Director IS Strategy & Advisory Services

Kaiser Permanente

Pleasanton (CA)

On-site

USD 180,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kaiser Permanente is seeking a Director to lead security strategy across IT initiatives, aligning with enterprise KPIs. The role includes workforce planning, vendor relationships, and governance to scale security operations globally.

The ideal candidate will drive cross-functional collaboration, partner with executives on risk remediation, and oversee secure delivery models across offshore, onshore, and global teams. A strong background in leadership and cybersecurity is essential.

Qualifications

  • Minimum three years informal leadership experience.
  • Minimum eight years IT or related field experience, including six years in information security.
  • Bachelor's degree in related field; Master’s preferred.

Responsibilities

  • Directs operation of multiple units and sets standards aligning with strategy.
  • Leads recruitment, staffing, and development to maintain a skilled workforce.
  • Communicates technical security findings to non-technical audiences.

Skills

Ambiguity Management
Attention to Detail
Communication
Leadership
Strategic Thinking
Team Building
Problem Solving

Education

Bachelor's degree in IT / Business / related field

Job description

Job Summary:

Key responsibilities include leading security strategy, methodologies, and standards for complex IT initiatives across multiple security domains, ensuring alignment with enterprise strategy and organizational KPIs. The Director will drive workforce planning, talent acquisition, and capability building at scale, addressing skill and knowledge gaps through talent development, managed-service partnerships, and vendor relationships. Additionally, the role involves partnering with cross-functional IT and business stakeholders, serving as an escalation point for risks and dependencies, and advising executive leadership on remediation and continuous improvement.

This director will be responsible for scaling and operating offshore, onshore, and global delivery models. The ideal candidate will have a background in global delivery operations, workforce and capacity planning, and vendor or managed-service partnerships.

  • Establish a centralized contingent workforce strategy and governance model including effective offshoring
  • Implement standardized processes for vendor selection, rate benchmarking, and contract management
  • Drive cost optimization through vendor consolidation and rate negotiations
  • Introduce reporting frameworks and dashboards for spend, performance, and utilization

This managing level position oversees the development, implementation and maintenance of assigned ITRM process and/or service portfolio by working collaboratively with leadership to develop the ITRM strategy. This role is responsible for staying current with industry trends, benchmarks, and best practices and providing guidance when difficult decisions need to be made.

Essential Responsibilities:
  • Directs the operation of multiple units and/or departments by identifying customer and operational needs; analyzing resources, costs, and forecasts and incorporating them into business plans; gaining cross-functional support for business plans and priorities; translating business strategy into actionable business requirements; obtaining and distributing resources; setting standards and measuring progress; removing obstacles that impact performance; guiding performance and developing contingency plans accordingly; and ensuring products and/or services meet customer requirements and expectations while aligning with organizational strategies.
  • Demonstrates continuous learning and maintains a highly skilled and engaged workforce by aligning resource plans with business objectives; overseeing the recruitment, selection, and development of talent; motivating teams; preparing individuals for growth opportunities and advancement; staying current with industry trends, benchmarks, and best practices; providing guidance when difficult decisions need to be made; and ensuring performance management guidelines and expectations drive business objectives and results.
  • Effectively communicates technical security findings to non-technical audiences.
  • Leads and assists in the development of project strategies, methodologies, and standard processes for moderately to highly complex IT initiatives across multiple security domains by analyzing business and technology requirements to ensure testability and traceability.
  • Reviews and signs off on project scope and approach, and partners with cross-functional IT and business stakeholders to review and approve the overall project approach.
  • Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems.
  • Serves as an escalation point on issues, dependencies, and risks related to security testing.
  • Determines if the necessary skills and knowledge required to meet ongoing and changing business demands exists across business or technical domains, and ensures skill and knowledge gaps are closed through talent development and outsourcing as appropriate.
  • Leverages partnerships between security consultants, Program/Project Managers, and other IT planning leaders to drive workforce planning efforts.
  • Approves and directs additional staff augmentation through managed service agreements as needed.
  • Oversees budgets and capital planning across departments and annual business cycle levels as appropriate.
  • Oversees the implementation of and adherence to standardized security tools, templates, and processes to support continuous process improvement across business domains.
  • Recommends and advocates for regional and national process or solution design improvements which align with sustainable best practices, and the strategic and tactical goals of the business.
  • Provides insight and guidance to ensure solutions are aligned with business strategies, operational work flow, established budgets, and vendor service level agreements.
  • Develops trends and high level themes related to lessons learned, and communicates this feedback to stakeholders, leadership, and the larger information security community.
  • Collaborates with cross-functional IT teams to gain buy-in and approval of test plans, and tracks quality metrics across testing phases (e.g., SIT, Performance, UAT, Automation, Production, Validation).
  • Ensures KPIs are defined, up-to-date, and aligned to higher level organizational KPIs.
  • Drives the development of cyber security intellectual capital by leading process or procedure improvements, consulting on brown bag training sessions, and leading the development of new training documents.
  • Directs information sharing and integration procedures across cyber security to ensure the exchange of threat intelligence and cyber security vulnerability assessment data.
  • Provides insight and influence to executive management and business leaders on how to remediate issues identified through security testing processes.
  • Reviews, evaluates, and prioritizes value gaps and opportunities for process enhancements or efficiencies.
  • Establishes a network of partnerships with technology risk teams and business stakeholders to respond to and remediate identified issues, and ensure the best approach for improving security posture.
Knowledge, Skills and Abilities: (Core)
  • Ambiguity/Uncertainty Management
  • Attention to Detail
  • Business Knowledge
  • Communication
  • Constructive Feedback
  • Critical Thinking
  • Cross-Group Collaboration
  • Decision Making
  • Dependability
  • Diversity, Equity, and Inclusion Support
  • Drives Results
  • Facilitation Skills
  • Health Care Industry
  • Influencing Others
  • Integrity
  • Leadership
  • Learning Agility
  • Organizational Savvy
  • Problem Solving
  • Short- and Long-term Learning & Recall
  • Strategic Thinking
  • Team Building
  • Teamwork
  • Topic-Specific Communication

