DescriptionJOB DESCRIPTION
POSITION: INFORMATION TECHNOLOGY DIRECTOR
CLASSIFICATION CODE: EXEMPT FULL TIME
DEPARTMENT: INFORMATION TECHNOLOGY
REPORTS TO: CEO
STATEMENT OF JOB: The Information Technology (IT) Director provides executive-level leadership, strategic direction, and hands-on management for all aspects of Apache Behavioral Health Services' (ABHS) technology operations. This includes IT infrastructure, cybersecurity, data protection, vendor relationships, electronic health record (EHR) systems, and digital innovation initiatives. The IT Director ensures compliance with HIPAA Security Rules, federal (IHS), state (AHCCCS), and Tribal (638 contract) requirements, while supporting clinical, administrative, and operational excellence across multiple ABHS facilities on the Fort Apache Reservation. As both a strategic leader and a hands-on practitioner, the IT Director develops IT policies, oversees staff and vendors, manages complex projects, and directly engages in technical problem-solving to guarantee secure, efficient, and reliable IT systems that support ABHS's mission of providing behavioral health care to the White Mountain Apache Tribe.
DUTIES AND RESPONSIBILITIES:
Strategic Leadership & Governance
- Serve as ABHS's senior technology executive, aligning IT strategy with agency mission, compliance requirements, and growth initiatives.
- Develop and execute multi-year IT roadmaps covering infrastructure upgrades, cybersecurity maturity, cloud adoption, and digital innovation.
- Lead the IT Steering Committee, advising the CEO and executive leadership team on technology investments, risk posture, and emerging solutions.
- Develop, manage, and monitor the IT department budget in collaboration with Finance and the CEO, balancing cost control with innovation.
- Represent ABHS in Tribal, state, and national IT consortiums, ensuring advocacy and access to shared resources.
- Establish and enforce IT governance, including change management, technology standards, and agency-wide compliance policies.
- Provide regular IT performance, risk, and compliance reporting to the CEO, Board of Directors, and regulatory agencies.
Cybersecurity & Compliance Oversight
- Serve as Chief Information Security Officer (CISO) for ABHS, ensuring compliance with HIPAA, IHS, AHCCCS, and Tribal IT security requirements.
- Lead enterprise-wide security frameworks, including NIST CSF and CIS controls, adapting to the needs of healthcare and behavioral health environments.
- Direct incident response, breach investigations, and forensic activities in coordination with Tribal, state, and federal partners.
- Oversee risk assessments, penetration testing, and vulnerability management programs; ensure timely remediation.
- Ensure encryption, MFA, endpoint protection, mobile device management, and secure cloud practices are enforced across ABHS.
- Maintain compliance with cybersecurity insurance requirements and support audits by insurers, regulators, and external entities.
- Develop and maintain ABHS's Information Security Program Manual and Business Continuity/Disaster Recovery (BC/DR) plans.
- Supervise data governance, data loss prevention (DLP), and secure data exchange practices across all platforms.
- Ensure Business Associate Agreements (BAAs) and vendor security reviews are current and enforceable.
IT Operations & Infrastructure
- Oversee day-to-day IT operations for all ABHS facilities, including clinics, shelters, residential facilities, and administrative offices.
- Provide hands-on technical leadership for infrastructure management, including servers, storage, networks, VoIP, firewalls, and wireless systems.
- Ensure continuous uptime and secure operation of ABHS's EHR (myEvolv), HRIS, and financial systems.
- Lead agency-wide cloud strategy, optimizing Microsoft 365, Azure AD, Teams, SharePoint, OneDrive, and hybrid integrations.
- Direct system monitoring, patch management, and lifecycle refresh planning for hardware, software, and network devices.
- Maintain centralized configuration management, CMDB accuracy, and IT asset inventory.
- Ensure effective vendor and managed services coordination for mission-critical infrastructure projects.
- Lead IT support for telehealth platforms, remote staff, and hybrid work environments.
- Oversee agency-wide audiovisual and conferencing systems for clinical and administrative use.
