- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Experience
- 3+ years
- Closing date
- Today
- Source
- Vincere
Description
Head of Security and Infrastructure
Job Details
Location Role type Work model Reports to Direct reports
Auckland Permanent, full-time Hybrid Chief Product and Technology Officer Yes
Last updated July 2026 SECURITY IS THE FOUNDATION OF HEALTHCARE TRUST. Medtech Global has spent 30 years building technology that supports clinicians across New Zealand and Australia. We have deep institutional knowledge of how healthcare actually works, and a clear-eyed view of where it needs to go. When a patient shares their health history with a clinician, they are sharing some of the most personal information about their life. They assume that it is stored securely. At Medtech, that assumption falls on us. Our software sits at the centre of clinical workflows across New Zealand and Australia. The data we handle belongs to real patients, and the clinicians relying on it are making real decisions. We are building what comes next, without stopping what works today. Security underpins both, and this role owns it - together with the infrastructure our products run on, the internal IT systems and helpdesk that keep Medtech itself running, and our privacy obligations as guardians of patient data. WHY THIS ROLE EXISTS Health systems trust us with data that is deeply personal and clinically critical. That trust has to be earned continuously, and it can be lost in a single incident. The Head of Security and Infrastructure at Medtech is the person who ensures it never is. This role sits at the intersection of technology, clinical trust, and commercial credibility. Security done well here does not just reduce risk, it opens doors. It is what allows us to enter new markets, win enterprise contracts, and keep building software that healthcare professionals can depend on. The role reports to the CPTO with a direct escalation path to the CEO on security and privacy matters - cyber risk is a standing item on the executive agenda, and the Privacy Officer's regulatory obligations are never subordinate to internal reporting lines.
- 2 -
WHY THIS IS WORTH DOING
This won't be easy. Healthcare is complex, regulated, and high-stakes. The legacy is real and the transformation ahead is significant. But the people using our software are clinicians doing their best work for patients, and the technology they work with shapes what that looks like every day.
The Head of Security and Infrastructure will help define the security, infrastructure and IT for Medtech. It is a rare opportunity. We are looking for someone who sees that clearly and wants to be part of making it real.
WHAT THIS ROLE DOES
Build and own the security programme
- Own Medtech's security posture across all products and cloud environments, from risk assessment through to driving and verifying remediation with engineering teams
- Lead the ISO 27001 / HISO 10029 programme, including scoping, gap analysis, controls implementation, and audit readiness
- Build and own the Business Continuity and Incident Response programme
- Govern vendor and third-party security obligations - access controls, cloud provider agreements, and managed security services across all third parties, including partners with access to our environments
Own the compliance programme and serve as Privacy Officer
- Lead Medtech's regulatory compliance obligations: NZ Privacy Act 2020, Health Information Privacy Code (HIPC), Australian Privacy Act, and HISO 10029 with Privacy by Design embedded from day one
- Own data sovereignty obligations across NZ and AU environments, so that patient data stays where it belongs
- Represent security and privacy in product and architecture decisions, so that new products are secure from day one, not retrofitted
- Act as Medtech's designated Privacy Officer under the NZ Privacy Act 2020 — the named point of accountability for privacy across the business
- Own the relationship with privacy regulators - the Office of the Privacy Commissioner (NZ) and the OAIC (AU) - including breach assessment and notification under both notifiable-breach regimes
- Handle privacy complaints and personal-information access and correction requests, with documented processes and timeframes
- Establish privacy impact assessments as standard practice for new products, integrations, and data flows
Embed security into how we build
- 3 -
- Shift security left into engineering practice, help with standards, tooling, and culture that make security a shared responsibility across the product and engineering organisation
- Establish a security awareness and education programme across the business, making security everyone's responsibility, with the Head of Security and Infrastructure as the standard- setter
Own the infrastructure and hosting estate
- Own the cloud hosting environments our products and customers depend on - private and public cloud, across New Zealand and Australia
- Own disaster recovery and business continuity infrastructure - architecture documented, recovery tested end-to-end, and no single person or vendor as a point of failure
- Own and govern the hosting and managed-service vendor relationships - contracts, SLAs, security obligations, performance, and genuine redundancy between providers
- Lead the internal infrastructure team and direct the managed-service partners that extend it
Lead the internal IT function
- Own and run the IT function - the tools and systems that the business depends on every day
- Lead and develop the IT team - setting direction, managing performance, and growing capability
- Own IT procurement and vendor management - selecting and managing the tools and services that keep the organisation running securely and efficiently
- Ensure IT practices meet security standards, like access management, device policies, and tooling aligned with the organisation's security posture from the ground up
- Partner with the business to understand what they need from IT and deliver it reliably
- Build the relationship with engineering, product, and executive teams so security is an enabler, not a blocker
HOW YOU WILL WORK
This is a player-coach role. You will be doing as much as directing: conducting risk assessments, writing policies, coordinating penetration testing, reviewing vendor contracts and getting into the detail of DR runbooks and hosting architecture. The credibility of this role is built in the work, not the title.