Knowledge, Skills and Abilities: (Functional)

  • Advanced Hacking
  • Analytical Skills
  • Application Design, Architecture
  • Application Development (Web)
  • Business Case Development
  • Business Planning
  • Client Focus
  • Conflict Resolution
  • Cross Department Coordination
  • Cybersecurity Event Correlation Tools
  • Debugging and Troubleshooting
  • Delegation
  • Demonstrating Personal Flexibility
  • Financial Acumen
  • Goal Setting
  • IT Quality Assurance
  • Information Security Management
  • Innovative Mindset
  • Key Performance Indicators
  • Low-Level Programming
  • Malicious Code Analysis
  • Managing Diverse Relationships
  • Mentoring and Coaching
  • Negotiation
  • Network Security
  • Organizational Skills
  • Penetration Testing
  • Prioritization
  • Project Management
  • Project Management Tools
  • Requirements Elicitation & Analysis
  • Technical Communication
Minimum Qualifications:
  • Minimum three (3) years informal leadership experience with or without direct reports.
  • Minimum four (4) years managing operating budgets and/or project financials.
  • Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum eight (8) years experience in IT or a related field, including Minimum six (6) years in information security. Additional equivalent work experience may be substituted for the degree requirement.
Preferred Qualifications:
  • Four (4) years of work experience in a role requiring interaction with executive leadership (e.g., Vice President level and above)
  • Two (2) years experience overseeing projects or programs requiring the integration of cross-functional technology and/or business solutions.
  • Two(2) years experience in risk management, governance, or compliance.
  • Two (2) years experience in business continuity, crisis management, or disaster recovery.
  • Two (2) years experience in financial or statistical modeling (e.g., net present value, options analysis, Monte Carlo analysis, linear regression).
  • Master's degree in Business Administration, Computer Science, Social Science, Mathematics, or related field.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director, Information Security (Relocation eligible)
Senior Director, Information Security (Relocation eligible)

Solving IT • Nashville (TN)

On-site
USD 180,000 - 260,000
Director, Cyber Security
Director, Cyber Security

Ziply Fiber • Kirkland (WA)

On-site
USD 180,000 - 230,000
Medical
dental
vision
+9
Director | Information Security
Director | Information Security

hire.ventures • San Jose (CA)

On-site
USD 150,000 - 200,000
Director of Cybersecurity Consulting Delivery and Operations
Director of Cybersecurity Consulting Delivery and Operations

TekStream Solutions • Atlanta (GA)

On-site
USD 180,000 - 280,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Director IT Security
Director IT Security

84 Lumber • Eighty Four (PA)

On-site
USD 90,000 - 150,000
Director, Cyber Security Wanted!
Director, Cyber Security Wanted!

HealthCare Talent • Irvine (CA)

On-site
USD 130,000 - 160,000
Cybersecurity Engagement Director
Cybersecurity Engagement Director

XCUTIVES INC. • United States

On-site
USD 130,000 - 160,000
Senior Technical Lead/ Security Architect
Senior Technical Lead/ Security Architect

TechDigital Group • Frisco (TX)

On-site
USD 120,000 - 180,000
Group Chief Information Security Officer
Group Chief Information Security Officer

Barnes & Noble, Inc. • New York (NY)

On-site
USD 350,000 - 400,000
Employee Discount
Health Benefits
Retirement Plan