Manager, Cybersecurity

Central Ohio Primary Care Physicians, Inc.

Westerville, Northern (OH, KY)

Hybrid

USD 140,000 - 170,000

Full time

9 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Central Ohio Primary Care Physicians, Inc. is seeking a Manager of Cybersecurity to lead COPC’s enterprise cybersecurity program across multiple sites.

You will oversee security operations, threat detection, incident response, vulnerability management, IAM, and security awareness training, while guiding a team of analysts and engineers. You will translate risk into actionable controls, collaborate with IT, Compliance, and clinical leadership to protect patient data, support HIPAA and SOC

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or related field.
  • 5+ years of progressive experience in information security or cybersecurity roles.
  • 2+ years in a leadership, team-lead, or supervisory capacity.
  • Experience working in healthcare or another highly regulated industry.
  • Master’s degree in Cybersecurity, Information Systems, or related field (preferred).
  • Additional certifications such as CISA, CCSP, CEH, or CompTIA Security+ (preferred).

Responsibilities

  • Develop, implement, and mature COPC's cybersecurity program with policies, standards, and procedures.
  • Lead day-to-day security operations including SIEM, EDR, firewalls, and IDS/IPS.
  • Own and improve incident response plans; coordinate tabletop exercises.
  • Manage vulnerability management including scanning, patching, and remediation tracking.
  • Lead and develop a high-performing cybersecurity team with performance reviews.
  • Partner with IT, network, applications, and EHR teams to embed security in system design and cloud migrations.
  • Administer IAM controls, including privileged access management and least-privilege enforcement.
  • Oversee third-party risk assessments and BAAs; ensure security obligations are reflected in contracts.
  • Ensure HIPAA, SOC, and related regulatory compliance; support audits and inquiries.
  • Design and measure security awareness training and phishing simulations.

Skills

Leadership
Incident response
Risk management
HIPAA compliance
Security architecture
Communication

Education

Bachelor's degree in CS/IT/InfoSec
Master's degree (preferred)
Certifications (CISA/CCSP/CEH/CompTIA Security+) (preferred)

Tools

SIEM
EDR/XDR
Firewalls
IDS/IPS
Cloud security (AWS/Azure)

Job description

The Manager, Cybersecurity is responsible for leading COPC’s cybersecurity program, protecting the confidentiality, integrity, and availability of clinical, financial, and administrative systems across all COPC practice sites. This position oversees security operations, threat detection and incident response, vulnerability management, identity and access management, and security awareness training, and manages the analysts and engineers who support these functions. Using sound judgment and technical expertise, the Manager translates enterprise risk into actionable controls, partners with IT, Compliance, and clinical leadership to safeguard patient data and support HIPAA and SOC compliance, and helps mature COPC’s security posture as the organization grows. The role serves as a key escalation point during security incidents and is accountable for maintaining a defensible, well-documented cybersecurity program across a multi-site healthcare enterprise.

