Director of Information Security

18 Feb 2025

Vacancy expired!

Job Summary: Provides the direction for EH data and cybersecurity protection and IT governance and policies. Develops enterprise security strategy, security awareness programs, security architecture, and security incident response. Provides strategic risk guidance for IT projects, including evaluation and recommendation of technical controls. Manages, leads, and hires the IT Cyber Security team that meets the needs of a dynamic and scaling organization.The Director of Information Security will be responsible for developing, implementing, and monitoring strategic, comprehensive enterprise cybersecurity and IT risk management program. The Director, IT Security, will provide the vision and leadership necessary to manage the organization’s risk and ensure business alignment, effective governance, system and product availability, integrity, and confidentiality. This position reports to Chief Information Officer (CIO).

Essential Functions:
  • Provides the direction for EH data and cybersecurity protection and oversees Technology governance and policies.
  • Develops enterprise security strategy, security awareness programs, security architecture, and security incident response.
  • Provides strategic risk guidance for IT projects, including evaluation and recommendation of technical controls.
  • Manage, lead and hire an IT Cyber Security team that meets the needs of a dynamic and scaling organization.
  • Educates IT and organizational leaders on appropriate security risk and mitigation strategies
  • Provide strategic and tactical vision and execution focused on incident prevention, detection, and response.
  • Collaborates with the IT and enterprise compliance team and coordinates the IT component of internal and external audits and federal and state examinations to ensure security programs comply with relevant laws, regulations, and policies.
  • Develops, maintains, and publishes up-to-date security policies, standards, and guidelines. Oversees training and dissemination of security policies and practices.
  • Evaluates new cybersecurity threats and IT trends and develop adequate security controls. Oversees development of security awareness programs.
  • Develops and oversees effective disaster recovery policies and standards to align with health center business continuity management program goals. Coordinates development of implementation plans and procedures to ensure business-critical systems and services are recovered in the event of disasters or other incidents and provide direction, support, and in-house consulting in these areas.
  • Evaluates potential security breaches, coordinate response, and recommend corrective actions.
  • Supervise and develop the Information Security team in the performance of the job duties.
  • Define and report on information security metrics.
  • Provides project management and leadership to staff and external resources supporting established goals and objectives, improved efficiencies, and problem resolution.
  • Ensures accomplishment of all objectives following Hospital and IT policies, procedures, strategic direction, and regulatory standards governing the Health center.
  • Maintains current knowledge of the industry and regulatory trends and developments for enterprise technology.

Other Functions:

Provide IT leadership to the Medical Center via planning, consulting, committees, and communications.
  • Provide vision for Healthcare IT direction. Keep abreast of Health Center IT Technology changes and incorporate them into the IT plan as required.
  • Participate in the development, documentation, and update IT Strategic Plan.
  • Lead efforts to acquire new technology and upgrade and maximize existing systems.
  • Provide education and information to EH enterprise as required.
  • Act as a bridge between operations and technology to foster and facilitate enterprise-wide opportunities for improved productivity and efficiencies.

Provide business consulting and support to the organization.
  • Ensure financial (ROI) and clinical systems goals are identified, and proper analysis and metrics are in place to ensure a sound decision-making process.
  • Develop, negotiate and oversee IT contracts to ensure EH is favorably represented.
  • Provide appropriate guidance and resources to the organization and IT teams in selecting and implementing the new solution with information security considerations.
  • Ensure CIO visibility with vendors and installation teams to facilitate implementation.

Represent IT Information Security functions to the senior leadership and the enterprise
  • Develop and present executive briefing packages and presentations on EH Security assessment and updates as required.
  • Identify, track, and communicate detailed metrics indicating overall security risk factors.
  • Represent senior staff and organization internally and externally as requested.

Direct IT Departmental Operations.
  • Establish and enforce technological standards, policies, and procedures and enforce compliance concerning regulatory requirements;
  • Ensure standards, security, and policies and procedures are developed and enforced.
  • Ensure regulatory requirements and HIPAA compliance are enforced.
  • Oversee budget preparations and ensure that the department operates within the budget.
  • Oversee acquisition, installation, management, and integration of automated systems.
  • Oversee the review of departmental and staff performances to effect changes for improved service and staff job enrichment.
  • Oversee staff recruitment, retention, discipline, and training via managers.

Staff and departmental responsibilities
  • Plan, direct and coordinate the operations of the Information Technology. Manage staff for optimum performance.
  • Demonstrate service excellence behaviors in all interactions and fosters the same in staff.
  • Determine staffing requirements; recruit, hire and train new staff.
  • Supervise direct reporting staff according to the policies of the Medical Center.
  • Delegate work duties to staff.
  • Monitor, evaluate, and manage staff performance, including performance reviews.
  • Coach and discipline staff; manage internal staff relations.
  • Provide oversight and approval of departmental payroll and pay rule practices.
  • Perform other related duties as required.

Job Essentials: The ideal candidate will meet the following requirements and competencies.
  • Minimum of eight (8) years within the last four (4) years of experience in the field related to Cybersecurity.
  • Experience in establishing cybersecurity and risk metrics for reporting.
  • Strong Emotional Intelligence with demonstrated sustained leadership in a large organization involving multiple stakeholders.7.Demonstrated management skills, e.g., budget development and administration, policy development and implementation, personnel administration, and staff training and development.
  • Demonstrated ability to work with diverse people; effective oral and written communication skills.
  • The position requires the ability to represent the organization internally and externally and interact with all levels of Medical Center staff, board members, vendors, etc.
  • Excellent presentation skills.
  • Demonstrated leadership qualities.

Education Requirements:
  • Bachelor’s degree from an accredited institution, with a degree preferred in Computer Science or Information technology systems security or related field.
  • Master’s degree preferred.

Licensure, Certifications, and Registrations:
  • Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) Certification.
  • Knowledge of Information technology infrastructure library (ITIL) (certification preferred) concerning security administration and information technology governance in a multi-platform environment.

  • ID: #49284360
  • State: New Jersey Englewood 07631 Englewood USA
  • City: Englewood
  • Salary: $160,000 - $180,000
  • Job type: Permanent
  • Showed: 2023-02-18
  • Deadline: 2023-04-18
  • Category: Et cetera