Director, Information Security

IHI Inc.
United States
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$96,171.0 - $173,109.0
Working hours
Regular working hours
Job source

Tech stack

Business Software Cloud Computing Security Cyber Security System Configuration Data Centers Data Files Information Security Management Information Technology Security Auditing Server Administration Software Security Information Technology Patch Management
+1 more
Malware Detection

Job description

The Information Security Director will be responsible for ensuring the confidentiality, integrity, and availability of all information assets within the organization. You will lead the development and implementation of the organization’s information security strategy, policies, and procedures.

In this role, you will also be responsible for ensuring compliance with all relevant laws, regulations, and industry standards. You will be responsible for identifying and mitigating information security risks, managing security incidents, and providing security awareness training to employees. The role requires a high level of technical expertise in information security, risk management, compliance, and governance.

This role will require a visionary leader who understands the global information security & risk impacts, and has a sound understanding of cybersecurity technology tools, methods and processes. This role requires a leader who works with business stakeholders, assesses needs, builds awareness and develops informed strategy and direction for information security.

Position Responsibilities:

Responsibilities include but are not limited to the following:

Awareness and Governance:

  • Develop and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences
  • Lead cross-functional Information Security Steering Committee, infusing information security governance procedures that foster resiliency, raise awareness, govern policy and review cybersecurity related activities
  • Provide clear risk mitigating directives for projects with components in IT, including the mandatory application of controls
  • Foster a ā€œSecurity Awareness Championsā€ program to spread the word and infuse security awareness behaviors, cybersecurity risks and policies
  • Perform annual risk assessment and business impact analysis
  • Assist in performing audits using industry standard security methods to help strengthen internal security controls, procedures and policies
  • Investigate security incidents, develop remediation plans, and work with appropriate stakeholders to implement resolutions

Security Operations:

  • Manage and provide additional security evaluations for existing or new vendors, partners, and systems. Leverage security tools and data sets to provide visibility into vendor security posture and risk
  • Work with IT and technology stakeholders to evolve new business continuity and disaster recovery plans
  • Support data protection and privacy initiatives in compliance with the data protection standards of both US and foreign. Align with internal compliance teams on policy updates in global data privacy standards
  • Work with MSSP to monitor and manage all IT security tools and platforms including Security management platforms, Anti-Malware/Ransomware, log management systems, and information security training systems
  • Work with IT department, MSP, legal and compliance teams to keep security polices updated, communicated and enforced
  • Review existing security architecture, identify design gaps, and recommend security enhancements
  • Stays abreast of emerging security technologies and integrates them into security architecture as needed
  • Ensures alignment between security architecture frameworks, IT standards and overall business strategy
  • Achieves security architecture compliance on industry-specific requirements as well as state and federal regulations

Leadership:

  • Lead, grow and manage the Information Security Program at IHI, with the responsibility to ensure that information assets and associated technology are all adequately protected
  • Partner with all business leaders while working closely with service desk, Infrastructure and Enterprise/Business Applications teams
  • Create a risk-based process for the assessment and mitigation of any information security risk in the IHI’s ecosystem consisting of faculty, vendors, consumers and any other third parties
  • Responsible for identifying, evaluating, and reporting on legal and regulatory, IT and cybersecurity risk while supporting and enabling business goals

Requirements

  • Strong Interpersonal skills and ability to translate complex issues into simple concepts
  • Ability to be key contributor in IT projects and new system implementation activities
  • Experience leading cross-functional teams
  • Exceptional problem-solving skills with the ability to proactively introduce solutions
  • Ability to manage many complex and challenging tasks and prioritize criticality
  • Strong documentation skills
  • Collaborative team player with strong interpersonal, verbal, and written communication and presentation skills
  • Highly motivated, driven, and willing to try new concepts
  • Strong work ethic with ability to maintain and safeguard confidential information
  • Ability to thrive in a fast-paced environment with multiple competing priorities
  • Ability to learn and use new systems and technology
  • Continuous improvement mindset
  • Strong ability to plan, organize and think strategically

IHI Values and Culture

  • Commitment to IHI Values of courage, love, equity, trust and impact
  • Commitment to equity, anti-racism, and the improvement of societal systems

Position Qualifications:

Required

  • Bachelor’s degree and 7 plus years of experience in leading Information Security initiatives, incident management and security operations

OR

  • 10 plus years of experience in leading Information Security initiatives, incident management and security operations

Preferred

  • Bachelor’s degree in cyber security, information risk management, or a relevant IT field
  • 5+ years of experience with regulatory compliance and information security management frameworks
  • Experience implementing, managing, and driving all Information Security, training, policies, and review activities in accordance with applicable cybersecurity standards and privacy regulations
  • Experience leading cross-functional teams
  • Strong Interpersonal skills and ability to translate complex issues into simple concepts
  • Adequate knowledge of server, network, application and perimeter security, vulnerability and patch management, endpoint security, incident response, security audit, compliance and industry certifications (e.g. SOC2, ISO27000)
  • Advanced experience managing cloud security tools such as CASB, UEM, Security Scorecards, Anti-Malware tools, IDR, MDR and Security Awareness training tools
  • Experience with NIST Cybersecurity framework
  • Knowledge of the Information Security market and information risk vendor landscape
  • Ability to manage many complex and challenging tasks and prioritize criticality
  • Strong documentation skills
  • Ability to be key contributor in IT projects and new system implementation activities
  • Exceptional problem-solving skills with the ability to proactively introduce solutions
  • Strong understanding of cloud security, datacenter security, application security, endpoint security and security audit practices and industry certifications

Physical Attributes:

  • Ability to Sit for Extended Periods: Capability to work at a desk for long durations
  • Manual Dexterity: Proficiency in using a computer, including typing, mouse handling, and other office equipment
  • Visual Acuity: Ability to read and view a computer screen for extended periods
  • Hearing and Speaking: Clear communication over phone and video calls
  • Environment Setup: Access to a quiet, professional home office setup conducive to focused work and virtual meetings
  • Lifting: Occasionally requires lifting up to 25 lbs as needed

Benefits & conditions

3.93.9 out of 5 stars United States Remote $96,171 - $173,109 a year - Full-time, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance
  • Flexible spending account

About the company

The Institute for Healthcare Improvement (IHI), is a leading, globally recognized not-for-profit health care improvement organization that has been applying evidence-based quality improvement methods to meet current and future health care challenges for more than 30 years. IHI provides millions of people in health care with methods, tools, and resources to make care better, safer, and more equitable; convenes experts to enable knowledge sharing and peer-learning; and advises health systems and hospitals of all sizes in improving their systems and outcomes at scale. IHI’s mission is to innovate and lead transformational improvement in health and health care worldwide., At IHI, we are inspired to do our best work and be our best selves by leaning into our values and uniting in our vision to create a future in which everyone has the best care and health possible. We ensure that people feel valued and supported in meaningful ways, as demonstrated in our total rewards package that features competitive compensation, medical, dental and vision coverage, life and disability plans, FSA plans, matching 401k contributions, generous time off including vacation time, sick time, and other special programs to support employee wellbeing.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:38 min

Reusing email software standards for HTTP file uploads

Imran Nazar Ā· WWC 2023

51 sec

Repurposing hardware and operating underwater data centers

Chris Heilmann +1 Ā· LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· WWC 2022

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder Ā· LIVE

5:21 min

Extracting and preprocessing HTML data into markdown files

Rainer Stropek Rainer Stropek Ā· LIVE

Videos

See all

Related articles

See all