The Cybersecurity Manager leads the organization’s enterprise information security program, ensuring the confidentiality, integrity, and availability of critical information assets. This role is responsible for defining and executing cybersecurity strategy, governance, risk management, and compliance initiatives aligned with regulatory requirements and organizational objectives. Partnering closely with IT leadership, the Cybersecurity Manager drives the development and maturity of security frameworks, policies, and incident response capabilities while embedding security into all technology operations and business processes. This role serves as the primary authority on cybersecurity risk and controls, providing oversight, guidance, and approval for security decisions across systems, networks, and cloud environments.
About the Role
Receives general supervision from the IT Director and other members of the IT Department. The Position and Job Summary (These are examples of the types of duties that may be performed. Additional duties may be added, and some tasks will be completed as needed.)
Responsibilities
- Cybersecurity Strategy & Program Leadership
- Lead and evolve the enterprise cybersecurity program aligned with business goals and risk tolerance
- Develop and manage a multi-year cybersecurity roadmap with measurable outcomes
- Report cybersecurity posture, risks, and maturity to executive leadership
- Establish KPIs/KRIs to track program effectiveness
- Governance, Risk & Compliance (GRC)
- Own and maintain the Information Security Management System (ISMS) aligned with ISO 27001
- Lead ISO 27001 certification readiness, audits, and continuous improvement
- Oversee HITRUST and HIPAA compliance, ensuring audit readiness and control effectiveness
- Conduct enterprise risk assessments and manage remediation lifecycle
- Develop and enforce security policies, standards, and procedures
- Security Architecture & Microsoft Security Ecosystem
- Drive improvements in Microsoft Secure Score and security posture
- Oversee security across:
- Endpoint (Defender)
- Cloud Security (Azure Security)
- Govern Microsoft Purview for data protection, DLP, and compliance
- Security Operations & Incident Management
- Provide oversight for:
- Vulnerability management
- Threat detection and monitoring
- Incident response and escalation
- Lead incident investigations and root cause analysis (RCA)
- Ensure security is integrated into:
- Change management
- Infrastructure standards
- Manage third‑party cybersecurity risk assessments
- Lead external audits, penetration testing, and compliance reviews
- Act as the primary liaison for auditors, regulators, and stakeholders
- Coordinate remediation across business and IT teams
- Leadership & Organizational Enablement
- Lead, mentor, and develop cybersecurity team members
- Drive security awareness and training programs across the organization
- Support budgeting, vendor selection, and strategic investments
- Foster a culture of security accountability
Qualifications
- Education & Experience
- Bachelor’s degree in IT, Computer Science, or related field
- 7+ years in cybersecurity, risk, or information security (healthcare preferred)
- 4+ years of leadership experience managing teams and programs
- 5+ years of hands‑on HIPAA compliance experience
A valid California Driver's License and transportation, or acceptable substitute, may be required based on assigned duties.
Required Skills
- Executive-level communication and stakeholder engagement
- Strategic thinking and risk-based decision making
- Deep understanding of regulatory environments (HIPAA, HITRUST, ISO)
- Strong leadership and cross‑functional collaboration
- Ability to translate technical risk into business impact
Preferred Skills
- CISSP, CISM, CRISC, HCISPP
- Microsoft Azure / Security certifications
Pay range and compensation package $133,000.14 - $168,000.00
Equal Opportunity Statement
We are committed to diversity and inclusivity in our hiring practices.