> Markdown version of [/jobs/ext/1147410-director-information-security-governance](https://www.wearedevelopers.com/jobs/ext/1147410-director-information-security-governance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director Information Security & Governance - **Company:** Duly Health And Care - **Location:** Downers Grove, IL, United States - **Experience:** Experienced - **Salary:** $140,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Cerner, Health Informatics, Cyber Security, Information Systems, Identity and Access Management, IT Management, Intrusion Detection and Prevention, Security Information and Event Management, Software Vulnerability Management, Enterprise Software Applications, Cloud Platform System, EHR Systems, Information Technology, Integration Frameworks - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b18fc0da60a64558 ## About the Role Required * 10+ years of progressive experience in information security, with at least 3 years in a leadership role managing a team. * Demonstrated expertise in GRC - including policy development, risk management, and regulatory compliance. * Deep knowledge of healthcare-specific security and privacy regulations, particularly HIPAA/HITECH. * Experience in large, complex enterprise environments; healthcare industry experience strongly preferred. * Proven ability to build trusted relationships with executive stakeholders and communicate risk in business terms. * Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent experience). Preferred: * Master's degree in a relevant discipline. * Active certifications such as CISSP, CISM, CRISC, HCISPP, or equivalent. * Hands-on experience with EHR platforms (Epic, Cerner) and their security architecture. If you are committed to putting our patients first and helping shape the future of care, you belong at Duly. ## Description Position Summary - We are seeking a dynamic and experienced Director of Cybersecurity to lead our enterprise security program and governance, risk, and compliance (GRC) function. Reporting to the CTO, this leader will be responsible for protecting the confidentiality, integrity, and availability of patient data, clinical systems, and enterprise assets across our large healthcare organization. The Director will serve as a strategic partner to clinical, operational, and IT leadership and ensuring patient/employee data and enterprise assets are effectively protected., * Lead, mentor, and develop a team of 5 security architects and specialists, fostering a culture of excellence, accountability, and continuous learning. * Define and execute the enterprise cybersecurity strategy in alignment with organizational goals and the CISO's vision. * Oversee security architecture design and review for enterprise systems, clinical applications, cloud environments, and third-party integrations. * Drive the maturation of security operations including threat detection, incident response, and vulnerability management programs. * Serve as a primary escalation point and decision-maker during significant security incidents or breaches. * Own and evolve organizations Governance, Risk & Compliance (GRC) program, ensuring alignment with HIPAA, HITECH, NIST CSF, SOC 2, and other applicable frameworks. * Lead risk assessment processes including third-party vendor risk assessments, enterprise risk registers, and ongoing risk treatment planning. * Oversee preparation for and response to regulatory audits, assessments, and examinations. * Develop, maintain, and enforce enterprise security policies, standards, and procedures. * Coordinate privacy and security initiatives in partnership with Legal, Compliance, and Privacy Office stakeholders. * Partner with clinical informatics, revenue cycle, HR, and other business units to embed security practices into workflows and new initiatives. * Present security risk posture, program metrics, and GRC status updates to executive leadership and the Board of Directors as needed. * Lead security awareness and training programs across the organization. * Evaluate and guide investment in security tooling including SIEM, EDR, CASB, DLP, identity governance, and zero trust capabilities. * Ensure robust identity and access management controls across EHR systems, cloud platforms, and enterprise applications. * Stay current on emerging threats specific to the healthcare sector (ransomware, medical device vulnerabilities, supply chain risks) and adapt program accordingly. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Bitcoin SV: The Massively Scaled Blockchain to Meet Developer Needs](https://www.wearedevelopers.com/videos/20-bitcoin-sv-the-massively-scaled-blockchain-to-meet-developer-needs) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)