Work backwards from outcomes. Security decisions should be anchored to what they protect, what they enable, and what it costs to get them wrong. The Head of Security and Infrastructure at Medtech is not a gatekeeper, they are a strategic partner who understands the commercial and clinical stakes equally.
Be a multiplier. You will build a team, but your leverage is the security culture you embed across the whole organisation. Engineers who think about security, product managers who design it in from the start, executives who understand the risk landscape - that is the real outcome of this role.
- 4 -
Be commercially aware. Security at Medtech is a competitive differentiator. Enterprise buyers evaluate our security posture before signing. Health system contracts require demonstrable compliance. You understand this and can speak to it in the boardroom, in a sales conversation, and in a contract review.
Be AI-native. Security is changing as fast as the technology it protects. We expect you to stay at the frontier, understanding how AI changes the threat landscape, how it can accelerate security operations, and how to govern AI systems in a regulated healthcare environment.
Be visionary when needed, pragmatic always. A strong security posture is built incrementally, not in a single transformation. Set the long-term direction clearly, then make the small, deliberate improvements that compound over time. Progress is made in well-designed iterative steps.
Diagnose before you solve. Our security landscape has complexity built up over decades. Before reaching for solutions, understand the system. Root causes matter more than symptoms. First principles matter more than checklists.
WHAT SUCCESS LOOKS LIKE AT 12 MONTHS
Working backwards from where we need to be:
- ISO 27001 programme scoped and in progress, with gap analysis complete, controls roadmap agreed, certification timeline defined
- BCP/IRP operational - documented, tested, and owned
- Security standards embedded in the SDLC - engineers have guardrails to rely on, not guesswork
- Regulatory compliance posture documented and managed - NZ Privacy Act 2020, Australian Privacy Act, Health Information Privacy Code (HIPC), and HISO 10029 obligations mapped and addressed
- Vendor and third-party security obligations governed, with access controls in place and auditable
- The enterprise security risk register is actively managed, with critical risks materially reduced and progress visible to the executive and board
- A security roadmap the CPTO and executive team can present to enterprise clients and health system partners with confidence
- Disaster recovery proven - architecture documented, recovery tested, and no single person or vendor as a point of failure
- Hosting and managed-service vendor relationships under active governance - contracts, SLAs, and security obligations reviewed, with clear accountability
- Internal IT at a managed baseline with clear KPIs and goals defined - access management, device posture, and identity controls documented and auditable
- Privacy function operational - breach assessment and notification process documented and tested, access requests handled within statutory timeframes, and PIAs standard for new integrations
- 5 -
WHAT WE'RE LOOKING FOR
Essential
- 10+ years in information security, with at least 3 years in a security leadership role; a strong security manager ready to step up into their first head-of role will be considered.
- Proven experience building a security programme from scratch - policies, standards, culture, and capability; not just inheriting and maintaining
- Deep working knowledge of ISO 27001 - you have led or significantly contributed to a certification programme end-to-end
- Privacy operations experience in any regulated sector - breach assessment and notification, personal-information access requests, and privacy impact assessments; you have operated under a privacy regulator before, even if not in healthcare
- Hands-on capability - risk assessments, policy writing, penetration test coordination, security tooling; you are comfortable doing as well as directing
- Excellent communication: able to translate technical risk into business language, brief executives clearly, and build credibility with engineering teams
- Commercially aware - you understand that security posture directly affects enterprise sales, contract eligibility, and customer trust, and you can represent that in commercial conversations
- Experience owning production infrastructure or cloud operations - hosting environments, disaster recovery, and service management, ideally delivered through managed-service partners
- Proven vendor and MSP management - you have run critical operations through external partners, holding them to SLAs and security obligations
Strong advantage
- Experience in healthcare or another regulated industry such as financial services or government
- Health data literacy - working knowledge of the Health Information Privacy Code, HISO 10029, HIPPA, and how regulated health data environments work in practice
- Experience governing cloud security on Azure
- Background in security architecture - you can contribute meaningfully to architectural decisions, not just review them after the fact
- IAPP certification (CIPP/CIPM) or equivalent privacy qualification.
OUR PRINCIPLES
Here are the operating beliefs that shape every decision we make:
- Diagnose before you solve - understand the situation fully before reaching for a solution; root cause over symptoms
- 6 -
- The treasure is worth finding - hard problems are worth pursuing with conviction; believe the answer exists, even when it is not yet visible
- Meaningful work and meaningful relationships - the work matters, and so do the people doing it; we optimise for both
- Build great businesses by building great people - the quality of our people and their interactions is the engine of everything we produce
- First principles over analogy - break problems to fundamentals rather than reasoning from how others have solved it
At Medtech, we value adaptability and recognise that business needs may evolve over time. As such, this position description is subject to change.