IT & Security Leadership  ·  Houston, TX

I design systems, then I run them.

Twenty-plus years in IT, ten of them in healthcare, including four as Chief Information Officer of a HIPAA-compliant healthcare service. I built that company’s IT and security function from nothing, scaled it 5×, and kept it audit-ready across a fully remote, regulated environment. A hands-on leader who sets the strategy and does the work.

Steve Miranda
Steve Miranda · CIO
0
Years in IT · 10 in healthcare
0
Years operating HIPAA controls
0
Scaled from 8 to 45+ orgs
0
Healthcare practices supported
What I Am

Three Roles I Play

And what an employer gets from each.

01

Architect & Operator

Infrastructure & Systems

I design the system, then I own it in production: the one who builds it, runs it, and is accountable when it has to work at 2 a.m.

“I design systems and then run them.”
02

Security & Compliance Lead

HIPAA · Governance · Risk

Seven-plus years operating HIPAA controls in production. Environments built audit-ready from day one; the same operator discipline that maps straight to SOC 2.

“Audit-ready from the beginning, not bolted on afterward.”
03

Translator

Technical Risk → Decisions

I turn technical risk and trade-offs into language leadership and stakeholders can act on.

“I make the technical legible to those who rely on it, and those who fund it.”
Selected Work

What I’ve built and run.

A few representative problems I owned end-to-end, where the judgment mattered as much as the technology.

AI Governance · HIPAA

AI in patient workflows, without the risk riding along

I put production AI voice systems (GoHighLevel, ElevenLabs) into a regulated healthcare environment, but only behind a shadow-testing methodology I designed: AI responses scored in parallel against live human calls under augmented BAAs, building a failure-case taxonomy for PHI exposure, workflow misrouting, and hallucination before anything reached a patient.

Outcome: AI as a measured augmentation layer, with the human kept in the loop.
Engineering

A leader who writes the code

I designed and developed a 1,341-line React/Babel internal analytics platform from scratch: a custom “True Answer Rate” methodology, multi-location aggregation, and AI-generated narrative reporting that adapted to real-time context.

1,341 lines · React/Babel · delivered to production
Service Desk & ITSM

Operations that run on systems

I stood up the service-desk function end-to-end: an eight-form ticketing taxonomy with SLA-driven workflows, escalation paths, and root-cause classification (preventable versus unpredictable), plus RMM and mobile-device management across a mixed Windows and Mac fleet. Blameless incident reviews turned recurring tickets into permanent fixes.

ITSM design · RMM / MDM fleet · SLA & escalation workflows
Vendor & Cost Strategy

Cost discipline that holds up

I selected, vetted, and administered the contact-center platform, then led its migration to a modern UCaaS stack. The result: recurring telephony cost cut 33%, surplus licensing eliminated, and transition terms that paid for the migration itself.

33% recurring reduction · $15,600/yr saved
Identity & Compliance

Policy author and operator of controls

Seven-plus years operating HIPAA controls in production: Microsoft 365 and Entra identity governance, organization-wide MFA, vendor BAA management, and audit-ready documentation. The same operator discipline maps directly to SOC 2.

M365 / Entra · MFA · BAA management · audit-ready
Infrastructure & Identity

HIPAA-compliant remote infrastructure

I owned, hardened, and scaled a Citrix Gateway and Windows Server environment for a fully distributed workforce, including a controlled multi-image maintenance pipeline that isolated patching and policy changes from production so the whole fleet updated with zero disruption. As Microsoft 365 Global Admin, I ran identity governance, organization-wide MFA, endpoint protection, and audit-ready documentation.

Citrix · Windows Server · Azure / M365 / Entra · zero-downtime patching
Scale

From eight client organizations to forty-five and counting.

Day One
8

client organizations, no dedicated IT function, reactive support.

Four Years Later
45+

client organizations and 100+ healthcare practices, on infrastructure built to stay audit-ready.

How I Work

Four Principles

The technology changes. These don’t.

01

Security-first, by design

I build systems to be secure and audit-ready from day one. Compliance bolted on after the fact leads to gaps that become liabilities.

02

Apply root fixes, not band-aids

When a problem recurs, I treat it as a process problem: I automate it, fix it at the root, and document it so the next person doesn’t inherit the same fire.

03

Human-centered technology

I believe AI augments people; it doesn’t replace the human in the room. The best systems make good people faster, not redundant.

04

Translate, don’t mystify

If I can’t explain the risk and the trade-off in language stakeholders can act on, I don’t understand it well enough yet.

Background

The path here.

My career in technology started in 2003 at Best Buy’s Geek Squad and continued at Circuit City, first in its flagship home audio and video department, then in Firedog, its IT services arm. When Circuit City closed its doors in 2009, I kept the clients who trusted me and went independent for three years, supporting their IT and A/V needs on my own. The entrepreneurial instinct never left; it just got sharper. Microsoft, healthcare IT, and eventually the CIO seat turned the technician into a leader. The title kept changing. The habit of being hands-on never did.

2022 – 2026

Chief Information Officer

WrightChat · Houston, TX

Built the IT and security function from zero and scaled it 5× (8 to 45+ client organizations, 100+ healthcare practices). Sole IT architect; owner of HIPAA controls; led a team of up to six across the U.S. and the Philippines.

2019 – 2022

General Manager

NETIT · Houston, TX

Architected a Citrix-based ITaaS environment from the ground up with RapidScale and ran a managed IT services practice: vendor contracting, customized cybersecurity and cloud solutions, and direct client consulting. Three years operating HIPAA controls for healthcare clients.

2016 – 2019

Founder & Principal Consultant

TopFlight IT Consulting · Houston, TX

Network architecture, Microsoft 365 migration, identity and SSO deployment, and security and compliance advisory for SMB and healthcare clients.

2014 – 2016

IT Director

Dow Healthcare, Inc. · Houston, TX

Opened four healthcare facilities from conception through launch with full HIPAA and Texas Department of Health compliant IT buildout; established a centralized data center.

2012 – 2014

Technical Support Advisor

Microsoft · Houston, TX

Enterprise help-desk support across Windows and Mac, where I learned to translate technical complexity into language anyone could act on.

2009 – 2012

Independent IT & A/V Consultant

Self-employed · Houston, TX

Retained my Circuit City client base and supported their IT and home audio/video needs independently. My first taste of running the whole thing.

2003 – 2009

Geek Squad & Firedog

Best Buy, then Circuit City · Houston, TX

Where it began: computer repair and consumer-tech support at Best Buy’s Geek Squad, then home A/V and IT services at Circuit City through its final day in 2009.

Certifications — MCSE · MCSA · CompTIA A+
Steve Miranda
Open to new roles

Let’s build something that lasts.

Available for IT & Security Director roles and fractional or contract engagements: healthcare-adjacent, or any environment where security and compliance depth matter.

LocationHouston, TX · Remote