Chief Information Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Availity is seeking a Chief Information Security Officer to lead the companyâs enterprise cybersecurity, security assurance, and technology risk programs. Reporting directly to the Chief Technology Officer, the Chief Information Security Officer is responsible for protecting Availity, its customers, and the highly sensitive healthcare information entrusted to its platforms.
The successful candidate must have personally led significant healthcare security audit and assurance programs, including multiple Health Information Trust Alliance assessment or certification cycles, multiple System and Organization Controls examination cycles, major healthcare customer audits, and remediation of significant findings., * Develop and execute a multi-year cybersecurity strategy aligned to business strategy, customer commitments, technology direction, and risk tolerance.
- Set the enterprise security vision, priorities, policies, standards, operating model, and accountability across technology, product, engineering, business, and corporate functions.
- Ensure security is built into application development, cloud architecture, data platforms, APIs, AI capabilities, and other core technology capabilities.
Security assurance, audits, and continuous compliance
- Own Availityâs enterprise security audit and assurance strategy, including continuous readiness for customer, external, regulatory, and internal audits.
- Lead major healthcare assurance programs, including HITRUST, SOC examinations, customer security audits, and remediation of significant findings.
- Simplify, standardize, and automate the control environment, including automated control monitoring and reusable audit evidence across cloud environments.
- Track findings, exceptions, risks, evidence requirements, owners, deadlines, and remediation commitments with clear executive visibility.
Board and executive engagement
- Serve as the principal cybersecurity advisor to the CTO, executive leadership team, and Board of Directors.
- Translate complex technical risks into business, customer, financial, operational, and reputational impact.
- Give candid updates on audit posture, material findings, accepted risks, incidents, emerging threats, and areas requiring investment or Board attention.
Multi-cloud and global security
- Establish a consistent security model across multiple cloud providers, including identity, workloads, applications, networks, data, logging, detection, and privileged access.
- Secure Availityâs highly virtual and international operating model, including teams outside the United States that appropriately access or support systems containing PHI and sensitive healthcare data.
- Ensure international operations are incorporated into audits, control testing, incident response, training, and risk management.
Security operations, incident response, and resilience
- Ensure Availity can rapidly detect, investigate, contain, communicate, and recover from security incidents.
- Lead significant cyber incident response when required and coordinate across technology, legal, privacy, compliance, communications, customers, and executive leadership.
- Regularly test recovery from disruptive events involving cloud services, identities, APIs, software supply chains, third parties, international operations, AI systems, and healthcare platforms.
Future security strategy
- Prepare Availity for the next three to five years of cybersecurity risk, including AI security, machine and workload identity, software supply chain risk, automation, and cyber resilience.
- Establish AI security standards that protect sensitive healthcare data, control autonomous actions, support auditability, and manage third-party AI platform risk.
- Build, develop, and retain a high-performing global security leadership team and succession pipeline.
Customer and external leadership
- Represent Availity as a trusted security executive with major health plans, providers, partners, auditors, regulators, and industry forums.
- Respond credibly and transparently to customer security concerns and strengthen Availityâs reputation as a trusted healthcare technology platform., NOTICE: Federal law requires all employers to verify the identity and employment eligibility of all persons hired to work in the United States. When required by state law or federal regulation, Availity uses I-9, Employment Eligibility Verification in conjunction with E-Verify to determine employment eligibility. Learn more about E-Verify at http://www.dhs.gov/e-verify.
Requirements
- Significant executive cybersecurity leadership experience, with substantial cybersecurity leadership experience in healthcare.
- Demonstrated experience protecting PHI and other regulated healthcare data in a large-scale, cloud-based healthcare technology environment.
- Direct executive accountability for major healthcare security audits, certifications, customer assessments, and regulatory examinations.
- Personal leadership of multiple HITRUST assessment or certification cycles and multiple SOC examination cycles.
- Experience leading complex healthcare customer security audits and assessments, including remediation of significant findings and prevention of repeat findings.
- Experience establishing continuous audit readiness, automating control monitoring, and automating audit evidence collection.
- Experience operating security programs across multiple cloud providers and securing highly distributed, virtual, and international teams.
- Experience establishing controls for cross-border access to healthcare information and systems containing PHI or other sensitive healthcare data.
- Board and executive-level communication experience, including presentation of security posture, audit results, risks, incidents, findings, and remediation status.
- Strong knowledge of cloud security, software security, identity, data protection, security operations, incident response, and cyber resilience.
- Proven ability to build and lead high-performing security organizations across multiple countries., * Security leadership experience in a large healthcare technology company serving health plans and healthcare providers.
- Experience with healthcare transaction networks, regulated healthcare data exchanges, large API ecosystems, and major healthcare customers.
- Experience consolidating overlapping security frameworks into a common control environment and materially reducing recurring audit time and cost.
- Experience implementing continuous control monitoring across multiple cloud providers.
- Experience with AI security and governance, acquisition integration, and security teams distributed across the United States and India.
Benefits & conditions
- Availity is a certified âGreat Place to Workâ, a âBest Workplaces for Technology Companiesâ, a âBest Workplaces for Womenâ and a âBest Workplaces for Millennialsâ!
- Culture is important to us and there are many ways for you to make your mark here!
- We have several Diversity & Inclusion teams and various ways to engage with fellow Availity associates. âAvaiLadiesâ, âBeyond Blackâ, âHOLAâ, âAvaility Prideâ, âVetAvailityâ a Young Professionals Group and âShe Can Code ITâ a group for women in tech are some of the groups you can get involved in.
- Availity is a culture of continuous learning. We have many resources and experts in our tech stack and in our industry that can help get you there too!
- We offer a competitive salary, bonus structure, generous HSA company contribution, healthcare, vision, dental benefits and a 401k match program that you can take advantage of on day one!
- We offer unlimited PTO for salaried associates + 9 paid holidays. Hourly associates start at 19 days of PTO and go up from there with all the same holiday benefits.
- Interested in wellness? We allow our associates to reimburse up to $250/year for gym memberships, participation in racing events, weight management programs, etc.
- Interested in furthering your education? We offer education reimbursement!
- Availity offers Paid Parental Leave for both moms and dads, both birth parents and adoptive parents.
- Want to work for an organization that gives back to the community? Youâre at the right place! Availity partners with various organizations, both locally and nationally, to raise awareness, funds and morale as our staff members volunteer their time and funds to engage the organizations campaign.
About the company
Availity delivers revenue cycle and related business solutions for health care professionals who want to build healthy, thriving organizations. Availity has the powerful tools, actionable insights and expansive network reach that medical businesses need to get an edge in an industry constantly redefined by change.
At Availity, weâre not just another Healthcare Technology company; weâre pioneers reshaping the future of healthcare! With our headquarters in vibrant Jacksonville, FL, and an exciting office in Bangalore, India, along with an exceptional remote workforce across the United States, weâre a global team united by a powerful mission.
Weâre on a mission to bring the focus back to what truly matters - patient care. As the leading healthcare engagement platform, weâre the heartbeat of an industry that impacts millions. With over 2 million providers connected to health plans, and processing over 13 billion transactions annually, our influence is continually expanding.
Join our energetic, dynamic, and forward-thinking team where your ideas are celebrated, innovation is encouraged, and every contribution counts. Weâre transforming the healthcare landscape, solving communication challenges, and creating connections that empower the nationâs premier healthcare ecosystem.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on jobs.localjobnetwork.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Understanding and Mitigating Common Web Vulnerabilities
Navigating the AI Shift
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production