MARK HITCHCOCK
000
IT, Security & DevOps / Greater Pittsburgh, PA / Remote

Growing company. High-stakes data. No real IT function.

Three industries, one problem. Built the function from nothing twice and stayed to run each: five years at a multi-site card processor, then nearly five years as a legal services nonprofit's sole IT professional. Today that scope is IT, security and DevOps for 300 employees and a 1,400+ site production fleet.

Mark Hitchcock
Mark HitchcockDirector of Information Technology
0
Years in technology
0
Sites in the fleet
0
Outbreak containment
0
Annual SaaS spend cut
0
Hires since 2019
The through-line

Three industries. One problem.

Card processing, legal services and marketing technology look nothing alike from the outside. From the inside they arrived the same way: growing fast, sitting on data that could not afford a bad day, and running without anybody who owned the technology end to end. Twice the function did not exist at all and had to be built from nothing, and both times the job carried on for years after the build.

01 / 2014-2019

Payments

Merchant Lynx Services

Arrived at a multi-site card processor with no compliance program in place. Built and ran the company technology environment for five years inside a $500K-a-year estate.

Led the first PCI DSS Level 1 service provider certification and project managed the SOC 2 Type II obtained in 2016. Carried growth from 75 to 150 users and 6 to 8 operating sites.

02 / 2019-2024

Legal services

Neighborhood Legal Services

First technology leader the organization ever had. Ran the entire IT function single-handed for 150 employees, 250 endpoints and 100 tickets a month.

Built its first security architecture and access controls, led a full on-premise to cloud migration, and cut operating cost from about $500K to $420K. Documented the environment to a standard that survived transition to an outside provider.

03 / 2024-Present

Marketing technology

MyAdvice

Own IT, security and DevOps for 300 employees, 354 managed endpoints and a 1,400+ site client hosting fleet at a $15M+ revenue company.

Hold final architecture authority for the fleet security and operations tooling layer, approve about $1M in annual technology spend, and lead four engineers across the US and India.

Signature work

Incident command, played back.

Every square below is one site in the production fleet. In one incident, 130 of them were hit at once. What follows is how that ran and what got built afterward so it did not run twice.

Phase
T+0 / Detection
Healthy site Affected Contained
Fleet map of 1,400 sites with 130 affected sites highlighted

130 sites, surfaced at once.

A malware outbreak hit 130 sites inside the fleet. Detection ran off a malware signature list built from our own incident forensics rather than vendor defaults, so the sweep matched what was actually running in the environment. Fleet malware remediation itself runs through one of three AI agents shipped into production.

130
Sites affected
1,400+
Sites in the fleet
3
AI agents in production, one covering fleet malware remediation

The operating surface

What actually sits under me.

Corporate IT, the security program and the DevOps layer, plus the budget that funds all three. Final architecture authority for the fleet security and operations tooling layer sits here too.

01

Fleet & security

  • Final architecture authority for the fleet security and operations tooling layer
  • Incident command with a 7 playbook library and an FMEA program driving preventive fixes
  • Forensics-led malware signatures, SentinelOne EDR, Datadog and GuardDuty
  • Weekly security posture reporting on remediation, exposure and repeat incidents
02

Identity & endpoint

  • IAM, SSO, MFA, TOTP and SCIM across JumpCloud and Google Workspace
  • Quarterly access reviews across identity and endpoints
  • 354 managed endpoints owned end to end alongside identity
  • SSH key lifecycle and rotation tracking on the fleet management plane
03

DevOps & AI

  • 3 AI agents shipped into production covering DevOps runbooks, fleet malware remediation and triage
  • Voice AI platform delivered from the PM seat, now live with close to 500 users
  • Python runbooks with staged rollout and verification gates on every release
  • Fleet security platform built in-house for $10K to $15K against a $37K vendor quote
04

Budget & vendors

  • Approval authority over about $1M in annual technology spend
  • License management, SaaS cost reduction and vendor strategy
  • Build vs buy called on evidence, not preference
  • Vendor risk, third-party risk and hardware asset lifecycle
05

Service desk

  • Zendesk service desk built from zero, now 150 to 300 tickets a month
  • 99 percent positive across more than 1,000 responses in under two years
  • ITSM and ITIL practice with SLA delivery and change management
  • Service desk ownership across 300 employees
06

Governance

  • AI licensing and acceptable use policy authored for 300 employees
  • Quarterly technology priorities set against security risk, client impact and cost
  • PCI DSS Level 1 and NIST 800-171 program experience
  • Security awareness training and phishing simulation programs
Decisions on the record

Money moved, time returned.

Owning the budget only matters if the number changes. Each of these was a call made, funded and measured afterward.

Custom security platform quoted by a vendorBuilt the equivalent in-house on Python and vendor APIs
$37K quote
$10-15K built
Annual SaaS spend across Zendesk, Google Workspace, AI licensing, Planhat and JumpCloudConsolidated and renegotiated
Baseline
$150K+ cut a year
Operating cost at Neighborhood Legal Services$40K workflow automation, $35K VoIP, $5K ticketing
~$500K
~$420K
Security emphasis after an external assessment returned 24 findings with a Critical overall ratingPriorities reset against security risk, client impact and cost
WordPress
AWS
Experience

Eighteen years, front to back.

