JOB DESCRIPTION IT MANAGER
Position Details
Department: Functional Teams Location: Mumbai Employment Type: Full-time Experience Required: 8–10 years Reporting To: Project Head
1. Role Summary
Leads the IT strategy, governance and compliance, day-to-day technology operations of the organisation, overseeing healthcare applications, system integrations, infrastructure, cybersecurity, data protection, business continuity, up-to-date healthcare regulatory information, updated technology, IT Services vendors and IT teams.
The role is accountable for secure, reliable, scalable and cost-effective technology services supporting clinical, operational, research and business requirements, adhering to the Healthcare Regulatory Framework.
2. Key Responsibilities
IT Strategy & Governance
- Develop and maintain the IT roadmap aligned with organisational, clinical, operational and business priorities.
- Establish IT policies, standards, SOPs, architecture principles, governance forums and technology decision processes.
- Maintain an IT risk register and report technology performance, risks, dependencies and improvement plans to management.
- Ensure technology decisions consider scalability, security, interoperability, maintainability, total cost of ownership and adherence to the Regulatory Framework.
Healthcare Applications & Application Portfolio
- Oversee HIS, LIS, OMS, patient, clinic and other healthcare applications and platforms.
- Supervise IT – Infra Services, IT – Mobile Apps and IT – Web Apps, ensuring clear ownership and service accountability.
- Maintain an application portfolio with system owners, criticality, dependencies, licences, support model and lifecycle status.
- Ensure application availability, performance, support, enhancement, release and lifecycle management.
Integration & Interoperability
- Ensure seamless integration between internal applications and external platforms.
- Govern APIs, interfaces, data flows and integration dependencies across HIS, LIS, OMS, CRM, patient, mobile and web platforms.
- Ensure integration documentation, interface ownership, monitoring, error handling and reconciliation mechanisms are maintained.
- Coordinate healthcare interoperability requirements where applicable, including HL7/FHIR/DICOM or vendor-specific interfaces.
Infrastructure, Cloud & Network
- Oversee servers, cloud services, databases, networks, endpoints, storage, connectivity and related IT infrastructure.
- Ensure capacity planning, performance monitoring, patching, asset lifecycle management and infrastructure availability.
- Review architecture for scalability, redundancy and appropriate use of cloud/on-premise infrastructure.
- Maintain infrastructure diagrams, inventories, configuration records and critical dependency documentation.
Cybersecurity, Privacy & Compliance
- Establish and monitor cybersecurity, data privacy, access-control, audit logging and security governance requirements.
- Ensure least-privilege access, privileged-access controls, periodic access reviews, MFA where appropriate, endpoint protection and secure remote access.
- Coordinate vulnerability management, patching, security incidents, remediation and periodic security assessments.
- Ensure appropriate controls for sensitive healthcare and personal data and support applicable organisational and regulatory requirements.
Backup, Business Continuity & Disaster Recovery
- Own IT backup, restore, business continuity and disaster-recovery governance.
- Define and periodically review critical-system RPO/RTO requirements with business and clinical stakeholders.
- Ensure backups are monitored, protected and periodically restored/tested.
- Conduct DR/BCP exercises for critical systems and track remediation of identified gaps.
Service Management & Incident Management
- Establish service-management processes covering incidents, service requests, problems, changes and major incidents.
- Monitor critical incidents and coordinate resolution across relevant teams and vendors.
- Ensure agreed SLAs, escalation paths, root-cause analysis and corrective/preventive actions are followed.
- Track recurring incidents and drive permanent corrective actions rather than repeated temporary fixes.
Change, Release & Project Management
- Review and approve major technology changes, integrations and production releases through controlled change management.
- Oversee technology projects from requirement definition through planning, implementation, UAT, go-live and hypercare.
- Track scope, milestones, dependencies, risks, budget, vendor deliverables and stakeholder sign-offs.
- Ensure production changes have appropriate testing, rollback/contingency plans and documentation.
Vendor, Contract & SLA Management
- Manage technology vendors, implementation partners and service-level commitments.
- Define and monitor SLAs, support obligations, escalation mechanisms, deliverables and performance reviews.
- Review contracts, renewals, licences, AMC/support agreements and vendor risks in coordination with management/procurement.
- Drive vendor accountability for unresolved incidents, project delays, security issues and quality gaps.
Budget, Asset & Cost Optimisation
- Prepare and monitor the IT operating and project technology budget.
- Track technology spend, renewals, licences, cloud consumption, support contracts and infrastructure costs.
