Confidential mandate
Chief Information Officer — Diagnostic-Instruments Business
Planned Hiring / New
CIO mandate in Galway, Ireland · Medical Devices
Build a systematic global installed-base capability for a diagnostic-instruments business, establishing inventory, configuration and support visibility across hospital sites.
The mandate
A diagnostic-instruments business has identified a need to strengthen its installed-base management. Current records do not consistently show software build, hospital network context, remote-support method and compensating control for each active unit across the global fleet.
Field service, product engineering, cyber and quality teams are working urgently, but their information lives in different systems. Some hospitals block remote updates, distributors support units through locally arranged access and older instruments cannot accept the preferred patch without validation or performance consequences. A universal deadline would create false assurance; an open-ended exception process would leave unmanaged exposure.
The Chief Information Officer will own the information and service system that enables a defensible response and durable connected-device governance. The remit spans enterprise technology, installed-base data, identity and remote access, service platforms, incident coordination, data integration and vendor management. Product security, quality and medical functions retain independent decisions on safety, reportability and device change. The CIO makes their evidence complete, deployable and auditable.
Approximately 1,050 employees and material partners sit within the wider business and service perimeter. This planned new role is on site in Galway and reports to the Chief Executive or designated executive sponsor. The CIO must work directly with hospitals, distributors, field engineers and product teams and cannot treat the installed base as an enterprise asset register alone.
Why this seat is open
Information technology has historically supported corporate systems while connected-device and field platforms evolved through product and regional teams. The vulnerability response exposed the need for enterprise authority across the data, identity and service interfaces. The board created the CIO seat before the immediate remediation becomes another temporary reconciliation exercise.
What you will own
- Establish the authoritative installed-base record linking serial number, configuration, software, hospital, connectivity, remote access, service, vulnerability and mitigation status.
- Govern identity, privileged and vendor access across enterprise, field and remote-support environments, including time-bound approval and complete revocation.
- Lead information and service capabilities across a broader 1,050-person and partner perimeter and an annual technology investment above EUR 180 million.
- Support risk-based patch and mitigation deployment with product, quality and cyber teams, preserving validation, customer coordination, rollback and evidence.
- Replace unsafe or ungoverned remote-service methods used by distributors and legacy contracts without disrupting urgent instrument support.
- Build data integration among product lifecycle, field service, customer, complaint, cyber and regulatory systems so affected populations can be identified quickly.
- Establish service continuity and recovery for diagnostic platforms whose outage could delay laboratory results, including hospital-controlled dependencies.
- Rationalise technology vendors and applications after response stability, distinguishing legacy that carries active device obligations from avoidable duplication.
The first 12 months
- Days 1–90: Reconcile affected instrument populations, remote accounts and mitigation evidence; create an exception register with named risk owners. Support hospital communication and field deployment, disable unjustified privileged access and stabilise critical service platforms. Agree the enterprise information and connected-service architecture.
- Months 4–9: Implement installed-base integration for priority families, move remote support to controlled access and complete patch or compensating-control evidence across defined cohorts. Test recovery and rollback, strengthen distributor obligations and launch joiner, mover and leaver control for all field and external users.
- Months 10–12: Demonstrate rapid identification of a simulated affected population, reliable deployment and audit evidence across markets. Retire emergency reconciliations and unsupported access routes, publish a multi-year technology and legacy plan and establish successors across enterprise, field and data leadership.
What the board will measure
- Completeness and accuracy of installed configuration, connectivity, access and mitigation status for active instruments.
- Affected devices patched or protected within risk-approved windows, with overdue exceptions explicitly accepted and tracked.
- Reduction in unmanaged distributor, shared and privileged remote access and verified timely revocation.
- Ability to identify and contact affected hospitals and field resources promptly during a new vulnerability or product event.
- Service continuity and recovery against laboratory-impact thresholds, including customer and third-party dependencies.
- Technology spend moved from emergency reconciliation and duplicate systems towards a sustainable connected-device information model.
The person
You are a CIO, divisional CIO, connected-device information leader or senior field-technology executive with 22–28 years in medical devices, diagnostics, health technology or another regulated installed-base business. You have led technology and service response to a product vulnerability or field safety issue. You have controlled at least EUR 150 million of technology investment and served an organisation of at least 900 employees.
You understand that device cybersecurity requires product and field evidence, not only enterprise controls. You can work with serial, configuration, software, hospital, remote access and mitigation data and have governed patching where customers or validation prevented one standard route. You have replaced distributor or third-party access without losing service continuity.
Relevant backgrounds include laboratory diagnostics, imaging, monitoring, connected capital equipment or industrial control systems with regulated change. A general corporate CIO must show deep installed-product and field-service experience. A product-security specialist must show broad information, vendor, service and enterprise accountability.
The role is on site in Galway with international travel. Candidates elsewhere may qualify with relocation and current European device experience. The CIO must collaborate with independent quality and product-security leaders and resist claiming that a technology control alone resolves patient or regulatory risk.
Compensation and terms
The indicative base salary is EUR 285,000–390,000, with annual incentive and long-term participation. Measures will focus on installed-base evidence, mitigation, access control, service resilience and technology simplification. This is a permanent newly created appointment. Relocation and documented forfeited awards may be considered.
Confidentiality
The company, vulnerability, products and hospital deployments are confidential. Identifying technical detail will be shared only after fit and the required protections are established. Candidates must not query vulnerability communities, distributors or hospital contacts to infer the organisation.
Each response must contain no more than 49 words.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.