Skip to main content
JobDescription.orgSearch

Information Technology

IT Director Job Description

An IT Director is the senior manager who runs an organization's technology function, or a large slice of it such as infrastructure, applications or support, and answers to a CIO, CFO or chief executive. The job covers budgets, staffing, vendor contracts, service levels and the security program, and it turns business plans into a working technology roadmap. BLS counts IT directors within Computer and Information Systems Managers, an occupation whose median annual wage was $175,140 in May 2025, with the 10th percentile at $107,550 and the 90th percentile at $297,510.

Last updated

Role at a glance

Typical education
A bachelor's degree in computing, information systems or engineering; some employers prefer a graduate degree.
Typical experience
Five or more years in related IT work, and usually many years in total before a director title.
Key certifications
ITIL 4 Foundation (PeopleCert), PMP (PMI), CISSP (ISC2), CISM and CGEIT (ISACA).
Top employer types
Computer systems design firms, finance and insurance, the information sector, corporate headquarters and manufacturers.
Growth outlook
BLS projects 16 percent growth for computer and information systems managers from 2025 to 2035.
AI impact (through 2030)
Directors are expected to select, secure and govern AI tools and to show what they deliver for the business.

Duties and responsibilities

  • Build and maintain the multi-year technology roadmap, tying infrastructure, application and security investments to the organization's operating plan and priorities.
  • Prepare and defend the annual IT operating and capital budget, then track spending against it and explain variances to finance leadership.
  • Hire, coach and evaluate the managers who run infrastructure, service desk, applications and security, and set clear goals for each team.
  • Own the cybersecurity program's governance, including risk assessments, policy approval, incident response readiness and reporting to executives and the board.
  • Negotiate and manage contracts with software vendors, cloud providers and managed service firms, holding each to measurable service levels and renewal terms.
  • Run the intake and prioritization process for technology requests so business units see a transparent queue and a defensible reason for each decision.
  • Set standards for identity and access management, endpoint management and data backup across on-premises systems and cloud tenants such as Microsoft 365.
  • Direct disaster recovery and business continuity planning, schedule recovery tests, and close the gaps those tests expose before an actual outage arrives.
  • Establish rules for how staff may use generative AI tools, including approved products, data handling limits, review steps and an inventory of use cases.
  • Report operating metrics such as uptime, incident resolution time, change success rate and project delivery status to senior leadership on a fixed cadence.

Overview

An IT Director is accountable for whether the organization's technology works, what it costs and how exposed it leaves the business. In a mid-size company that usually means the whole department: networks, servers and cloud tenants, the service desk, business applications, and security. In a large enterprise the title may cover a single domain, and BLS describes the same split: some managers oversee an entire IT department, while others handle a particular area such as infrastructure, support services or cybersecurity.

The daily work is management, not engineering. O*NET's task list for the occupation reads like a director's calendar: review project plans, assign and review the work of analysts and programmers, and meet with department heads, managers, vendors and others to solicit cooperation and resolve problems. A typical week mixes a budget review with finance, a renewal call with a SaaS vendor, a root-cause meeting on Saturday's storage failure and a one-on-one with a manager whose team is behind on a migration.

Intake and prioritization are a standing part of the job, and a political one. Every business unit arrives with a project it considers urgent, and the director runs the steering process that ranks them against a fixed budget and a finite team. Doing that well means publishing the criteria, showing the queue and giving a reason when the answer is no. Doing it badly turns IT into the department everyone routes around, which is one way unmanaged software and shadow cloud accounts appear.

Security governance sits squarely on the director's desk. Controls such as multifactor authentication, endpoint detection, patching cadence and privileged access review are delegated to engineers, but the director owns the risk register, the incident response plan and the explanation to executives of what residual risk remains and what it would cost to reduce. At public companies that explanation feeds formal disclosure, so it has to be accurate and documented.

Vendor management is a core skill rather than a side task. Enterprise agreements for productivity suites, ERP, ITSM platforms like ServiceNow and cloud commitments with AWS, Microsoft Azure or Google Cloud lock in costs for years. The director reads the contracts, tracks license consumption, benchmarks renewals and decides when a managed service provider is cheaper than an internal team.

Then there is AI. Directors are the people who decide which assistants employees may use, which data those tools may see, how output gets reviewed and how to measure whether any of it saved time or money. That job sits alongside, not instead of, keeping email, identity and the network running, and the same director is on the hook when either one fails.

Qualifications

Education. BLS lists a bachelor's degree as the typical entry-level education, usually in computing, information systems, engineering or a similar discipline. Some employers require or prefer a graduate degree in computer science, information technology or business administration. As guidance, the degree opens the door; the track record gets the offer.