- Identify opportunities for consolidation, automation, cloud optimisation and lifecycle-based cost reduction without compromising service or security.
- Maintain an accurate inventory of hardware, software, subscriptions and critical technology assets.
Team Leadership & Capability Development
- Lead, mentor and develop IT team members and ensure clear roles, DRIs, escalation paths and performance expectations.
- Set team objectives and review delivery against agreed KPIs.
- Build capability in cloud, cybersecurity, healthcare applications, integration, service management and emerging technologies.
- Promote documentation, knowledge sharing, cross-training and operational resilience.
Data, Reporting & Continuous Improvement
- Establish technology dashboards and management reporting for availability, incidents, security, projects, costs, vendors and risks.
- Use operational data and root-cause analysis to identify improvement opportunities.
- Drive automation and process improvement to reduce manual work, errors, downtime and recurring support effort.
- Maintain accurate IT documentation, SOPs, architecture records, asset registers and audit evidence.
3. Qualifications & Experience
- B.Tech / M.Tech in Computer Science, Information Technology or a related discipline; ITIL/PMP or relevant technology/security certifications preferred.
- 8–10 years of IT experience, with significant experience in IT management and healthcare IT implementations/operations.
- Demonstrated experience managing application, infrastructure, integration, cybersecurity and vendor functions.
- Experience managing technology projects, production environments, incidents, changes, budgets and external implementation/support partners.
- Healthcare domain exposure involving HIS/LIS/OMS, patient or clinic systems and healthcare data is strongly preferred.
- In-depth knowledge of the healthcare regulatory framework laid down by the Government of India, especially CDSCO, IMA and ABDM.
4. Technical & Functional Skills
- Healthcare IT systems, application portfolio management and system integrations.
- Enterprise architecture, cloud infrastructure, networks, databases and technology operations.
- API management and interoperability; familiarity with HL7/FHIR/DICOM and healthcare integration concepts.
- Cybersecurity, data privacy, IAM/RBAC, audit trails, vulnerability management and security incident coordination.
- Backup, disaster recovery, business continuity, monitoring and service management.
- IT governance, risk management, change/release management and project management.
- Vendor, contract, SLA, budget and cost management.
- Leadership, stakeholder management, communication, negotiation and problem-solving.
- Know‑how of CDSCO licensing pertaining to healthcare apps.
5. Performance Review Guidance
- KPIs should be measured using application/infrastructure monitoring, incident and service records, change/release records, project trackers, security records, backup/DR reports, vendor SLA reports, financial records and audit evidence.
- Critical-system KPIs should be measured separately from non-critical systems rather than using a single blended availability figure.
- For every major incident, project delay, security event or repeated service failure, the review should consider root cause, corrective action and closure effectiveness—not only the initial response time.
- KPI targets should be baselined before the performance period and adjusted only through documented management approval when scope, systems or business requirements materially change.
- Performance should consider service quality, risk reduction, business enablement, cost discipline, team capability and continuous improvement—not only ticket closure volume.
6. Key Deliverables / Management Outputs
- Annual IT strategy and technology roadmap.
- Monthly IT performance dashboard covering applications, infrastructure, incidents, security, projects, vendors, costs and risks.
- IT asset, software/licence and vendor/contract registers.
- Application and integration inventory with criticality, ownership and dependencies.
- Cybersecurity, access‑review and vulnerability‑remediation status reports.
- Backup, restore and DR test reports with action tracking.
- Project portfolio, change/release calendar and major-risk register.
- Quarterly vendor performance and SLA review.
- Annual IT budget, forecast and cost‑optimisation plan.
- Current architecture diagrams, SOPs, operational runbooks and audit evidence.
7. Role Success Definition
The IT Manager is successful when technology enables the organisation's healthcare and business operations reliably and securely; critical applications and integrations are available and monitored; cybersecurity and data‑protection risks are actively managed; infrastructure and recovery capabilities are tested; projects and changes are controlled; vendors are accountable; technology costs are governed; and the IT team operates with clear ownership, measurable service levels and continuous improvement.
8. Review Note
Source Review: The supplied JD already covered IT strategy/governance, healthcare applications, integrations, infrastructure team supervision, vendor/SLA management, availability/BCP/DR, cybersecurity, major changes/releases, critical incidents and management reporting.
The revised version expands these into measurable operational ownership and adds explicit coverage for application portfolio management, infrastructure/cloud/network operations, integration governance, service management, backup/restore testing, project governance, budget/assets, team capability, documentation and continuous improvement.