AVP Solutions Architecture

ScionHealth Corporate Support Center

Louisville (KY)

On-site

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ScionHealth is seeking an AVP, Information Security to lead the enterprise security program and protect clinical and corporate technology environments. You will direct security operations, threat detection, incident response, vulnerability management, IAM, HIPAA security compliance, and data governance while advising executives and building a high-performing security team.

You will collaborate with technology and clinical leaders to embed security requirements in operations and architecture,

Qualifications

  • 10+ years of progressive cybersecurity experience.
  • Experience leading a cybersecurity team of 6+ employees.
  • Experience protecting sensitive or regulated data in healthcare or multi-site organizations.
  • Experience leading HIPAA security or comparable compliance activities and audits.
  • Experience with enterprise IAM, data governance, and security service providers.

Responsibilities

  • Lead the enterprise information security program and day-to-day protection of clinical and corporate technology environments.
  • Develop and mature Security Operations Center capabilities and incident response.
  • Oversee vulnerability management, risk prioritization, and remediation tracking.
  • Maintain healthcare-focused threat intelligence and coordinate preventive actions.
  • Ensure HIPAA security compliance and regulatory audit support.
  • Partner with infrastructure and clinical teams to embed security into architecture and operations.

Skills

Security operations
SIEM
SOAR
Incident response
Vulnerability management
Threat intelligence
HIPAA security
Identity and access management
Data governance
Executive communication

Education

Bachelor’s degree in Computer Science/IT/Cybersecurity

Tools

Microsoft Defender
Microsoft Sentinel
IAM tools (Entra ID)

Job description

Description

At ScionHealth, we empower our caregivers to do what they do best. We value every voice by caring deeply for every patient and each other. We show courage by running toward the challenge and we lean into new ideas by embracing curiosity and question asking. Together, we create our culture by living our values in our day-to-day interactions with our patients and teammates.

Job Summary

The AVP, Information Security leads the enterprise information security program and the day-to-day protection of the organization's clinical and corporate technology environments. The AVP directs security operations, threat detection, incident response, vulnerability management, identity and access management, HIPAA security compliance, and data governance. This role advises executive leadership during security events, partners with technology and clinical leaders to incorporate security requirements into operations and builds a high-performing security team that protects systems, sensitive data, and protected health information.

