Director, Information & Cyber Security

Paycom

Southlake (TX)

On-site

USD 140,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

GI Alliance is seeking an experienced Director of Identity & Access Management to lead the strategy, governance, and operational execution of the IAM program across the enterprise. You will advance IAM modernization, including IGA, PAM, authentication technologies, and Zero Trust, partnering with executives to align identity security with business priorities.

The role requires 10+ years in governance, risk, and information security, healthcare industry experience, HIPAA knowledge, and a proven

Qualifications

  • Bachelor's degree in information security, cybersecurity, IT, or a related field.
  • 10+ years in governance, risk & compliance, information security or cybersecurity.
  • Healthcare industry experience and HIPAA knowledge are preferred.

Responsibilities

  • Lead enterprise IAM transformation programs including IGA and PAM.
  • Design, govern, and optimize IAM solutions for identity lifecycle and security.
  • Oversee audits, regulatory examinations, and remediation efforts.

Skills

Executive leadership
Identity governance
Privileged access management
Zero Trust
Strategic planning
Communication skills

Education

Bachelor's degree in Information Security / Cybersecurity / IT

Job description

GI Alliance is seeking an experienced Director of Identity & Access Management.Company Conformance StatementsIn the performance of their respective tasks and duties all employees are expected to conform to the following:Perform quality work within deadlines with or without direct supervision.Interact professionally with other employees, customers and suppliers.Work effectively as a senior contributor on all projects.Work independently while understanding the necessity for communicating and coordinating team efforts with departments and organizations.Position SummaryThe Identity and Access Management Director directs the strategy, governance, and operational execution of the enterprise Identity and Access Management (IAM) program to ensure secure, reliable, and compliant access to critical business systems, applications, and data. Leads the evolution of identity services, access governance, privileged access management, and authentication technologies to support organizational growth, regulatory requirements, and cybersecurity objectives. Partners with executive leadership, business stakeholders, infrastructure teams, application owners, and security functions to align identity capabilities with business priorities while enabling a secure and frictionless user experience. Drives the adoption of modern identity principles, including Zero Trust, automation, and cloud-based identity services, to strengthen the organization's security posture and operational efficiency.Responsibilities/Duties/Functions/Tasks:Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.Key ResponsibilitiesLead enterprise-scale Identity Access Management (IAM) transformation programs, providing strategic direction for Identity Governance Administration (IGA) and Privileged Access Management (PAM) initiatives across complex client environmentsOversee the design, architecture, and governance of IAM solutions leveraging Identity technologies to address identity lifecycle management, privileged access controls, compliance, and security requirementsServe as the executive technical advisor and escalation point for complex identity governance, privileged access, application onboarding, and modernization challenges, driving successful outcomes and mitigating security and operational risksLead and mentor cross-functional teams of technical specialists while fostering delivery excellence, innovation, and growth across IAM programsPartner with executive stakeholders, security leaders, application owners, and business executives to develop IAM roadmaps, align identity security strategies with business objectives, and establish leading practices for governance and risk managementSupport business development efforts through solution development, proposal creation, thought leadership, and identification of opportunities to expand identity security, governance, and privileged access services within existing and prospective accountsAct with integrity, professionalism, and personal responsibility to uphold a respectful and courteous work environmentEstablish IAM frameworks, security policies, standards, and procedures aligned with organizational objectives.Regulatory ComplianceLead compliance initiatives as they relate to IMA in the context of healthcare regulations, including HIPAA Privacy, Security, and Breach Notification Rules.Ensure IAM compliance with applicable federal, state, and industry regulations affecting healthcare organizations.Participate in internal and external compliance audits.Participate in regulatory examinations and respond to audit findings.Monitor regulatory changes and assess organizational impact.Security Frameworks & ControlsDevelop and maintain security controls aligned with:NIST Cybersecurity Framework (CSF)NIST SP 800-53NIST SP 800-171SOC 2 Trust Services CriteriaSarbanes-Oxley (SOX) IT General Controls (ITGCs)Evaluate control effectiveness and recommend improvements in the context of IAMPartner with IT and Security teams to ensure technical controls support regulatory and business requirements.Audit & AssuranceParticipate and assist TSA GRC in internal and external audits including HIPAA, SOC 2, SOX, and customer security assessments.Track remediation efforts through completion.QualificationsBachelor's degree in Information Security, Cybersecurity, Information Technology, Business, Risk Management, Healthcare Administration, or a related field.10+ years of progressive experience in Governance, Risk & Compliance, Information Security, Internal Audit, or Cybersecurity.5+ years of leadership experience managing GRC, Compliance, Risk, or Security teams.Experience within the healthcare, medical device, healthcare technology, payer, provider, or life sciences industry.Demonstrated experience leading enterprise compliance and risk management programs.Candidates must possess strong working knowledge of:HIPAA Privacy Rule, Security Rule, and Breach Notification RuleNIST Cybersecurity Framework (CSF)NIST Special Publication 800-53SOC 2 Trust Services Criteria and audit readinessSarbanes-Oxley (SOX), including IT General Controls (ITGCs)Security governance and policy developmentAudit management and regulatory examinationsIncident response governancePreferred QualificationsMaster's degree in Cybersecurity, Information Systems, Business Administration, Healthcare Administration, or related discipline.Professional certifications such as:Certified Information Systems Security Professional (CISSP)Certified Information Security Manager (CISM)Certified in Risk and Information Systems Control (CRISC)Certified Information Systems Auditor (CISA)Certified in Healthcare Privacy and Security (CHPS)Healthcare Information Security and Privacy Practitioner (HCISPP)Key CompetenciesExecutive communication and presentation skillsStrategic leadershipRegulatory interpretation and implementationEnterprise risk managementAnalytical problem-solvingCross-functional collaborationProgram and project managementAudit readiness and remediationPolicy development and governanceChange managementEquipment Operated: This role routinely uses standard office equipment such as computers, phones, and fax machines.Work Environment: This job operates in professional office environments.Physical Requirements: While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to finger, handle, or feel objects, tools or controls; reach with hands and arms; climb stairs; balance; stoop, kneel, crouch or crawl; talk or hear; and taste or smell. The employee must occasionally lift or move up to 50 pounds. Specific vision abilities required by the job include close vision, distance vision, color vision, peripheral vision, depth perception and the ability to adjust focus.QualificationsEducation/Experience:Bachelor s degree in computer science or other technical/scientific discipline.10+ years related work including 5+ years as in security.2+ years in a dedicated information security role at a senior level including cybersecurity experience specializing in enterprise security optimizationKnowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST.CISSP or equivalent certification required.Essential Skills and Experience:Leadership: a demonstrated ability to lead people and get results through others.Strategy and planning: an ability to think ahead and plan over a 12-24 month time span.Demonstrated understanding of Information Security best practices.Problem analysis and problem resolution at both a strategic and functional level.Experience in developing and deploying security specific solutions including the automation of repeatable security tasks and controlsExperience with security vulnerability and penetration tools, remediation, and processes.Strong customer orientation.Must be willing to travelPerformance Requirements:Excellent communication skills, both written and verbal.Proficient technical (computer) skills.Ability to multi-task and prioritize.Self-motivated with initiative.Strong sense of ethics.Ability to manage conflict and resolve problems.Equipment Operated: This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.Work Environment: This job operates in professional office environments.Physical Requirements: While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to finger, handle, or feel objects, tools or controls; reach with hands and arms; climb stairs; balance; stoop, kneel, crouch or crawl; talk or hear; and taste or smell. The employee must occasionally lift or move up to 30 pounds. Specific vision abilities required by the job include close vision, distance vision, color vision, peripheral vision, depth perception and the ability to adjust focus.GI Alliance is an Equal Opportunity Employer. We are committed to creating an inclusive, welcoming, and equitable work environment. Our company values and celebrates the diversity of our physicians, staff and patients. We firmly believe our service is greatly enriched by our diversity of thought, experience, perspective, culture, and background.Please Note: All job offers are contingent on the successful completion of pre-employment criminal history check.NOTE: ALL APPLICATIONS MUST BE COMPLETED IN FULL FOR CONSIDERATION.No phone calls or agencies, please.EEO/AA-M/F/disabled/protected veteran
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Information & Cyber Security (32561)
Director, Information & Cyber Security (32561)

