Role Description
Vehlo is seeking an innovative and visionary Director, Information Technology & Enterprise AI, to lead the next evolution of our technology, security, and AI capabilities. This leader will be responsible for developing and executing a modern enterprise technology strategy that enables business growth, strengthens cybersecurity resilience, improves operational efficiency, and accelerates responsible AI adoption across the organization.
Reporting to the Chief Product & Technology Officer (CPTO), the Director will serve as a trusted advisor to executive leadership, translating business objectives into scalable technology solutions while fostering a culture of security, innovation, automation, and continuous improvement.
This role requires a strategic thinker who can balance operational excellence with forward-looking technology leadership, ensuring Vehlo remains secure, agile, and positioned to capitalize on emerging technologies.
What Youβll Do
-
Technology Strategy & Leadership
-
Develop and execute a multi-year IT, cybersecurity, and AI roadmap aligned with company growth objectives.
-
Serve as a technology advisor to leadership on emerging technologies, industry trends, cyber risks, and AI opportunities.
-
Lead enterprise technology governance, architecture, standards, and best practices.
-
Drive digital transformation initiatives that improve employee productivity, customer outcomes, and operational scalability.
-
Establish a culture focused on innovation, service excellence, accountability, and business partnership.
-
Lead technology platform integrations for acquired businesses.
-
Cybersecurity & Risk Management
-
Own enterprise cybersecurity strategy, risk management, and security operations.
-
Oversee implementation and continuous improvement of security frameworks including NIST CSF, CIS Controls, SOC 2, and other relevant compliance requirements.
-
Lead incident response planning, tabletop exercises, business continuity, and disaster recovery programs.
-
Manage security awareness and training initiatives to strengthen organizational cyber resilience.
-
Partner with internal and external stakeholders to identify, assess, and mitigate cyber risks.
-
Oversee endpoint security, identity and access management, network security, cloud security, threat detection, and vulnerability management.
-
Ensure security-by-design principles are embedded across infrastructure, applications, and AI initiatives.
-
Extend the security program to AI systems: model and vendor risk assessment, data-loss prevention across AI channels, threat modeling for prompt injection and agent misuse, logging and monitoring of AI activity, and incident response procedures that cover AI-specific failure modes.
-
Enterprise AI Strategy & Governance
-
Own the enterprise AI strategy, governance framework, and adoption roadmap for AI used to run Vehloβs business.
-
Identify opportunities to leverage AI, machine learning, intelligent automation, and generative AI to increase organizational effectiveness and scalability.
-
Partner with business leaders to evaluate and implement AI-enabled solutions that drive measurable business value.
-
Develop and maintain policies and controls for responsible AI use, data protection, risk management, and regulatory compliance, aligned to NIST AI RMF and ISO/IEC 42001 and to evolving AI regulation.
-
Lead role-based AI enablement and change management, with defined adoption targets by function rather than general awareness training.
-
Evaluate emerging AI technologies, rationalize the tool portfolio to avoid overlapping spend, and recommend investments that create competitive advantage.
-
Serve as the governance and security authority for AI across Vehlo, including AI embedded in Vehlo products, without owning product AI delivery.
-
Enterprise AI Platform Operations
-
Administer Vehloβs enterprise AI platforms (Claude, Microsoft Copilot, and successors): tenant and workspace configuration, SSO and SCIM provisioning, role and permission models, data retention settings, and audit logging.
-
Manage AI licensing and spend: seat allocation and reclamation, plan tiering, API and consumption cost monitoring, showback to business units, and renewal negotiation.
-
Govern the AI integration surface β MCP servers, connectors, plugins, and agent access to enterprise systems β through a defined intake, security review, approval, and periodic recertification process.
-
Define and enforce data boundaries for AI: which classes of Vehlo and customer data may be used with which models, and under which contractual terms for training, retention, and sub-processors, in partnership with Legal, Security, and Product.
