> Markdown version of [/jobs/ext/1858930-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/1858930-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Availity - **Location:** Jacksonville, FL, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cloud Computing Security, Cloud Engineering, Cyber Security, Cloud Services, Information Technology Security Auditing, Software Engineering, Data Logging, Software Security, Multi-Cloud, AI Platforms, Data Management - **Published:** July 11, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87693247/1 ## About the Role * Significant executive cybersecurity leadership experience, with substantial cybersecurity leadership experience in healthcare. * Demonstrated experience protecting PHI and other regulated healthcare data in a large-scale, cloud-based healthcare technology environment. * Direct executive accountability for major healthcare security audits, certifications, customer assessments, and regulatory examinations. * Personal leadership of multiple HITRUST assessment or certification cycles and multiple SOC examination cycles. * Experience leading complex healthcare customer security audits and assessments, including remediation of significant findings and prevention of repeat findings. * Experience establishing continuous audit readiness, automating control monitoring, and automating audit evidence collection. * Experience operating security programs across multiple cloud providers and securing highly distributed, virtual, and international teams. * Experience establishing controls for cross-border access to healthcare information and systems containing PHI or other sensitive healthcare data. * Board and executive-level communication experience, including presentation of security posture, audit results, risks, incidents, findings, and remediation status. * Strong knowledge of cloud security, software security, identity, data protection, security operations, incident response, and cyber resilience. * Proven ability to build and lead high-performing security organizations across multiple countries., * Security leadership experience in a large healthcare technology company serving health plans and healthcare providers. * Experience with healthcare transaction networks, regulated healthcare data exchanges, large API ecosystems, and major healthcare customers. * Experience consolidating overlapping security frameworks into a common control environment and materially reducing recurring audit time and cost. * Experience implementing continuous control monitoring across multiple cloud providers. * Experience with AI security and governance, acquisition integration, and security teams distributed across the United States and India. ## Description Availity is seeking a Chief Information Security Officer to lead the company's enterprise cybersecurity, security assurance, and technology risk programs. Reporting directly to the Chief Technology Officer, the Chief Information Security Officer is responsible for protecting Availity, its customers, and the highly sensitive healthcare information entrusted to its platforms. The successful candidate must have personally led significant healthcare security audit and assurance programs, including multiple Health Information Trust Alliance assessment or certification cycles, multiple System and Organization Controls examination cycles, major healthcare customer audits, and remediation of significant findings., * Develop and execute a multi-year cybersecurity strategy aligned to business strategy, customer commitments, technology direction, and risk tolerance. * Set the enterprise security vision, priorities, policies, standards, operating model, and accountability across technology, product, engineering, business, and corporate functions. * Ensure security is built into application development, cloud architecture, data platforms, APIs, AI capabilities, and other core technology capabilities. Security assurance, audits, and continuous compliance * Own Availity's enterprise security audit and assurance strategy, including continuous readiness for customer, external, regulatory, and internal audits. * Lead major healthcare assurance programs, including HITRUST, SOC examinations, customer security audits, and remediation of significant findings. * Simplify, standardize, and automate the control environment, including automated control monitoring and reusable audit evidence across cloud environments. * Track findings, exceptions, risks, evidence requirements, owners, deadlines, and remediation commitments with clear executive visibility. Board and executive engagement * Serve as the principal cybersecurity advisor to the CTO, executive leadership team, and Board of Directors. * Translate complex technical risks into business, customer, financial, operational, and reputational impact. * Give candid updates on audit posture, material findings, accepted risks, incidents, emerging threats, and areas requiring investment or Board attention. Multi-cloud and global security * Establish a consistent security model across multiple cloud providers, including identity, workloads, applications, networks, data, logging, detection, and privileged access. * Secure Availity's highly virtual and international operating model, including teams outside the United States that appropriately access or support systems containing PHI and sensitive healthcare data. * Ensure international operations are incorporated into audits, control testing, incident response, training, and risk management. Security operations, incident response, and resilience * Ensure Availity can rapidly detect, investigate, contain, communicate, and recover from security incidents. * Lead significant cyber incident response when required and coordinate across technology, legal, privacy, compliance, communications, customers, and executive leadership. * Regularly test recovery from disruptive events involving cloud services, identities, APIs, software supply chains, third parties, international operations, AI systems, and healthcare platforms. Future security strategy * Prepare Availity for the next three to five years of cybersecurity risk, including AI security, machine and workload identity, software supply chain risk, automation, and cyber resilience. * Establish AI security standards that protect sensitive healthcare data, control autonomous actions, support auditability, and manage third-party AI platform risk. * Build, develop, and retain a high-performing global security leadership team and succession pipeline. Customer and external leadership * Represent Availity as a trusted security executive with major health plans, providers, partners, auditors, regulators, and industry forums. * Respond credibly and transparently to customer security concerns and strengthen Availity's reputation as a trusted healthcare technology platform., NOTICE: Federal law requires all employers to verify the identity and employment eligibility of all persons hired to work in the United States. When required by state law or federal regulation, Availity uses I-9, Employment Eligibility Verification in conjunction with E-Verify to determine employment eligibility. Learn more about E-Verify at http://www.dhs.gov/e-verify. ## Related Videos - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)