About this role
The Director of Infrastructure and Cybersecurity leads both disciplines for Advita with equal weight. The role owns the systems that keep manufacturing, quality, and commercial operations running, and it owns the security program that protects Advita’s intellectual property, design and production data, and regulated electronic records. This is a working leadership role in a validated, FDA-regulated manufacturing environment. The Director is expected to be close enough to the technology to make sound architecture and risk decisions, and senior enough to set direction, own the budget, and represent both agendas to the executive team. Neither mandate is treated as secondary to the other. Infrastructure Own the architecture, deployment, and operation of network, server, storage, endpoint, and cloud environments across all Advita sites. Prioritize infrastructure work by its effect on production uptime, quality system availability, and the ability to ship. Manufacturing continuity is the first test of any infrastructure decision. Own disaster recovery and business continuity for critical systems. Define recovery objectives with the business, test them on a published schedule, and report the results. Direct lifecycle management, capacity planning, and modernization. Maintain a rolling multi-year plan for hardware, operating systems, and platforms approaching end of support. Manage the infrastructure supporting validated and GxP-relevant systems in coordination with Quality. Ensure changes move through validation and change control rather than around them. Bring the plant floor under a defined standard. Establish segmentation, patching, backup, monitoring, and remote access requirements for manufacturing equipment, historians, and OT networks. Own the service desk and end-user computing experience. Publish response and resolution targets and hold internal staff and outside providers to them. Ensure infrastructure changes conform to organization-wide change management standards and are documented, reversible, and communicated in advance. Cybersecurity Own Advita’s cybersecurity program: roadmap, policies, standards, procedures, and controls, measured against a named framework such as ISO 27001 or NIST CSF rather than against opinion. Own identity and access management, including privileged access, joiner and leaver processes, and periodic access reviews for systems holding regulated or confidential data. Own enterprise security controls across network defense, endpoint protection, email security, logging, and monitoring. Maintain a clear view of what is covered, what is not, and what closing the gap costs. Lead vulnerability management across both IT and OT, with remediation targets by severity and regular reporting against them. Own incident response. Maintain and exercise the plan, define escalation and notification paths, and lead the response when an incident occurs. Maintain a risk register leadership can act on, with named owners, treatment decisions, and dates. Lead periodic risk assessments and report movement over time. Ensure controls over electronic records and signatures meet FDA 21 CFR Part 11 expectations, and that IT controls supporting the quality system hold up under audit. Support internal audits, customer security questionnaires, and regulatory inspections. Keep evidence and documentation current so audits do not become projects. Manage third-party and supply chain risk. Assess vendors and service providers before they receive access to Advita systems or data, and reassess on a defined schedule. Partner with business leaders so controls fit how the work is actually done. Where a control creates real friction, propose a workable alternative rather than an exception. Leadership, Vendor & Financial Responsibilities Provide direction and leadership to the infrastructure and security teams. Recruit, develop, and retain staff, and build enough depth that no critical system depends on one person. Develop and manage the operating and capital budgets for both mandates. Make spend tradeoffs and defend them. Evaluate, select, and manage technology vendors and managed service providers. Hold contracts and service levels accountable and be prepared to change providers who underperform. Communicate infrastructure and security risk to technical and non-technical audiences. Give the executive team a current, usable picture without requiring them to interpret technical detail. Maintain regular written and in-person communication with executives, department heads, and end users regarding planned work, outages, and changes. Act as the liaison between IT, Quality, Operations, and Commercial on technology decisions affecting regulated processes. Support applicable regulatory and contractual obligations across Advita’s markets, including FDA 21 CFR Part 11 and Part 820, ISO 13485, and, where relevant to Advita’s data and geographies, HIPAA, GDPR, and EU MDR requirements.