Director of Information Technology

Oct 2024 - Present
MyAdvice / Salt Lake City, UT (Remote)
  • Own IT, security and DevOps for 300 employees, 354 managed endpoints and a 1,400+ site client hosting fleet serving 800 to 1,000 accounts.
  • Approve about $1M in annual technology spend at a $15M+ revenue marketing technology company.
  • Hold final architecture authority for the security and operations tooling layer of the fleet.
  • Ran incident response on a 130-site malware outbreak: contained in 24 hours, remediated in 48, with no clients lost and no credits.
  • Closed an AWS IAM compromise behind about 620,000 unauthorized calls at zero net cost after a full vendor refund.
  • Shipped 3 AI agents into production covering DevOps runbooks, fleet malware remediation and triage.
  • Delivered a voice AI platform now live with close to 500 users as PM across development and systems.
  • Designed and ran a four-wave plugin vulnerability remediation release with a Python runbook, staged rollout and verification gates.
  • Rejected a $37K custom security platform and built the equivalent in-house on Python and vendor APIs for $10K to $15K in year one.
  • Cut over $150K a year from SaaS spend across Zendesk, Google Workspace, AI licensing, Planhat and JumpCloud.
  • Built the Zendesk service desk from zero: 99 percent positive across 1,000+ responses in under two years.
  • Authored the AI licensing and acceptable use policy for 300 employees and won funding for the deployment behind it.
  • Lead 4 engineers across the US and India, all direct reports, including the lead; hired three of them.
  • Own identity and 354 endpoints across JumpCloud and Google Workspace with SSO, MFA, SCIM and quarterly access review.
  • Shifted security emphasis to AWS after an external assessment returned 24 findings with a Critical overall rating.
  • Report security posture to leadership weekly on remediation, exposure and repeat incidents.
  • Turned post-mortems into 7 incident playbooks and an FMEA program driving preventive fixes.

Director of Information Technology

Sept 2019 - May 2024
Neighborhood Legal Services / Pittsburgh, PA
  • First technology leader the organization ever had; built its first security architecture and access controls.
  • Ran the entire IT function single-handed for 150 employees, 250 endpoints and 100 tickets a month.
  • Led a full on-premise to cloud migration, replacing VoIP, ticketing and core infrastructure.
  • Cut operating cost from about $500K to $420K: $40K workflow automation, $35K VoIP, $5K ticketing.
  • Ran Microsoft 365, Active Directory, Okta, Azure and Salesforce in production across 250 endpoints.
  • Applied NIST 800-171, ran SentinelOne endpoint security across 100 devices, led penetration testing remediation.
  • Founded and chaired the monthly technology steering committee owning all technology decisions and spend.
  • Hardened the environment for three years past the build as the threat picture changed.
  • Built and documented the environment to a standard that survived transition to an outside provider.

Director of Information Technology

June 2014 - July 2019
Merchant Lynx Services / Annapolis, MD
  • Built and ran the company technology environment for five years inside a $500K-a-year estate.
  • Led the first PCI DSS Level 1 service provider certification from no compliance program on arrival, then carried it through two consecutive annual assessment cycles.
  • Project managed the SOC 2 Type II certification obtained in 2016.
  • Ran DynamoDB, CloudFormation and IoT device management in production.
  • Took email incidents from several a month to effectively none and held that year over year.
  • Built the internal help desk and promoted an engineer to help desk manager over a team of 5.
  • Led penetration testing remediation and established backup and data integrity controls.
  • Carried growth from 75 to 150 users and 6 to 8 operating sites between 2015 and 2017.

Network Administrator / IT Consultant

2013 - 2014
Quality Computer Services / Blawnox, PA
  • Supported a 300+ client SMB base and completed 60+ router, firewall and switch installations.
  • Deployed mobile workstations for support engineers across the client base.

IT Consultant / Network Administrator

2013
Houk Consulting LLC / Pittsburgh, PA
  • Ran IT across 40+ client environments as an embedded consultant.
  • Launched warehouse infrastructure for the firm's largest client.

System Administrator / Technical Instructor

2011 - 2013
DCI Career Institute / Monaca, PA
  • Ran network operations across two campuses and built a secure cross-campus VPN.
  • Top technical instructor for A+, Network+, server administration and networking.
Credentials & capability

On file.

Mark Hitchcock

Education & certification

  • Project Management Professional (PMP) PMI
  • CISM In progress
  • BS, Computer Science and Networking DCI Career Institute

Programs led

  • PCI DSS Level 1 service provider Certified
  • SOC 2 Type II 2016
  • NIST 800-171 Applied
Security & incident
Incident CommandIncident ResponsePlaybook LibraryForensics-Led SignaturesFMEA ProgramSentinelOne EDRDatadogGuardDutyPenetration TestingVulnerability RemediationPhishing SimulationSecurity Awareness TrainingRisk Management
Identity & endpoint
IAMSSO / MFA / TOTPSCIMSSH Key LifecycleQuarterly Access ReviewMDMEndpoint SecurityOktaJumpCloudActive Directory
Cloud, data & DevOps
AWSAzureCloudFormationRDSDynamoDBSQL / NoSQLKinstaFleet OperationsProcess AutomationPythonPowerShellGitLab / GitHubRelease ManagementStaged Rollout & Verification GatesCloud Security Posture
AI engineering
Production AI AgentsAI GovernanceVoice AI DeliveryAI-Augmented DevelopmentAI-Assisted Incident InvestigationCursorZapier
Leadership & commercial
Technology BudgetSpend Approval AuthorityBuild vs BuyVendor ManagementVendor StrategyLicense ManagementIT Function BuildoutVendor & Third-Party RiskSteering CommitteesQuarterly Planning & OKRsExecutive ReportingPolicy AuthorshipService Desk OwnershipITSM / ITILSLA DeliveryChange ManagementDistributed TeamsHiring & Development
Open to CIO, CTO and Director-level roles

Somebody has to own it. Twice that meant building it first.

Based in Greater Pittsburgh, PA and working remotely. Open to IT, security, technology operations and DevOps leadership across industries where the data matters and the function needs building or rebuilding.

Open to new roles