ESSENTIAL FUNCTIONS AND RESPONSIBILITIES
  • Develop, implement, and continuously mature COPC's cybersecurity program, including policies, standards, and procedures aligned to recognized frameworks such as NIST CSF and SOC.
  • Lead day-to-day security operations, overseeing SIEM, endpoint detection and response (EDR), firewalls, and intrusion detection/prevention systems to identify, triage, and respond to threats in real time.
  • Own and continuously improve COPC's security incident response plan; lead investigation, containment, eradication, and recovery efforts for security incidents, and coordinate tabletop exercises to validate readiness.
  • Manage the vulnerability management program, including recurring vulnerability scanning, patch prioritization, coordination of penetration testing, and tracking of remediation across servers, endpoints, network devices, and cloud environments.
  • Lead and develop a high-performing team, which includes interviewing and selection of new employees, onboarding, coaching, training, professional development, conflict resolution and disciplinary action and follow-up. Ensure completion of performance reviews and related actions for direct and indirect reports and address personnel processes/issues including conflict management, goal attainment and disciplinary action (as needed).
  • Lead and mentor Cybersecurity team members while ensuring consistency and accountability across COPC, ensuring scope, deliverables and budgets achieve expectations; foster a culture of accountability, collaboration, continuous improvement, and innovation.
  • Partner with IT infrastructure, network, applications, and EHR teams to embed security requirements into system design, cloud migrations, integrations, and new technology deployments across all COPC practice sites.
  • Administer identity and access management controls, including privileged access management, multi-factor authentication, periodic access reviews, and enforcement of least-privilege principles across clinical and business systems.
  • Own third-party and vendor risk management, including security assessments of business associates and vendors handling protected health information, and ensure Business Associate Agreements reflect appropriate security obligations.
  • Ensure ongoing compliance with HIPAA, SOC, and other applicable regulatory and payer security requirements; support internal and external security audits, risk assessments, and regulatory inquiries.
  • Design, implement, and measure the effectiveness of COPC's security awareness training while managing a regular phishing simulation program for all workforce members.
  • Partner with the CIO to manage the security tooling budget and licensing, while evaluating emerging security technologies to recommend investments that reduce organizational risk.
  • Maintain data loss prevention, encryption, and secure backup controls, and participate actively in business continuity and disaster recovery planning and testing.
  • Prepare and present security metrics, risk assessments, and program updates to IT leadership, executive stakeholders, and the Compliance Committee.
  • Serve as a subject matter expert and primary escalation point for security-related questions and incidents across the organization, including escalation of urgent matters to the CIO; provide after-hours response as needed.
  • Other duties as assigned.
QUALIFICATIONS
A. Education, Licensures, Certifications & Experience
  • Required: Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field; or equivalent combination of education and experience.
  • Required: 5+ years of progressive experience in information security or cybersecurity roles.
  • Required: 2+ years in a leadership, team-lead, or supervisory capacity.li>
  • Required: Experience working in healthcare or another highly regulated industry.
  • Preferred: Master’s degree in Cybersecurity, Information Systems, or related field.
  • Preferred: Additional certifications such as CISA, CCSP, CEH, or CompTIA Security+.
B. Knowledge, Skills & Abilities
  • Strong knowledge of security frameworks and standards such as NIST CSF, SOC, HITRUST CSF, ISO 27001, and healthcare-specific regulations including HIPAA and HITECH.
  • Hands-on experience with SIEM, EDR/XDR, firewalls, IDS/IPS, vulnerability scanning tools, and cloud security services (e.g., AWS or Azure security tooling).
  • Demonstrated experience leading incident response for security events, including forensic investigation, containment, and remediation.
  • Working knowledge of identity and access management, network security architecture, and encryption technologies.
  • Experience conducting or overseeing risk assessments, security audits, and penetration testing engagements.
  • Ability to evaluate multiple security technologies and platforms and recommend the right solution for a given risk or problem.
  • Ability to learn new technologies, threats, and business concepts quickly in a fast-evolving field.
  • Extensive knowledge of best practices regarding security policies, procedures, and controls in a healthcare environment.
  • Experience gathering, documenting, prioritizing, and tracking security requirements and remediation efforts.
  • Must recognize and evaluate problems and refer to the appropriate channels for action.
  • Strong analytical, organizational, and problem-solving skills with sound judgment under pressure.
  • Demonstrated ability to lead, mentor, and develop a technical team.
  • Translates technical risk into business terms for non-technical executive, clinical, and operational stakeholders.
  • Effective written and verbal communication skills, with a strong customer service orientation and the ability to work with stakeholders at all levels of the organization.
  • Ability to manage multiple priorities, projects, and vendors simultaneously in a fast-paced environment.
  • High degree of integrity and discretion in handling sensitive and confidential information.
  • Ability to remain current on the evolving cybersecurity threat landscape and emerging technologies, and to communicate implications to leadership.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Executive Director Cybersecurity
Executive Director Cybersecurity

The Security Executive Council • Miami (FL)

On-site
USD 100,000 - 130,000
Competitive salary
Health insurance
Professional development opportunities
Director Chief Information Security Officer
Director Chief Information Security Officer

The Security Executive Council • Montana

On-site
USD 130,000 - 180,000
Director I – Cybersecurity Operations, Incident Response
Director I – Cybersecurity Operations, Incident Response

Jobtailor • Kentucky

On-site
USD 150,000 - 210,000
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
Info Security Program Manager
Info Security Program Manager

Columbia University Irving Medical Center • New York (NY)

On-site
USD 120,000 - 145,000
Cybersecurity Specialist
Cybersecurity Specialist

PACS in • Salt Lake City (UT)

On-site
USD 80,000 - 120,000
Health coverage
Paid time off
Financial wellness (HSA/FSA)
+2
Manager – Cybersecurity Fusion Center
Manager – Cybersecurity Fusion Center

Jobtailor • West Valley City (UT)

On-site
USD 190,000 - 240,000
Cybersecurity Officer (Remote)
Cybersecurity Officer (Remote)

CloseKnit • Rockville (MD), Northern (KY)

Hybrid
USD 140,000 - 190,000