Under the direction of the Information Security Manager, act as a subject matter expert and technical leader concerning complex information security technology, topics, and issues. Responsible for technical and specialized duties in security framework, architecture design, risk management, incident management, vulnerability management, and information security programs and technology implementations, with the goal of enhancing the organization’s security posture.
Key Responsibilities
- Provide expertise in defining, evaluating, and recommending/implementing security controls and technologies to protect organizational assets.
- Lead security architecture and technology design, identify gaps, recommend enhancements, and ensure security requirements are integrated and implemented.
- Collaborate with Architecture, Infrastructure, and Technology teams to review existing architectures, identify gaps, and suggest security improvements.
- Assist in defining architectural and technology standards impacting system and data security.
- Develop, validate, maintain, and implement security policies, standards, guidelines, and procedures to ensure compliance with the Information Security Program.
- Conduct detailed risk analyses and assessments to identify, mitigate, and control risks to infrastructure, systems, and data; advocate for security and risk management with stakeholders.
- Oversee third-party evaluations to ensure their technology environments adequately protect shared data, meet security contract requirements, and are regularly audited.
- Monitor current threat trends and conduct future threat analysis to proactively design security measures against evolving threats.
Job Specifications
Typically requires:
- Bachelor’s Degree in Computer Science or related field, or equivalent experience.
- Minimum 8 years of hands-on technical experience in information security.
- Expert knowledge of security principles and technologies.
- Over 5 years of experience designing and implementing diverse security solutions across disciplines.
- Broad experience with risk and threat assessment methodologies.
- Ability to balance business needs with risk concerns and communicate effectively with leadership.
- Extensive experience with compliance standards such as HIPAA, PCI, ISO 27001.
- Proven skills in identifying and analyzing vulnerabilities, performing security testing, and remediating issues.
- Strong communication skills and ability to interpret complex issues and technologies.
- Ability to exercise discretion and independent judgment.
Additional Information
Salary Range: $84,000 - $141,750. Compensation includes potential bonuses and commissions. For more details on benefits, click here.
VSP Vision is an equal opportunity employer and maintains a drug-free workplace. We do not discriminate based on age, gender, race, religion, or other protected categories. Pre-employment drug testing is required.
Notice to Candidates: Beware of fake job offers. Click here to learn about our legitimate application process and warning signs of scams.