MARK HITCHCOCK
000
IT, Security & DevOps / Greater Pittsburgh, PA / Remote

Growing company. High-stakes data. No real IT function.

Three industries, one problem. Built it twice from nothing and stayed to run it: five years at a multi-site card processor, then nearly five years running a legal services nonprofit's entire IT function single-handed. Today that scope is IT, security and DevOps for 300 employees and a 1,400+ site production fleet.

0
Years in technology
0
Sites in the fleet
0
Outbreak containment
0
Annual SaaS spend cut
0
Hires since 2019
The through-line

Three industries. One problem.

Card processing, legal services and marketing technology look nothing alike from the outside. From the inside they arrived the same way: growing fast, sitting on data that could not afford a bad day, and running without anybody who owned the technology end to end. That has been the job three times.

01 / 2014-2019

Payments

Merchant Lynx Services

Arrived at a multi-site card processor with no compliance program in place. Built and ran the company technology environment for five years inside a $500K-a-year estate.

Led the first PCI DSS Level 1 service provider certification and project managed the SOC 2 Type II obtained in 2016. Carried growth from 75 to 150 users and 6 to 8 operating sites.

02 / 2019-2024

Legal services

Neighborhood Legal Services

First technology leader the organization ever had. Ran the entire IT function single-handed for 150 employees, 250 endpoints and 100 tickets a month.

Built its first security architecture and access controls, led a full on-premise to cloud migration, and cut operating cost from about $500K to $420K. Documented the environment to a standard that survived transition to an outside provider.

03 / 2024-Present

Marketing technology

MyAdvice

Own IT, security and DevOps for 300 employees, 354 managed endpoints and a 1,400+ site client hosting fleet at a $15-20M revenue company.

Hold final architecture authority for the fleet security and operations tooling layer, approve about $1M in annual technology spend, and lead four engineers across the US and India.

Signature work

Incident command, played back.

Every square below is one site in the production fleet. In one incident, 130 of them were hit at once. What follows is how that ran and what got built afterward so it did not run twice.

Phase
T+0 / Detection
Healthy site Affected Contained
Fleet map of 1,400 sites with 130 affected sites highlighted

130 sites, surfaced at once.

A malware outbreak hit 130 sites inside the fleet. Detection ran off a malware signature list built from our own incident forensics rather than vendor defaults, so the sweep matched what was actually running in the environment. Triage that used to mean site-by-site manual log review now runs through a purpose-built malware bot.

130
Sites affected
1,400+
Sites under watch
P0
Payment and subscription sites carry elevated monitoring

The operating surface

What actually sits under me.

Corporate IT, the security program and the DevOps layer, plus the budget that funds all three. The boundary above the hosting contract is defined, and every control above it is mine.

01

Fleet & security

  • Final architecture authority for the fleet security and operations tooling layer
  • Risk classification so P0 payment and subscription sites carry elevated monitoring
  • Forensics-led malware signatures, SentinelOne, Datadog, GuardDuty, Wordfence
  • Weekly security posture reporting on remediation, exposure and repeat incidents
02

Identity & endpoint

  • IAM, SSO, MFA, TOTP, SCIM and identity lifecycle across JumpCloud, Workspace and Planhat
  • Quarterly access reviews on a monthly remediation cycle
  • 354 managed endpoints across Windows, macOS, Linux and mobile
  • SSH key lifecycle and rotation tracking on the fleet management plane
03

DevOps & AI

  • 3 AI agents shipped into production covering DevOps runbooks, fleet malware remediation and triage
  • Voice AI platform delivered from the PM seat, now live with close to 500 users
  • Python runbooks with staged rollout and verification gates in place of manual SSH
  • Production RDS upgrade run alongside the fleet remediation program
04

Budget & vendors

  • Approval authority over about $1M in annual technology spend
  • Joint signature with the VP of Engineering on large items
  • Build vs buy called on evidence, not preference
  • Vendor risk, third-party risk and hardware asset lifecycle
05

Service desk

  • Zendesk service desk built from zero, now 150 to 300 tickets a month
  • 99 percent positive across more than 1,000 responses over two years
  • 48-hour resolution target set and measured where no ticketing data had existed
  • Support solve time moved from 1 to 2 days down to same day
06

Governance

  • AI licensing and acceptable use policy authored for 300 employees
  • Quarterly technology priorities set against security risk, client impact and cost
  • PCI DSS Level 1 and NIST 800-171 program experience
  • Monthly phishing simulations with click and open rates falling over time
Decisions on the record

Money moved, time returned.

Owning the budget only matters if the number changes. Each of these was a call made, funded and measured afterward.

Custom security platform quoted by a vendorBuilt the equivalent in-house on Python and vendor APIs
$37K quote
$10-15K built
Annual SaaS spend across Zendesk, Google Workspace, Claude, Planhat and JumpCloudConsolidated and renegotiated
Baseline
$150K+ cut a year
Operating cost at Neighborhood Legal Services$40K workflow automation, $35K VoIP, $5K ticketing
~$500K
~$420K
Account build time on the hosting fleetAutomation replacing one-task-at-a-time work
40 to 60 min
5 to 10 min
Support solve timeTicketing buildout and triage automation
1 to 2 days
Same day
Security emphasis after an audit returned 24 Critical findingsRepeat incidents now sit at zero
WordPress
AWS
Experience

Eighteen years, front to back.