Experience. BLS puts work experience in a related occupation at 5 years or more for the occupation as a whole, and it notes that directors and other senior-level managers usually need many years in the field. A practical path looks like this: systems administrator, network engineer, developer or business analyst; then team lead; then IT manager with direct reports; then director. Along the way, aim to collect three things hiring committees look for in a director's record:

  • Ownership of a real budget, including a capital project, rather than just input into one
  • A finished, cross-functional project such as an ERP rollout, a data center exit or a cloud migration
  • Experience presenting risk and investment cases to executives who do not share your vocabulary

Certifications. None is legally required. Pick them to fill gaps:

  • ITIL 4 Foundation (PeopleCert) for service management vocabulary and process design
  • Project Management Professional, PMP (Project Management Institute) for delivery credibility
  • CISSP (ISC2) or CISM (ISACA) if security reports to you
  • CGEIT (ISACA) for enterprise IT governance work

Technical fluency. A director does not configure firewalls, but should be able to challenge an architecture proposal. The working list:

  • Cloud platforms (AWS, Azure, Google Cloud) at the level of cost management, landing zones and shared responsibility
  • Identity: Microsoft Entra ID or Okta, single sign-on, conditional access, privileged access management
  • ITSM: incident, problem and change management, usually on ServiceNow, Jira Service Management or a similar platform
  • Frameworks: the NIST Cybersecurity Framework and, where AI is in play, the NIST AI Risk Management Framework
  • Networking basics: SD-WAN, segmentation and zero trust concepts

People skills. The job rewards directors who can translate technical risk into business terms, build managers who make decisions without escalating everything, and hold a position with a vendor or a business unit leader without burning the relationship.

Career outlook

The federal projections are strong. BLS expects employment of computer and information systems managers, the occupation that includes IT directors, to grow 16 percent from 2025 to 2035, much faster than the average for all occupations. The occupation held 685,800 jobs in 2025, the projected employment change over the decade is 108,100, and BLS expects about 53,500 openings each year on average, many of them from people who retire or move to other occupations. BLS attributes the demand to organizations building out cloud computing, cybersecurity, digital platforms and artificial intelligence.

Computer and information systems managers work in many different industries. By BLS count, computer systems design and related services employed 19% of these managers, finance and insurance 13%, the information sector 13%, management of companies and enterprises 10% and manufacturing 6%. That breadth matters for career planning: a director who has run IT for a hospital system, a manufacturer and a software firm has seen three very different risk profiles and budgets.

At public companies, securities regulation reaches directly into the director's work. On July 26, 2023, the SEC adopted rules requiring public companies to disclose material cybersecurity incidents on Item 1.05 of Form 8-K, generally due four business days after the company determines an incident is material, and to report annually on cybersecurity risk management, strategy and governance. Directors at registrants now feed that process: incident triage has to produce a materiality record, and the security program has to be described in terms a securities lawyer will sign.

The reference frameworks have also been revised. NIST released version 2.0 of its Cybersecurity Framework on February 26, 2024, the first major update since its creation in 2014, adding a Govern function to the original five and widening the audience to all organizations, not only critical infrastructure. For AI, NIST's AI Risk Management Framework, released January 26, 2023, is intended for voluntary use, and on April 7, 2026 NIST released a concept note for a profile on trustworthy AI in critical infrastructure.

Public-sector directors have a specific mandate. OMB memorandum M-25-21, dated April 3, 2025, rescinded and replaced M-24-10 and requires federal agencies to keep updating their annual AI use case inventories and apply minimum risk management practices to what it calls high-impact AI. Agency IT leaders often help build those inventories and run the controls.

What this means for a working director: governing spending, risk and AI adoption sits alongside keeping systems running, and both get judged. A director preparing for the next role should be ready to show a security program mapped to a recognized framework, a written AI usage policy with an inventory behind it, and cloud and SaaS cost figures that finance trusts. Describing infrastructure built years ago is a weaker story than showing how today's environment is governed and paid for.

Sample cover letter

Dear Ms. Alvarez,

I am applying for the IT Director position at Harborview Regional Health. For the past six years I have led infrastructure and service delivery at Cedar Valley Medical Group, a multi-site outpatient network, and I am ready to take on the full technology function for an organization with Harborview's reach.

When I arrived at Cedar Valley, the service desk, the network team and the application analysts reported to three different executives and competed for the same budget. I consolidated them into one department with a single intake process and a published priority list. Within the first year, clinic managers stopped escalating around IT because they could see where their requests stood and why.

