 365 security, Intune and endpoint management, the Defender suite.
Real, current security discipline — you have owned an actual program, not just implemented someone else's checklist. Identity-first thinking.
You have written and tested a disaster recovery plan, and can speak to what broke the first time you tested it.
Working proficiency in at least one scripting or programming language (PowerShell, Python, TypeScript, Go, C#) plus infrastructure-as-code (Terraform, Bicep, or ARM).
Comfort securing physical environments, not only cloud ones: office networking, wireless, and on-site systems across multiple locations.
Clear writing. You can produce a one-page risk summary an executive will actually read.
Experience leading distributed or nearshore teams — setting standards and reviewing work across time zones without becoming the bottleneck yourself.
Good judgment about pace. You will find things that should have been fixed years ago; we need someone who sequences the work rather than alarming everyone.
Preferred Experience:
Hands-on AWS and/or GCP experience — we have real workloads and vendor dependencies there and expect that to grow.
Experience in a multi-site retail, clinical, or consumer services business.
HIPAA, PCI, or SOC 2 audit experience from the inside of the company being audited.
Certifications such as CISSP, CISM, AZ-500, SC-100, or an AWS/GCP security specialty — useful signal, not a substitute for the work.
Experience introducing AI development tooling to a small team.
You will be part of a supportive and close-knit team and given the opportunity to perform purposeful work. Removery is proud to offer a competitive salary, based upon experience, in tandem with a competitive benefits package for FT associates including:
Comprehensive Medical, Dental, and Vision with HRA option, STD and LTD
50K in Life Insurance, at no cost to you! Plus, the option to purchase more.
Flexible Paid Time Off
Paid Parental Leave
Eight (8) company paid holidays
8 hours of paid volunteer time per year
401K with generous Company Match
Team Member Referral Bonus Program
Employee Assistance Program
Collaborative work environment with an amazing culture committed to diversity and inclusion.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Other duties may be assigned.
We are deeply committed to attracting talented team members from all backgrounds regardless of race, age, gender, ethnicity, religion, sexual orientation, disability status, or nationality. However, currently, we are not sponsoring any Visas.
Equal Opportunity Employer
https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf
https://www.e-verify.gov/sites/default/files/everify/posters/IER_RightToWorkPoster%20Eng_Es.pdf