Hiring.Camp

Head of Security & Infrastructure

Parker Bridge

·

Today

Workplace
Hybrid
Type
Full-time
Department
IT
Experience
3+ years
Closing date
Today
Source
Vincere

Description

Microsoft Word - HoSI-PD

Head of Security and Infrastructure

Job Details

Location Role type Work model Reports to Direct reports

Auckland Permanent, full-time Hybrid Chief Product and Technology Officer Yes

Last updated July 2026 SECURITY IS THE FOUNDATION OF HEALTHCARE TRUST. Medtech Global has spent 30 years building technology that supports clinicians across New Zealand and Australia. We have deep institutional knowledge of how healthcare actually works, and a clear-eyed view of where it needs to go. When a patient shares their health history with a clinician, they are sharing some of the most personal information about their life. They assume that it is stored securely. At Medtech, that assumption falls on us. Our software sits at the centre of clinical workflows across New Zealand and Australia. The data we handle belongs to real patients, and the clinicians relying on it are making real decisions. We are building what comes next, without stopping what works today. Security underpins both, and this role owns it - together with the infrastructure our products run on, the internal IT systems and helpdesk that keep Medtech itself running, and our privacy obligations as guardians of patient data. WHY THIS ROLE EXISTS Health systems trust us with data that is deeply personal and clinically critical. That trust has to be earned continuously, and it can be lost in a single incident. The Head of Security and Infrastructure at Medtech is the person who ensures it never is. This role sits at the intersection of technology, clinical trust, and commercial credibility. Security done well here does not just reduce risk, it opens doors. It is what allows us to enter new markets, win enterprise contracts, and keep building software that healthcare professionals can depend on. The role reports to the CPTO with a direct escalation path to the CEO on security and privacy matters - cyber risk is a standing item on the executive agenda, and the Privacy Officer's regulatory obligations are never subordinate to internal reporting lines.

- 2 -

WHY THIS IS WORTH DOING

This won't be easy. Healthcare is complex, regulated, and high-stakes. The legacy is real and the transformation ahead is significant. But the people using our software are clinicians doing their best work for patients, and the technology they work with shapes what that looks like every day.

The Head of Security and Infrastructure will help define the security, infrastructure and IT for Medtech. It is a rare opportunity. We are looking for someone who sees that clearly and wants to be part of making it real.

WHAT THIS ROLE DOES

Build and own the security programme

- Own Medtech's security posture across all products and cloud environments, from risk assessment through to driving and verifying remediation with engineering teams

- Lead the ISO 27001 / HISO 10029 programme, including scoping, gap analysis, controls implementation, and audit readiness

- Build and own the Business Continuity and Incident Response programme

- Govern vendor and third-party security obligations - access controls, cloud provider agreements, and managed security services across all third parties, including partners with access to our environments

Own the compliance programme and serve as Privacy Officer

- Lead Medtech's regulatory compliance obligations: NZ Privacy Act 2020, Health Information Privacy Code (HIPC), Australian Privacy Act, and HISO 10029 with Privacy by Design embedded from day one

- Own data sovereignty obligations across NZ and AU environments, so that patient data stays where it belongs

- Represent security and privacy in product and architecture decisions, so that new products are secure from day one, not retrofitted

- Act as Medtech's designated Privacy Officer under the NZ Privacy Act 2020 — the named point of accountability for privacy across the business

- Own the relationship with privacy regulators - the Office of the Privacy Commissioner (NZ) and the OAIC (AU) - including breach assessment and notification under both notifiable-breach regimes

- Handle privacy complaints and personal-information access and correction requests, with documented processes and timeframes

- Establish privacy impact assessments as standard practice for new products, integrations, and data flows

Embed security into how we build

- 3 -

- Shift security left into engineering practice, help with standards, tooling, and culture that make security a shared responsibility across the product and engineering organisation

- Establish a security awareness and education programme across the business, making security everyone's responsibility, with the Head of Security and Infrastructure as the standard- setter

Own the infrastructure and hosting estate

- Own the cloud hosting environments our products and customers depend on - private and public cloud, across New Zealand and Australia

- Own disaster recovery and business continuity infrastructure - architecture documented, recovery tested end-to-end, and no single person or vendor as a point of failure

- Own and govern the hosting and managed-service vendor relationships - contracts, SLAs, security obligations, performance, and genuine redundancy between providers