-
Manage identity and access for non-human actors: service accounts, agent credentials, least-privilege scoping, activity monitoring, and rapid revocation for AI agents operating in enterprise systems.
-
Detect and remediate unsanctioned AI use, and provide a sanctioned alternative that makes the approved path the easier one.
-
Instrument adoption and value: usage telemetry, adoption and utilization reporting by function, and measured productivity or cost impact against stated targets.
-
Run the enterprise AI evaluation process: structured vendor and model assessment, security and privacy review, pilot design, success criteria, and go/no-go recommendations.
-
Own AI-related responses to customer, auditor, and sponsor diligence, including security questionnaires, AI use disclosures, and control evidence.
-
IT Operations & Infrastructure
-
Ensure reliable, secure, and efficient delivery of enterprise technology services.
-
Lead end-user support, collaboration platforms, endpoint management, and workplace technology services.
-
Oversee Microsoft 365, Slack, Zoom, enterprise AI assistants, identity management, endpoint solutions, and enterprise productivity platforms.
-
Drive infrastructure modernization, cloud optimization, and operational automation initiatives.
-
Partner with cloud and managed service providers to maintain high-performing, cost-effective technology environments.
-
Establish service level objectives (SLOs), performance metrics, and operational KPIs.
-
Cloud & Platform Security
-
Collaborate with AWS, DevOps, and engineering teams to enhance cloud security posture and governance.
-
Establish cloud security architecture standards and monitoring capabilities.
-
Implement security controls, automation, and compliance capabilities across cloud environments.
-
Support secure development practices and DevSecOps initiatives.
-
Financial, Vendor, Facility Management
-
Develop and manage the IT and security budget.
-
Evaluate technology investments and ensure alignment with strategic priorities and ROI objectives.
-
Lead vendor selection, contract negotiations, performance management, and optimization efforts.
-
Identify opportunities to reduce risk, improve efficiency, and optimize technology spend.
-
Own the enterprise AI budget as a distinct line item, with unit economics β cost per active user and cost per workflow automated β and a stated payback expectation.
-
Manage workplace and facilities technology across Vehlo locations, including remote and hybrid offices in the United States and Mexico.
-
People Leadership
-
Build, mentor, and develop high-performing IT and security teams.
-
Foster a culture of continuous learning, innovation, and technical excellence.
-
Establish clear performance expectations and career development opportunities.
-
Lead cross-functional collaboration across technology, product, operations, finance, HR, and business teams.
Qualifications
-
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or related field.
-
7+ years of progressive technology leadership experience.
-
3+ years leading enterprise IT, cybersecurity, or digital transformation programs.
-
Experience developing and implementing cybersecurity frameworks and risk management programs.
-
Experience managing cloud-based environments, preferably AWS and Microsoft ecosystems.
-
Strong understanding of enterprise architecture, infrastructure, networking, endpoint management, and SaaS platforms.
-
Demonstrated experience leading cross-functional initiatives and influencing executive stakeholders.
-
Exceptional communication, leadership, and strategic planning skills.
-
Hands-on experience deploying and administering an enterprise generative AI platform (Claude, Microsoft Copilot, or equivalent) at organizational scale, including tenant administration, access control, data governance settings, and license management.
-
Experience establishing AI governance in an enterprise: acceptable-use policy, tool intake and review, data-use boundaries, and adoption measurement.
-
Experience leading IT and security integration of acquired businesses.
Preferred Qualifications
-
Master's degree in Technology, Cybersecurity, Business Administration, or related discipline.
-
CISSP, CISM, CRISC, CGEIT, Security+, AWS Security Specialty, Microsoft Security certifications, or equivalent credentials.
-
Experience with private equity-backed, SaaS, or multi-entity organizations.
-
Familiarity with SOC 2, ISO 27001, PCI, privacy regulations, and modern governance frameworks.
-
Global experience with operations in Mexico.
-
Familiarity with NIST AI RMF, ISO/IEC 42001, the EU AI Act, and emerging US state AI regulation.
-
Experience with agentic AI and non-human identity management.