Director of Information Technology

Oct 2024 - Present
MyAdvice / Salt Lake City, UT (Remote)
  • Own IT, security and DevOps for 300 employees, 354 managed endpoints and a 1,400+ site client hosting fleet serving 800 to 1,000 accounts.
  • Approve about $1M in annual technology spend at a $15-20M revenue company, signing jointly with the VP of Engineering on large items.
  • Hold final architecture authority for the security and operations tooling layer of the fleet.
  • Ran incident response on a 130-site malware outbreak: contained in 24 hours, remediated in 48, with no clients lost and no credits.
  • Closed an AWS IAM compromise behind about 620,000 unauthorized calls at zero net cost after a full vendor refund.
  • Shipped 3 AI agents into production covering DevOps runbooks, fleet malware remediation and triage.
  • Delivered a voice AI platform now live with close to 500 users as PM across development and systems.
  • Designed and ran a four-wave plugin vulnerability remediation release with a Python runbook, staged rollout and verification gates.
  • Rejected a $37K custom platform and built the equivalent in-house on Python and vendor APIs for $10-15K.
  • Cut over $150K a year from SaaS spend across Zendesk, Google Workspace, Claude, Planhat and JumpCloud.
  • Built the Zendesk service desk from zero: 99 percent positive across 1,000+ responses over two years.
  • Authored the AI licensing and acceptable use policy for 300 employees and won funding for the deployment behind it.
  • Lead 4 engineers across the US and India, all direct reports, including the lead; hired three of them.
  • Turned post-mortems into 7 incident playbooks and an FMEA program driving preventive fixes.

Director of Information Technology

Sept 2019 - May 2024
Neighborhood Legal Services / Pittsburgh, PA
  • First technology leader the organization ever had; built its first security architecture and access controls.
  • Ran the entire IT function single-handed for 150 employees, 250 endpoints and 100 tickets a month.
  • Led a full on-premise to cloud migration, replacing VoIP, ticketing and core infrastructure.
  • Cut operating cost from about $500K to $420K: $40K workflow automation, $35K VoIP, $5K ticketing.
  • Ran Microsoft 365, Active Directory, Okta, Azure and Salesforce in production across 250 endpoints.
  • Applied NIST 800-171, ran SentinelOne endpoint security across 100 devices, led penetration testing remediation.
  • Founded and chaired the monthly technology steering committee owning all technology decisions and spend.
  • Ran refresh, renewal and hardening cycles for three years past the build as the threat picture changed.
  • Built and documented the environment to a standard that survived transition to an outside provider.

Director of Information Technology

June 2014 - July 2019
Merchant Lynx Services / Annapolis, MD
  • Built and ran the company technology environment for five years inside a $500K-a-year estate.
  • Led the first PCI DSS Level 1 service provider certification from no compliance program on arrival, then carried it through two consecutive annual assessment cycles.
  • Project managed the SOC 2 Type II certification obtained in 2016.
  • Ran DynamoDB, CloudFormation and IoT device management in production.
  • Took email incidents from several a month to effectively none and held that year over year.
  • Built the internal help desk and promoted an engineer to help desk manager over a team of 5.
  • Carried growth from 75 to 150 users and 6 to 8 operating sites between 2015 and 2017.

Network Administrator / IT Consultant

2013 - 2014
Quality Computer Services / Blawnox, PA
  • Supported a 300+ client SMB base and completed 60+ router, firewall and switch installations.
  • Deployed mobile workstations for support engineers across the client base.

IT Consultant / Network Administrator

2013
Houk Consulting LLC / Pittsburgh, PA
  • Ran IT across 40+ client environments as an embedded consultant.
  • Launched warehouse infrastructure for the firm's largest client.

System Administrator / Technical Instructor

2011 - 2013
DCI Career Institute / Monaca, PA
  • Ran network operations across two campuses and built a secure cross-campus VPN.
  • Top technical instructor for A+, Network+, server administration and networking.
Credentials & capability

On file.

Education & certification

  • Project Management Professional (PMP) PMI
  • CISM In progress
  • BS, Computer Science and Networking DCI Career Institute

Programs led

  • PCI DSS Level 1 service provider Certified
  • SOC 2 Type II 2016
  • NIST 800-171 Applied
Security & incident
Incident CommandIncident ResponsePlaybook LibraryFMEA ProgramSentinelOne EDRDatadogGuardDutyWordfencePenetration TestingVulnerability RemediationPhishing SimulationSecurity Awareness TrainingRisk Management
Identity & endpoint
IAMSSO / MFA / TOTPSCIMIdentity LifecycleSSH Key LifecycleQuarterly Access ReviewMDMEndpoint SecurityOktaJumpCloudActive DirectoryWindows / macOS / Linux
Cloud, data & DevOps
AWSAzureCloudFormationRDSDynamoDBMicrosoft SQL ServerSQL / NoSQLKinstaPythonPython RunbooksPowerShellGitLab / GitHubRelease ManagementStaged Rollout & Verification GatesCloud Security Posture
AI engineering
Production AI AgentsAI GovernanceVoice AI DeliveryAI-Augmented DevelopmentAI-Assisted Incident InvestigationCursorZapier
Leadership & commercial
Technology BudgetSpend Approval AuthorityBuild vs BuyVendor ManagementVendor & Third-Party RiskAsset LifecycleSteering CommitteesQuarterly Planning & OKRsExecutive ReportingPolicy AuthorshipService Desk OwnershipITSM / ITILSLA DeliveryChange ManagementDistributed TeamsHiring & Development
Open to CIO, CTO and Director-level roles

Somebody has to own it. That has been me, three times.

Based in Greater Pittsburgh, PA and working remotely. Open to IT, security, technology operations and DevOps leadership across industries where the data matters and the function needs building or rebuilding.

Open to new roles