- Lead the internal infrastructure team and direct the managed-service partners that extend it

Lead the internal IT function

- Own and run the IT function - the tools and systems that the business depends on every day

- Lead and develop the IT team - setting direction, managing performance, and growing capability

- Own IT procurement and vendor management - selecting and managing the tools and services that keep the organisation running securely and efficiently

- Ensure IT practices meet security standards, like access management, device policies, and tooling aligned with the organisation's security posture from the ground up

- Partner with the business to understand what they need from IT and deliver it reliably

- Build the relationship with engineering, product, and executive teams so security is an enabler, not a blocker

HOW YOU WILL WORK

This is a player-coach role. You will be doing as much as directing: conducting risk assessments, writing policies, coordinating penetration testing, reviewing vendor contracts and getting into the detail of DR runbooks and hosting architecture. The credibility of this role is built in the work, not the title.

Work backwards from outcomes. Security decisions should be anchored to what they protect, what they enable, and what it costs to get them wrong. The Head of Security and Infrastructure at Medtech is not a gatekeeper, they are a strategic partner who understands the commercial and clinical stakes equally.

Be a multiplier. You will build a team, but your leverage is the security culture you embed across the whole organisation. Engineers who think about security, product managers who design it in from the start, executives who understand the risk landscape - that is the real outcome of this role.

- 4 -

Be commercially aware. Security at Medtech is a competitive differentiator. Enterprise buyers evaluate our security posture before signing. Health system contracts require demonstrable compliance. You understand this and can speak to it in the boardroom, in a sales conversation, and in a contract review.

Be AI-native. Security is changing as fast as the technology it protects. We expect you to stay at the frontier, understanding how AI changes the threat landscape, how it can accelerate security operations, and how to govern AI systems in a regulated healthcare environment.

Be visionary when needed, pragmatic always. A strong security posture is built incrementally, not in a single transformation. Set the long-term direction clearly, then make the small, deliberate improvements that compound over time. Progress is made in well-designed iterative steps.

Diagnose before you solve. Our security landscape has complexity built up over decades. Before reaching for solutions, understand the system. Root causes matter more than symptoms. First principles matter more than checklists.

WHAT SUCCESS LOOKS LIKE AT 12 MONTHS

Working backwards from where we need to be:

- ISO 27001 programme scoped and in progress, with gap analysis complete, controls roadmap agreed, certification timeline defined

- BCP/IRP operational - documented, tested, and owned

- Security standards embedded in the SDLC - engineers have guardrails to rely on, not guesswork

- Regulatory compliance posture documented and managed - NZ Privacy Act 2020, Australian Privacy Act, Health Information Privacy Code (HIPC), and HISO 10029 obligations mapped and addressed

- Vendor and third-party security obligations governed, with access controls in place and auditable

- The enterprise security risk register is actively managed, with critical risks materially reduced and progress visible to the executive and board

- A security roadmap the CPTO and executive team can present to enterprise clients and health system partners with confidence

- Disaster recovery proven - architecture documented, recovery tested, and no single person or vendor as a point of failure

- Hosting and managed-service vendor relationships under active governance - contracts, SLAs, and security obligations reviewed, with clear accountability

- Internal IT at a managed baseline with clear KPIs and goals defined - access management, device posture, and identity controls documented and auditable

- Privacy function operational - breach assessment and notification process documented and tested, access requests handled within statutory timeframes, and PIAs standard for new integrations

- 5 -

WHAT WE'RE LOOKING FOR

Essential

- 10+ years in information security, with at least 3 years in a security leadership role; a strong security manager ready to step up into their first head-of role will be considered.

- Proven experience building a security programme from scratch - policies, standards, culture, and capability; not just inheriting and maintaining

- Deep working knowledge of ISO 27001 - you have led or significantly contributed to a certification programme end-to-end

- Privacy operations experience in any regulated sector - breach assessment and notification, personal-information access requests, and privacy impact assessments; you have operated under a privacy regulator before, even if not in healthcare

- Hands-on capability - risk assessments, policy writing, penetration test coordination, security tooling; you are comfortable doing as well as directing

- Excellent communication: able to translate technical risk into business language, brief executives clearly, and build credibility with engineering teams

- Commercially aware - you understand that security posture directly affects enterprise sales, contract eligibility, and customer trust, and you can represent that in commercial conversations

- Experience owning production infrastructure or cloud operations - hosting environments, disaster recovery, and service management, ideally delivered through managed-service partners

- Proven vendor and MSP management - you have run critical operations through external partners, holding them to SLAs and security obligations

Strong advantage

- Experience in healthcare or another regulated industry such as financial services or government

- Health data literacy - working knowledge of the Health Information Privacy Code, HISO 10029, HIPPA, and how regulated health data environments work in practice

- Experience governing cloud security on Azure

- Background in security architecture - you can contribute meaningfully to architectural decisions, not just review them after the fact

- IAPP certification (CIPP/CIPM) or equivalent privacy qualification.

