Director Enterprise Identity Services and Cybersecurity

Riverside Hospital, Inc.
Newport News, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Health Informatics Cyber Security Identity and Access Management Role-Based Access Control Zero Trust Network Access Software Security Information Technology

Job description

The Director Enterprise Identity Services and Cybersecurity serves as a senior cybersecurity leader responsible for the design, implementation, and governance of enterprise identity and access management (IAM) across the health system. This role combines hands-on IAM leadership with senior-level cybersecurity responsibilities, ensuring secure, compliant, and efficient access to clinical, administrative, and third-party systems. The position requires extensive cybersecurity experience in a healthcare environment and direct leadership of an IAM team, supporting patient safety, regulatory compliance, and organizational risk management.

What you will do

  • Lead, mentor, and manage the IAM team, including engineers, analysts, and administrators. Define and execute the IAM strategy aligned with organizational cybersecurity and clinical objectives. Oversee user lifecycle management (JML: joiner, mover, leaver) across workforce, clinicians, contractors, and vendors. Manage privileged access management (PAM), role-based access control (RBAC), and least-privilege models.Ensure secure identity integration across EHR (Epic), clinical systems, cloud platforms, and third-party applications. Lead the design and implementation of Identity Governance (IGA) frameworks, specifically defining Separation of Duties (SoD) policies and orchestrating periodic access certifications to ensure the principle of least privilege. Integrate robust Change Management protocols into the IAM lifecycle to ensure that identity-related updates, configuration shifts, and privilege escalations are executed with minimal operational disruption and full audit-ability.
  • Serve as a senior cybersecurity leader, collaborating with members of the information security, infrastructure, and application security teams. Assess, mitigate, and manage identity-related cybersecurity risks, including insider threats and credential compromise. Support incident response and breach investigations involving identity, access, or authentication events. Contribute to enterprise security architecture and zero-trust initiatives. Lead security reviews for new systems, integrations, and vendor access.
  • Ensure IAM controls meet healthcare regulatory requirements (HIPAA, HITECH, NIST, HITRUST, ISO 27001)
  • Support audits, risk assessments, and compliance reporting related to identity security
  • Develop and enforce IAM policies, standards, and procedures
  • Partner with clinical leadership to balance security, usability, and patient care workflows

Requirements

Do you have experience in Zero Trust security?, Do you have a Bachelor’s degree?, * Bachelors Degree, Bachelor’s degree in Information Security, Computer Science, Healthcare Informatics, or related field (or equivalent experience) (Required), * 7-10 years Cybersecurity experience, with significant experience in healthcare environments (Required)

  • 3-4 years Supervisory experience (Required)

Skills and Abilities

  • Experience with Zero Trust Architecture and modern identity security frameworks
  • Prior experience supporting large health systems or multi-facility organizations
  • Strong knowledge of IAM, PAM, MFA, SSO, directory services, and cloud identity
  • Proven experience supporting regulatory compliance and audits in healthcare
  • Demonstrated ability to lead cross-functional security initiatives
  • Strategic leadership and team development
  • Strong communication skills with technical and non-technical stakeholders
  • Risk-based decision making in clinical environments
  • Ability to balance security, compliance, and patient care priorities
  • High level of integrity and accountability

Licenses and Certifications

  • CISSP Upon Hire (Preferred)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:39 min

Navigating strict environments for enterprise banking

Lea Fragner · LIVE

Videos

See all

Related articles

See all