> Markdown version of [/jobs/ext/1426820-it-manager-information-technology-information-security](https://www.wearedevelopers.com/jobs/ext/1426820-it-manager-information-technology-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Manager - Information Technology & Information Security - **Company:** Pacific Health Group - **Location:** San Diego, CA, United States - **Salary:** $78,500.0 - $82,500.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing Security, Cyber Security, Data Security, Disaster Recovery, Monitoring of Systems, Identity and Access Management, Information Security Management, Phishing, Data Logging, Data Classification, Reliability of Systems, Information Technology - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=246085b06cce1db9 ## About the Role * Extensive experience in IT, cybersecurity, or information security leadership. * Demonstrated expertise in HIPAA compliance and healthcare data protection. * Strong understanding of cloud security, endpoint security, and identity management. * Experience creating policies, controls, and compliance frameworks from the ground up. * Ability to operate with high autonomy and accountability., * CISSP, CISM, or equivalent security certifications. * Prior experience in healthcare, health tech, or regulated industries. * Experience managing audits, risk assessments, and compliance programs. * Familiarity with NIST, ISO 27001, or similar security frameworks. Authority & Accountability * Authority to approve or deny technology tools, vendors, and system access. * Responsible for enforcing security policy across all departments. * Accountable for protecting company data, systems, and regulatory standing. ## Description The Manager of Information Technology & Information Security is responsible for the end-to-end ownership of all technology systems, data security, and regulatory compliance at Pacific Health Group. This role establishes, governs, and enforces the organization's security posture, ensuring that all systems, data, and operations meet or exceed HIPAA, HITECH, and industry best practices. This position functions as the single point of accountability for IT infrastructure, cybersecurity, data protection, PHI safeguards, and security governance. The role requires both strategic leadership and hands-on execution in a regulated healthcare environment. This position directly safeguards organizational integrity, regulatory standing, and operational continuity. Key ResponsibilitiesCore ResponsibilitiesInformation Security Program Ownership * Architect and maintain a formal, organization-wide Information Security Program. * Define and enforce security controls across applications, infrastructure, devices, and users. * Establish policies for data classification, encryption, access control, logging, monitoring, and retention. * Implement least-privilege access and zero-trust principles across systems. * Continuously monitor evolving threat landscapes and proactively adapt controls. HIPAA, PHI & Regulatory Compliance * Serve as the internal authority for HIPAA Security Rule and Privacy Rule compliance. * Ensure proper safeguards for the creation, storage, transmission, and disposal of PHI. * Maintain compliance documentation, risk assessments, and audit evidence. * Lead HIPAA risk analyses and remediation plans. * Oversee Business Associate Agreements (BAAs) from a security and IT standpoint. * Coordinate and support internal and external audits, assessments, and investigations. * Conduct regular testing of disaster recovery and business continuity plans. IT Infrastructure & Systems Oversight * Own the design, implementation, and maintenance of all IT systems, including cloud platforms, networks, endpoints, SaaS applications, and internal tools. * Ensure systems are secure, resilient, and scalable. * Implement and maintain backup and disaster recovery plans, business continuity procedures, and system redundancy strategies. * Approve and govern all technology deployments and architectural changes. * Oversee installation, configuration, and lifecycle management of hardware, software, and telecommunications systems. * Ensure system reliability, uptime, and performance across all departments. Cybersecurity Operations & Incident Response * Establish formal incident response plans and escalation procedures. * Lead response efforts for security incidents, attempted breaches, phishing, impersonation, or data exposure. * Conduct root cause analysis and implement corrective actions. * Ensure proper breach notification processes are followed when required by law. * Maintain logs, alerts, and monitoring systems to detect suspicious activity. Data Protection & Privacy * Define and enforce controls for sensitive data, PHI, and confidential business information. * Ensure encryption standards are applied to data at rest and in transit. * Govern data access, sharing, and retention policies. * Partner with legal and compliance stakeholders on privacy matters. * Prevent unauthorized data access, leakage, or misuse. Vendor, Tool & Third-Party Risk Management * Evaluate the security posture of third-party vendors and platforms. * Approve technology vendors based on security, compliance, and risk criteria. * Monitor ongoing vendor compliance and contractual obligations. * Ensure third-party access is controlled, monitored, and revoked as needed. Governance, Training & Enforcement * Develop and enforce IT and security policies applicable to all staff. * Deliver security awareness training, including phishing and impersonation prevention. * Ensure staff understand approved communication channels and security protocols. * Investigate and address violations of IT or security policy. * Establish clear escalation paths and disciplinary guidance related to security breaches. * Supervise IT staff, providing direction, training, and performance evaluations. Strategy, Reporting & Executive Advisory * Define a long-term IT and security roadmap aligned with business growth. * Provide regular reporting to executive leadership on security risks, compliance status, incidents, and improvement initiatives. * Advise leadership on technology risk, investments, and operational trade-offs. * Balance operational efficiency with regulatory and security requirements. Success Measures * Successful implementation and maintenance of a formal Information Security Program. * 100% compliance with HIPAA Security Rule and related regulatory requirements. * Reduced security incidents and rapid, compliant response to threats. * Completion of risk assessments, audit readiness, and remediation initiatives. * Secure, scalable IT infrastructure supporting organizational growth., Pacific Health Group is committed to maintaining a transparent, lawful, and secure hiring process in compliance with California labor laws and employment standards. Employment offers are contingent upon meeting role qualifications and successfully completing all required recruitment steps, which may include: * Submission of an internal application * Recruiter pre-screen * Skills assessment if applicable * Final interview with hiring leadership * Formal verbal offer from authorized hiring representatives ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)