OUR PRINCIPLES

Here are the operating beliefs that shape every decision we make:

- Diagnose before you solve - understand the situation fully before reaching for a solution; root cause over symptoms

- 6 -

- The treasure is worth finding - hard problems are worth pursuing with conviction; believe the answer exists, even when it is not yet visible

- Meaningful work and meaningful relationships - the work matters, and so do the people doing it; we optimise for both

- Build great businesses by building great people - the quality of our people and their interactions is the engine of everything we produce

- First principles over analogy - break problems to fundamentals rather than reasoning from how others have solved it

At Medtech, we value adaptability and recognise that business needs may evolve over time. As such, this position description is subject to change.

Skills

AzurePenetration TestingComplianceProcurementISO 27001

Similar Jobs

30

Head of Security

Tremendous · United States +1 · Remote

2 days ago

Head of Security

Profound · New York, New York · Onsite

2 days ago

Head of Security

Pivotal Health · Santa Monica, CA +2 · Hybrid

1 week ago

Head of Security

Kontigo · San Francisco, California, US · Remote

3 weeks ago

Head of Security

Tatari · San Francisco, California, United States +2

2 months ago

Head of Security

Tatari · New York, New York, United States +2

2 months ago

Head of Security

Tatari · Los Angeles, California, United States +2

2 months ago

Head of Security

Revenuecat · Americas +1 · Remote

2 months ago

Head of Security

Edenpeople · United Kingdom - Swindon - Station Square (PPS)

3 months ago

Head of Security

Defuse Labs · Global - Remote · Remote

3 months ago

Head of Security

Fresha · London · Onsite

3 months ago

Head of Security

Stedi · USA · Remote

3 months ago

Head of Security

Protege · Remote · Remote

3 months ago

Head of Security Assurance.Information Security Group-ISG

Mashreq · Bengaluru, Karnataka, India · Remote

Today

Head Of Security - Base44

Wix.com · Tel Aviv, Israel

Today

Head of Security Architecture and Assurance, Charles River Development, Vice Presdient

Statestreet · Dublin 2, Ireland

1 week ago

Global Head of Security Detection and Response

Ing · Madrid (Hubs Spain)

1 week ago

Head of Security GRC

DriveWealth · AMER-US-Remote; Austin, Texas, United States; Dallas, Texas, United States; Denver, Colorado, United States; Miami, Florida, United States; San Francisco, California, United States; Seattle, Washington, United States · Remote

2 weeks ago

Head of Security Engineering

January · New York City · Hybrid

2 weeks ago

Head of Security & AI Governance

Flip · Los Angeles +1 · Onsite

2 weeks ago

Head of Security & Compliance

Aerospike · Mountain View, CA +1 · Remote, Hybrid

3 weeks ago

SVP, Head of Security Technology

Berkley · Wilmington, DE, US

1 month ago

Sub-Regional Head of Security

Digital Realty Global · LONDON, United Kingdom, GB · Onsite

1 month ago

Head of Security Control

Gevernova · Rugby, United Kingdom · Hybrid

1 month ago

Head of Security & Compliance

Casca · San Francisco, US

1 month ago

Head of Security & Compliance

Casca · San Francisco · Onsite

1 month ago

Head of Security Engineering

Harvey · New York · Hybrid

1 month ago

Head of Security Engineering

Harvey · San Francisco · Hybrid

1 month ago

Managing Director & Head of Security and Defense, Public Sector Banking

citibank · New York, NY,US, US +1

1 month ago

Head of Security Architecture and Engineering - CISO function - BPL

Barclays · Canary Wharf, 1 Churchill Place, United Kingdom

1 month ago
Head of Security & Infrastructure at Parker Bridge | Hiring.Camp