We are seeking a Manager of Information Security to lead and build an enterprise-wide security program for a growing healthcare organization. Reporting directly to the VP of IT and Cybersecurity, this individual will play a pivotal role in shaping the organization's security strategy, governance framework, and long-term security roadmap.
This is a unique opportunity for a security leader who enjoys building programs from the ground up. You will establish policies, standards, controls, and processes that strengthen the organization's security posture while supporting regulatory compliance and business growth. As the security function expands, this role offers a clear path toward future leadership advancement.
Key Responsibilities
- Develop and lead the organization's information security strategy, policies, standards, and multi-year roadmap.
- Drive security governance initiatives, including HIPAA compliance, HITRUST certification readiness, and ongoing control framework management.
- Oversee identity and access governance programs, including privileged access management, access reviews, and access control standards.
- Manage third-party and vendor security risk assessments and establish security requirements for business partners.
- Own the incident response program, including escalation procedures, response coordination, post-incident reviews, and partnership with managed detection and response providers.
- Design and deliver security awareness and training initiatives for a distributed, multinational workforce.
- Collaborate with Legal, Compliance, and business leaders to address regulatory requirements, security risks, and policy decisions.
- Build and lead the future information security team, including defining organizational structure, hiring talent, and establishing operational processes.
Key Requirements
- 5+ years of information security experience, including at least 2 years leading a security program, function, or team.
- Demonstrated experience within healthcare, pharmacy, or similarly regulated industries governed by HIPAA or comparable regulatory standards.
- Hands-on experience with HITRUST, HIPAA Security Rule, SOC 2, NIST Cybersecurity Framework (NIST CSF), or related compliance and governance programs; HITRUST r2 experience strongly preferred.
- Strong expertise within Microsoft and Azure environments, including Entra ID, Conditional Access, Privileged Identity Management (PIM), Microsoft Defender, and Microsoft Purview.
- Experience developing security policies, standards, risk assessments, governance processes, and executive-level reporting.
- Proven ability to manage incident response programs, vendor risk management, and security awareness initiatives.
- Strong communication and relationship-building skills with the ability to partner effectively across IT, Legal, Compliance, and executive leadership teams.
- Sound business judgment, strategic thinking, and the ability to communicate complex security risks to both technical and non-technical audiences.
Preferred Qualifications
- CISSP, CISM, CCSP, HITRUST CCSFP, or similar security certification.
- Experience supporting organizations backed by private equity or navigating periods of rapid organizational growth.
- Experience working with offshore or nearshore teams and distributed global workforces.
- Previous background in security engineering, infrastructure, or cloud security before transitioning into leadership.