The OpportunityDirector of Information Technology is the Company's internal IT leader, reporting to the Chief Financial Officer. The role owns the technology function for the platform: managing the MSP relationship and holding it to its service levels; integrating newly acquired and legacy operating companies onto the Company's standard IT platform; and owning the cybersecurity program that protects the enterprise from phishing, business email compromise, and payment fraud. This is a high-visibility position within the Office of the CFO, with regular exposure to executive leadership, the private-equity sponsor's deal team, and lenders.
Position Summary- Serve as the Company's internal owner of information technology: set IT strategy, standards, budget, and priorities across the platform.
- Manage the MSP relationship: govern service levels (SLAs), performance, and cost, and hold the provider accountable for reliable, high-quality service to the Company and all operating companies.
- Integrate new and legacy operating companies onto the Company's standard IT platform, systems, and controls.
- Own cybersecurity and risk: establish the controls and safety net that protect the business from phishing, social engineering, and payment/wire fraud.
Key Responsibilities- Managed Services Provider (MSP) Management and Service Delivery
- Own the relationship with the Company's managed services provider (MSP) as the internal executive accountable for IT service delivery across all operating companies.
- Define, govern, and enforce service levels (SLAs), response and resolution targets, escalation paths, and performance reporting; hold the MSP accountable to the contracted standards.
- Review and approve the MSP scope, service catalog, and pricing; manage the contract, renewals, and change orders; ensure the Company receives the service it is paying for.
- Run regular service reviews with the MSP; monitor ticket volumes, uptime, response times, and end-user satisfaction; and report performance to leadership.
- Serve as the escalation point for major incidents and service failures; drive root-cause resolution and corrective-action plans.
- Ensure MSP delivery is standardized and consistent across all sites and newly acquired operating companies.
- Operating-Company Onboarding and Platform Integration (M&A)
- Own IT integration for newly acquired operating companies: current-state assessment, cutover planning, and migration onto the Company's standard platform (identity, email, network, endpoints, and business systems), directing the MSP as the delivery resource.
- Develop a repeatable IT integration playbook with Day-1 / Day-30 / Day-90 checklists to accelerate onboarding and reduce integration risk.
- Consolidate and standardize disparate legacy domains, email tenants, applications, and toolsets onto common platforms; retire redundant infrastructure and licenses.
- Standardize identity and access management (single sign-on, multi-factor authentication, role-based access) across every operating company.
- Partner with corporate development, finance, and operating-company leadership on IT diligence input, integration timelines, and transition-services-agreement (TSA) exit.
- Cybersecurity, Risk, and Fraud Prevention
- Own the enterprise cybersecurity program and ensure appropriate, consistent controls across all operating companies, whether delivered internally or through the MSP.
- Direct email security and anti-phishing controls; run continuous phishing simulations and mandatory security-awareness training for all employees.
- Prevent payment fraud: implement controls against business email compromise (BEC), wire / ACH fraud, and vendor or banking-detail change fraud, working with finance and accounts payable on verification, call-back, and dual-control procedures.
- Ensure endpoint detection and response (EDR), multi-factor authentication, patch management, least-privilege access, and secure backup and disaster recovery are in place, and validate that the MSP is delivering them.
- Establish incident-response and business-continuity plans; run tabletop exercises; define breach escalation and notification protocols.
- Align the program to a recognized framework (for example, NIST CSF or CIS Controls); manage cyber-insurance requirements, vendor risk (including the MSP's own security posture), and periodic security assessments.
- Provide clear, periodic risk and posture reporting to the CFO, executive leadership, the sponsor deal team, and the Board.
- Infrastructure, Networks, and End-User Computing
- Oversee, through the MSP, the network, connectivity, cloud, and telephony across headquarters, branch offices, and distributed field / job-site locations.
- Ensure reliable management of the endpoint and mobile-device fleet and field technology, and dependable connectivity for a mobile, field-based workforce.
- Ensure backup, disaster recovery, and business continuity for business-critical systems.
- Applications, Data, and Business Systems
- Support and rationalize core business applications (accounting, project management, payroll / HRIS, service dispatch, and estimating).
- Partner with finance and operations on system consolidation, reporting, and data integrity across operating companies.
- Support the data-governance and reporting needs of the Office of the CFO.
Measures of Success (First 12 Months)- Establish SLA governance over the MSP, including a standing service-review cadence and published performance reporting, within 90 days.
- Complete a current-state assessment and cybersecurity risk baseline across all operating companies.
- Achieve enterprise-wide coverage of multi-factor authentication, email security, EDR, and phishing simulation / training.
- Deliver the targeted number of operating-company integrations onto Company standards on schedule.
- Stand up tested incident-response and backup / disaster-recovery capabilities.
- Deliver a quantified reduction in IT run-rate cost through standardization and MSP contract management.
Required Qualifications- Bachelor's degree in information technology, computer science, or a related field, or equivalent experience.
- 8+ years of progressive IT experience for the Director level (5+ for the Manager level), including responsibility for IT operations.
- Demonstrated experience managing an outsourced IT provider or MSP, including owning SLAs, vendor performance, contracts, and cost.
- Hands-on experience integrating acquired companies onto common IT platforms in an M&A, carve-out, or roll-up environment.
- Strong cybersecurity background across email security, MFA / SSO, EDR, phishing defense, BEC / payment-fraud prevention, backup / DR, and incident response.
- Working knowledge of a recognized security framework (NIST CSF, CIS Controls, or similar).
- Experience owning IT budgets and managing vendors and contracts.
- Clear communicator able to work with non-technical, field-based stakeholders and executive leadership.
Key Competencies- Security-first mindset: treats protection of people, data, and payments as a primary accountability, not an afterthought.
- Vendor governance: holds service providers to SLAs and outcomes, and manages cost and quality without abdicating ownership.
- Bias for standardization: builds repeatable process and reduces one-off complexity across many entities.
- Commercial and cost-disciplined: manages to a budget and quantifies value delivered.
- Hands-on and resilient: operates effectively in a lean, fast-growing, acquisitive environment.