GI Alliance • Southlake (TX)

On-site
USD 180,000 - 260,000
Information Security Manager
Information Security Manager

Team Select Home Care • Phoenix (AZ)

Hybrid
USD 120,000
Medical, Dental, and Vision Insurance
Paid Time Off and Paid Sick Time
401(k)
+1
Manager Information Security and Risk Management – Enterprise Data Security
Manager Information Security and Risk Management – Enterprise Data Security

Highmark Health • Richmond (VA)

On-site
USD 129,000 - 215,000
Manager Information Security and Risk Management – Enterprise Data Security
Manager Information Security and Risk Management – Enterprise Data Security

Highmark Health • Columbus (OH)

On-site
USD 129,000 - 215,000
Manager Information Security and Risk Management – Enterprise Data Security
Manager Information Security and Risk Management – Enterprise Data Security

Highmark Health • Jackson (MS)

On-site
USD 129,000 - 215,000
Director, IAM - Global Industrial
Director, IAM - Global Industrial

Motion Industries (MOT) • Alabama

On-site
USD 170,000 - 210,000
Healthcare coverage
401(k) plan
Tuition reimbursement
Director, Cyber Defense
Director, Cyber Defense

Genuine-Parts-Company • Atlanta (GA)

On-site
USD 180,000 - 240,000
Cybersecurity Engineer
Cybersecurity Engineer

SSA Marine • Seattle (WA)

Hybrid
USD 130,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+11
Executive Director, Governance Risk & Compliance
Executive Director, Governance Risk & Compliance

HCSC Group • Town of Texas (WI)

Hybrid
USD 178,000 - 330,000
Senior Manager, IAM Cloud
Senior Manager, IAM Cloud

F-Prime Capital • United States

On-site
USD 186,000 - 202,000
Remote work