> Markdown version of [/jobs/ext/2103488-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2103488-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** CAPITAL HEALTH PARTNER, LLC - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software Applications, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Disaster Recovery, Identity and Access Management, Information Systems Security Architecture Professional, Cloud Services, Software Engineering, Cloud Platform System, EHR Systems, Software Security, Information Technology, Cybercrime, Data Analytics, Enterprise Integration, Virtual Agents, Devsecops - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/0b88172a-1747-474a-b57a-6fe4997d8bbd ## About the Role Education: Bachelor's degree in Information Security, Computer Science, Information Technology, Business, Engineering, or related field required. Master's degree preferred. Experience: Ten years of progressive experience in cybersecurity, with a proven track record of building and maturing enterprise-level security programs. Direct experience leading security initiatives in healthcare or another highly regulated environment, with a deep understanding of operational needs and regulatory rules. Significant experience architecting and securing complex digital environments - including cloud-native platforms, DevSecOps pipelines, clinical systems and APIs - to ensure safety and security are built into the design from the start. Extensive experience acting as a trusted advisor to executive leadership, boards and governance committees on cyber risk and digital trust. Preferred certifications include: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), HCISPP or healthcare-specific security certification and cloud security certifications (Azure, AWS, or equivalent). Other Credentials: Knowledge and Skills: Deep working knowledge of healthcare security standards (HIPAA/HITECH, NIST CSF, ISO 27001) and clinical accreditation expectations (DNV). Specific understanding of securing medical devices and healthcare-specific operational technology (IEC 62443). Strong technical depth in cloud-native systems, DevSecOps, AI governance and the security of internally developed applications. Expert knowledge of the Secure Software Development Lifecycle (SSDLC) and modern application security principles. Advanced understanding of enterprise risk management and the ability to make data-driven, risk-based decisions. Professional proficiency in translating complex technical concepts into clear, actionable reports for executive and board-level presentations. Mental, Behavioral and Emotional Abilities: A leadership style focused on supporting the clinical mission and ensuring security enables - rather than hinders - patient care. Natural ability to build trust and influence others within a complex, matrixed organization, from clinicians to executives. High level of interpersonal effectiveness and the ability to mentor technical teams to increase their maturity. A proactive drive to modernize and scale security capabilities while balancing innovation with practical operational realities. Proven ability to take ownership of difficult security decisions and remain accountable for the organization's resilience. Demonstrated ability to think long-term and manage the organizational shifts required to align security with business goals., The pay range listed is a good faith determination of potential base compensation that may be offered to a successful applicant for this position at the time of this job advertisement and may be modified in the future. When determining base salary and/or rate, several factors may be considered including, but not limited to location, years of relevant experience, education, credentials, negotiated contracts, budget, market data, and internal equity. Bonus and/or incentive eligibility are determined by role and level. ## Description The Information Security Officer (ISO) serves as the executive leader responsible for protecting Capital Health's digital environment and building organizational resilience against cyber threats. This role defines the organization's cybersecurity strategy, safeguarding the confidentiality and availability of patient data, clinical systems and connected medical technologies by establishing clear policies and governance that align with healthcare regulations and industry standards. The ISO also acts as a principal advisor to leadership, working across clinical, legal and technical teams to embed security into daily operations and build a culture of digital trust. Additionally, the role oversees risk management and business continuity planning to ensure the organization can defend against emerging threats and quickly resume serving the community in the event of a disruption., * Define and execute the enterprise cybersecurity strategy and multi-year roadmap to ensure protection stays ahead of evolving threats * Act as the principal advisor to the Board and leadership, providing clear reporting on cyber risk, resilience and maturity * Establish the policies, standards and accountability frameworks that govern how data and systems are protected across the health system * Lead the enterprise cybersecurity risk program, ensuring that risks are identified, prioritized and managed in line with healthcare regulations * Partner with Clinical Engineering to secure medical devices (BioMed) and connected technologies that directly impact patient care * Oversee the design of secure environments, ensuring "security-by-design" is built into cloud platforms and infrastructure * Integrate security into the software development lifecycle, ensuring internally developed applications are secure from the start * Drive the maturity of DevSecOps practices, integrating security into CI/CD pipelines and automation frameworks * Strengthen identity management and privileged access controls to enforce a "least-privilege" approach across the enterprise * Improve visibility and control over sensitive data (PHI, PII and PCI) across all clinical and operational platforms * Strengthen and elevate the organization's ability to detect and respond to incidents through advanced monitoring and automation * Lead enterprise-wide incident response planning and coordinate executive communication during cybersecurity events * Oversee disaster recovery and business continuity planning to guarantee that clinical services can resume quickly after a disruption * Establish vendor security governance, ensuring partners and cloud services meet strict security and contractual standards * Partner with Procurement to embed cybersecurity into vendor selection, onboarding and Business Associate Agreements (BAAs) * Establish governance and security standards for Artificial Intelligence (AI), automation and intelligent agents * Ensure the secure exchange of data across EHR systems, cloud services and enterprise integration platforms * Partner with Legal and Compliance teams to maintain alignment with HIPAA, NIST and DNV accreditation expectations * Perform other duties as assigned ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Bitcoin SV: The Massively Scaled Blockchain to Meet Developer Needs](https://www.wearedevelopers.com/videos/20-bitcoin-sv-the-massively-scaled-blockchain-to-meet-developer-needs) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)