Essential Functions
  • Directs enterprise security operations, including threat monitoring, detection, investigation, containment, recovery, and post-incident review across clinical and corporate environments.
  • Develops and matures Security Operations Center capabilities, monitoring coverage, operating procedures, escalation paths, and supporting security technologies.
  • Owns the incident response program, including playbooks, tabletop exercises, digital forensics coordination, lessons learned, and timely communication with executive and board leadership.
  • Leads the enterprise vulnerability management program, including scanning, risk-based prioritization, remediation tracking, exception management, and reporting across enterprise and clinical systems.
  • Maintains a healthcare-focused threat intelligence capability and coordinates preventive and responsive action for ransomware, phishing, business email compromise, and other sector-relevant threats.
  • Establishes enterprise identity and access management strategy and controls for authentication, single sign-on, multifactor authentication, conditional access, privileged access, and access governance.
  • Leads the HIPAA security compliance program, including security risk assessments, control documentation, policy maintenance, corrective action tracking, audit readiness, and regulatory support.
  • Establishes data governance practices for the classification, protection, retention, and lifecycle management of sensitive data and protected health information in partnership with Compliance and clinical stakeholders.
  • Partners with infrastructure, network, application, and clinical technology teams to incorporate security requirements into architecture, design, implementation, and ongoing operations.
  • Selects and oversees security technologies and service providers; manages vendor performance, contracts, service levels, and managed or co-sourced security operations relationships.
  • Builds and leads a multidisciplinary team of security professionals; establishes clear accountabilities, staffing models, on-call coverage, development plans, and performance expectations.
  • Defines and reports security metrics, key performance indicators, risk trends, and program priorities to the Chief Technology Officer / Chief Information Security Officer and executive leadership.
  • Directs security due diligence, risk assessment, and operational integration for acquisitions and newly affiliated facilities.
  • Develops and manages department priorities, budgets, resource plans, and roadmaps aligned with organizational risk and business needs.
  • Maintains current knowledge of cybersecurity threats, regulatory requirements, and industry practices and applies that knowledge to the enterprise security program.
Knowledge/Skills/Abilities/Expectations
  • Expert knowledge of security operations, Security Information and Event Management (SIEM), Security Orchestration Automation and Response (SOAR), endpoint detection and response, and structured incident response methods.
  • Advanced knowledge of vulnerability management, cyber threat intelligence, digital forensics coordination, and healthcare-targeted threats.
  • Strong knowledge of HIPAA and HITECH security requirements, security risk assessment, control documentation, policy governance, and regulatory audit support.
  • Strong knowledge of enterprise identity and access management, including Microsoft Entra ID, Privileged Identity Management, Conditional Access, multifactor authentication, and single sign-on.
  • Knowledge of data classification, protection, retention, and lifecycle management for sensitive data and protected health information.
  • Knowledge of enterprise security technologies, including Microsoft Defender, Microsoft Sentinel, email security, and vulnerability scanning platforms.
  • Ability to assess complex security risks, set priorities, make sound decisions under pressure, and direct coordinated response during active incidents.
  • Ability to translate technical risk into clear business implications and communicate effectively with executives, board members, regulators, clinicians, and technical teams.
  • Ability to lead, develop, and retain a geographically dispersed, multidisciplinary team and manage on-call and service delivery expectations.
  • Ability to build effective partnerships, manage vendors and budgets, establish measurable performance standards, and drive remediation across organizational boundaries.
Qualifications
Education
  • Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, or a related field (Preferred) Or
  • Other: An equivalent combination of relevant education and professional experience in lieu of the preferred degree (May be Considered)
Licenses/Certifications
  • Other: Current Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), or GIAC Certified Intrusion Analyst (GCIA) certification Upon Hire (Required)
  • Other: Additional relevant certification such as CISM, GCFA, OSCP, Microsoft Certified Identity and Access Administrator Associate, CDPSE, or CIPT Upon Hire (Preferred)
Experience
  • 10+ years progressive cybersecurity experience, including significant responsibility for security operations and/or incident response (Required)
  • Prior Experience leading a cybersecurity team of six (6) or more employees (Required)
  • Prior Experience protecting sensitive or regulated data in healthcare or another highly regulated, multi-site organization (Required)
  • Prior Experience leading HIPAA security or comparable compliance activities and supporting regulatory audits (Required)
  • Prior Experience with enterprise identity and access management, privileged access, data governance, security technologies, and managed or co-sourced security service providers (Required)
  • Prior Experience in a private-equity-owned, multi-site healthcare organization and with security due diligence or integration related to mergers and acquisitions (Preferred)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Cybersecurity
Manager, Cybersecurity

Central Ohio Primary Care Physicians, Inc. • Westerville (OH), Northern (KY)

Hybrid
USD 140,000 - 170,000
Manager, Cybersecurity
Manager, Cybersecurity

Central Ohio Primary Care Physicians,Inc • Westerville (OH)

On-site
USD 120,000 - 160,000
Manager, Cybersecurity
Manager, Cybersecurity

Central Ohio Primary Care • Westerville (OH)

On-site
USD 140,000 - 180,000
Manager of Information Security
Manager of Information Security

The Intersect Group • United States

On-site
USD 120,000 - 180,000
AVP & Security Operations Manager - Cyber Security
AVP & Security Operations Manager - Cyber Security

WesBanco Bank Inc. • Parkersburg (WV)

On-site
USD 110,000 - 160,000
AVP & Security Operations Manager - Cyber Security
AVP & Security Operations Manager - Cyber Security

WesBanco Bank Inc. • Indianapolis (IN)

On-site
USD 110,000 - 170,000
AVP & Security Operations Manager - Cyber Security
AVP & Security Operations Manager - Cyber Security

WesBanco Bank Inc. • Columbus (OH)

On-site
USD 120,000 - 160,000
AVP & Security Operations Manager - Cyber Security
AVP & Security Operations Manager - Cyber Security

WesBanco Bank Inc. • Naples (FL)

On-site
USD 95,000 - 120,000
AVP & Security Operations Manager - Cyber Security
AVP & Security Operations Manager - Cyber Security

WesBanco Bank Inc. • West Palm Beach (FL)

On-site
USD 120,000 - 170,000
AVP & Security Operations Manager - Cyber Security
AVP & Security Operations Manager - Cyber Security

WesBanco Bank Inc. • Toledo (OH)

On-site
USD 110,000 - 140,000