- Personally intervene in escalated IT support issues, providing direct technical expertise.
Vendor & Project Management
- Negotiate contracts, SLAs, and renewals with technology vendors, MSPs, and cloud providers.
- Direct IT capital projects (network upgrades, cloud migrations, cybersecurity implementations), ensuring timelines, budgets, and compliance.
- Enforce vendor compliance with HIPAA, Tribal, and ABHS standards through BAAs and ongoing audits.
- Oversee vendor risk assessments and remediation for third-party hosted systems.
- Ensure knowledge transfer from vendors to internal staff upon project completion.
- Manage procurement and licensing compliance for agency-wide hardware and software.
Staff Development & Leadership
- Provide mentorship, professional development, and performance oversight for IT staff, fostering a culture of accountability and service.
- Ensure adequate IT staffing coverage for multi-site operations, after-hours support, and emergency response.
- Lead annual security awareness and phishing simulation training for all ABHS employees.
- Model hands-on leadership by actively participating in troubleshooting, system deployments, and complex IT challenges.
- Develop succession planning and career pathways for IT personnel to promote growth and retention.
Communication & Stakeholder Engagement
- Serve as IT liaison to Tribal government, IHS, AHCCCS, and external regulators.
- Communicate IT strategies, risks, and initiatives in accessible language for staff, leadership, and community stakeholders.
- Support all Board and executive meetings requiring IT, audiovisual, or cybersecurity support.
- Maintain culturally competent and professional relationships with Tribal leaders, community members, and external partners.
QUALIFICATIONS
Required:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
- Minimum ten (10) years of progressive IT experience, with at least five (5) years in senior leadership roles.
- Demonstrated experience managing IT operations across multi-site, healthcare, or behavioral health environments.
- Advanced technical knowledge of:
- Microsoft 365, Azure AD, Teams, SharePoint
- Windows Server (2016/2019/2022), virtualization, and cloud services
- HIPAA compliance, NIST CSF, CIS benchmarks
- Firewalls, networking, endpoint security, patch management
- Strong leadership, vendor negotiation, and project management skills.
- Valid Arizona driver's license and reliable transportation.
- Ability to pass fingerprint clearance, background checks, and pre-employment testing.
Preferred:
- Master's degree in Information Technology, Cybersecurity, or Business Administration.
- Professional certifications: CISSP, CISM, CompTIA Security+, Microsoft Certified Azure Administrator/Architect, or PMP.
- Experience in Tribal health, behavioral health, or federal contract-based IT environments.
- Provide leadership for ABHS' overall IT strategy, infrastructure management, cybersecurity posture, and operational excellence.
- Supervise all internal IT staff, including IT Supervisors, Specialists, and Helpdesk teams.
- Manage contracts and relationships with outsourced IT partners (Managed Services Providers) and technology vendors.
- Develop and monitor the annual IT budget in collaboration with the CEO and Finance.
- Advise executive leadership on technology solutions aligned to agency growth, compliance, and operational needs.
- Lead IT participation in strategic agency initiatives, including expansions, facility upgrades, and telehealth deployments.
- Coordinate IT operations across all ABHS offices, residential facilities, field operations, and remote environments.
- Lead IT Disaster Recovery and Business Continuity Planning (DR/BCP), ensuring resiliency of critical systems including EHR, finance, and HRIS platforms.
- Oversee cybersecurity compliance programs, including HIPAA Security Rule adherence, risk analysis, and security incident response.
- Develop long-term IT infrastructure and systems upgrade roadmaps, ensuring secure and scalable solutions.
- Develop annual IT goals and objectives aligned to ABHS's strategic plan and report progress quarterly to executive leadership.
- Maintain and enforce policies regarding appropriate use of agency technology and internet resources.
- Lead or assist with investigations of technology misuse, security breaches, or compliance violations.
- Design, implement, and test backup, replication, and disaster recovery systems to protect agency data.
- Approve standard operating environments (SOEs) for endpoint device imaging and deployment.