Security was the second priority. I led our adoption of the NIST Cybersecurity Framework, rebuilt the incident response plan with our compliance officer, and ran tabletop exercises with clinical leadership so the plan reflected how the clinics actually operate. I also moved our backup environment to immutable storage and scheduled quarterly recovery tests, which gave the board a clear answer when it asked how we would recover from ransomware.

Most recently I wrote Cedar Valley's policy for generative AI tools. We approved two assistants for administrative staff, blocked patient data from both, set a review step for anything sent to patients, and kept an inventory of every use case. It was not glamorous work, but it let people use the tools without creating a privacy problem.

I would welcome the chance to discuss how that experience fits Harborview's plans for its EHR consolidation and security program.

Sincerely, Daniel Okafor

Frequently asked questions

What does an IT Director do?
An IT Director is the senior manager who runs an organization's technology function, or a large slice of it such as infrastructure, applications or support, and answers to a CIO, CFO or chief executive. The job covers budgets, staffing, vendor contracts, service levels and the security program, and it turns business plans into a working technology roadmap. BLS counts IT directors within Computer and Information Systems Managers, an occupation whose median annual wage was $175,140 in May 2025, with the 10th percentile at $107,550 and the 90th percentile at $297,510.
What are the main duties of an IT Director?
Core duties include: build and maintain the multi-year technology roadmap, tying infrastructure, application and security investments to the organization's operating plan and priorities; prepare and defend the annual IT operating and capital budget, then track spending against it and explain variances to finance leadership; and hire, coach and evaluate the managers who run infrastructure, service desk, applications and security, and set clear goals for each team.
How is an IT Director different from a CIO?
A CIO usually sits on the executive team and owns technology strategy for the whole enterprise. An IT Director typically reports to that executive, or to the CFO, and runs a defined scope such as infrastructure, a region or a business unit. In organizations without a CIO, the IT Director can end up carrying both jobs.
What does an IT Director earn?
BLS reports a median annual wage of $175,140 for Computer and Information Systems Managers in May 2025, the occupation that includes IT directors. The 10th percentile was $107,550 and the 90th percentile was $297,510.
How is AI changing the work of an IT Director?
CIO.com's 2026 State of the CIO survey, reported on May 18, 2026, found that CEOs put researching and implementing AI at the top of their priority lists for CIOs. For an IT Director, the practical work is picking tools, writing usage rules, securing the data those tools touch and proving the business result. Federal IT leaders also work under OMB memo M-25-21, which requires the head of each agency to retain or designate a Chief AI Officer.
Which certifications help an IT Director?
Common choices are ITIL 4 Foundation from PeopleCert for service management, the Project Management Professional (PMP) from the Project Management Institute, and CISSP from ISC2 or CISM from ISACA for security oversight. ISACA's CGEIT targets enterprise IT governance specifically. None is a legal requirement, so pick the ones that match the gaps in your record.
How long does it take to become an IT Director?
BLS notes that chief technology officers, IT directors and other senior-level managers usually need many years of experience in the IT field before being considered. The usual route runs from an engineering or analyst role to team lead, then IT manager, then director. Along the way, budget ownership and a record of finished projects strengthen the case for promotion.

Sources

Salary figures and role details on this page were checked against the following sources. Dates show when each was last reviewed.

  1. Computer and Information Systems Managers, BLS Occupational Employment and Wage Statistics (May 2025)Checked Sep 27, 2026
  2. Computer and Information Systems Managers, Occupational Outlook Handbook, U.S. Bureau of Labor Statistics (2026)Checked Sep 27, 2026
  3. Computer and Information Systems Managers (11-3021.00), O*NET OnLine, U.S. Department of LaborChecked Sep 27, 2026
  4. SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, U.S. Securities and Exchange Commission (July 26, 2023)Checked Sep 27, 2026
  5. NIST Releases Version 2.0 of Landmark Cybersecurity Framework, National Institute of Standards and Technology (February 26, 2024)Checked Sep 27, 2026
  6. M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, Office of Management and Budget (April 3, 2025)Checked Sep 27, 2026
  7. AI Risk Management Framework, National Institute of Standards and Technology (2026)Checked Sep 27, 2026
  8. CEOs' top priorities for IT leaders today, CIO.com (May 18, 2026)Checked Sep 27, 2026
  9. ITIL 4 Foundation, PeopleCertChecked Sep 27, 2026
  10. CGEIT Certification, ISACAChecked Sep 27, 2026
  11. CISM Certification, ISACAChecked Sep 27, 2026
  12. CISSP Certified Information Systems Security Professional, ISC2Checked Sep 27, 2026