- Manage onboarding/offboarding technology processes to ensure secure access and data protection.
- Coordinate periodic HIPAA Security Risk Assessments and ensure timely completion of corrective actions.
- Ensure configuration management database (CMDB) accuracy and oversee IT asset audits.
- Lead annual network penetration testing with third-party vendors and implement remediation plans.
- Supervise IT helpdesk knowledgebase development to ensure consistent, accurate, and timely technical support.
- Maintain up-to-date documentation of IT infrastructure, systems architecture, and vendor configurations.
- Prepare technology investment proposals for leadership and Board approval, providing cost-benefit analyses and security implications.
- Coordinate quarterly IT steering committee meetings involving senior leadership and department heads.
- Lead annual IT staff security awareness training and phishing simulations.
- Manage email security gateway and filtering systems to protect against spam, phishing, and malware threats.
- Oversee the protection of mobile devices, including laptops and phones, using MDM solutions.
- Ensure secure remote access technologies (VPN, MFA) are fully operational and monitored.
- Supervise agency data loss prevention (DLP) efforts across email, network, and storage environments.
- Maintain oversight of electronic health record (EHR) data security, access control, and user activity monitoring.
- Develop and test business continuity procedures for mission-critical services, including EHR and telehealth platforms.
- Participate in crisis response teams to support operational technology continuity during emergencies.
- Coordinate software development or customization projects supporting agency operations or reporting needs.
- Ensure compliance with federal, state, and Tribal regulations related to electronic records, privacy, and security.
- Supervise user rights reviews to ensure staff have minimum necessary access under HIPAA Privacy Rule standards.
- Manage centralized log collection, retention, and monitoring processes for audit and compliance reporting.
- Facilitate annual hardware refresh planning to replace aging systems proactively.
- Participate in external technology consortiums or Tribal IT networks to share knowledge and resources.
- Create and maintain IT service catalogs for internal stakeholders, clearly outlining available services and support channels.
- Collaborate with Facilities Department regarding physical security systems, including badge access and video surveillance integration.
CYBERSECURITY & COMPLIANCE:
- Serve as lead to the Information Security Officer (ISO), ensuring implementation of cybersecurity frameworks and agency security policies.
- Manage HIPAA compliance related to technology systems, including annual security risk assessments and mitigation activities.
- Oversee endpoint protection, encryption, multifactor authentication (MFA), patch management, and network security monitoring.
- Coordinate regular IT security audits, vulnerability assessments, and penetration testing with external providers.
- Ensure accurate tracking and reporting of PHI security incidents and breaches in compliance with HIPAA regulations.
- Implement cybersecurity awareness training programs for all ABHS employees.
- Ensure continuous compliance with the HIPAA Security Rule across all technology systems.
- Implement and enforce encryption at rest and in transit for all sensitive agency data.
- Conduct quarterly security awareness training for all employees, covering phishing, password management, and data handling.
- Ensure agency compliance with National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) controls where applicable.
- Manage and monitor endpoint detection and response (EDR) or extended detection and response (XDR) solutions across the network.
- Ensure multi-factor authentication (MFA) is enforced for all systems accessing PHI and financial data.
- Perform role-based access control (RBAC) reviews quarterly, ensuring minimum necessary access levels.
- Manage Secure File Transfer Protocol (SFTP) systems or equivalent for sensitive data exchanges.
- Enforce patch management policies to remediate vulnerabilities within defined timelines based on criticality.
- Maintain full asset inventory for IT hardware and software per HIPAA and cybersecurity insurance requirements.
- Ensure that Electronic Health Record (EHR) audit logs are active, maintained, and reviewed as required.
- Manage and test secure data backup and recovery protocols with offsite or cloud-based storage redundancy.
- Maintain and review vendor risk assessments to ensure third-party compliance with security standards.
- Supervise the application of Data Loss Prevention (DLP) technologies to prevent unauthorized data exfiltration.
- Require encrypted email transmission for all PHI and sensitive data communications.