IT Security, Director I (Hybrid)

American Medical Association
Chicago, IL, United States
1 day ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$146,384.0 - $197,728.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) .NET Framework Microsoft Windows Active Directory Federation Services Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Antivirus Softwares Macintosh Computers
+71 more
User Authentication Microsoft Azure Microsoft Online Services Burp Suite Cloud Computing Security Code Review Cyber Security Computer Programming Databases Data Integration Information Leak Prevention Data Security DDoS Mitigation Linux File Systems Drupal Freeware Github Identity and Access Management Information Security Management Information Technology Audit Intrusion Detection and Prevention Virtual Private Networks (VPN) Mobile Application Software Python (Programming Language) Network Security Lightweight Directory Access Protocols (LDAP) Multi-Purpose Internet Mail Extensions (MIME) Nmap Open Shortest Path First (OSPF) OAuth Open Source Technology Open Systems Interconnection (OSI) Open Web Application Security Systems Development Life Cycle Red Hat Enterprise Linux Regular Expressions Azure Active Directory Zero Trust Network Access Standard Sql Security Assertion Markup Language (SAML) Microsoft SharePoint Security Information and Event Management Software Engineering TCP/IP Wireshark Software Vulnerability Management Web Applications Web Services Data Logging Network Routing Enterprise Software Applications Office365 Software Security Firewalls (Computer Science) Cloudformation Microsoft InTune Azure Security Center AngularJS Information Technology Malware Detection Bitbucket Cloud Optimization Restful APIs Terraform Network Server Software Version Control Qualys Vulnerability Analysis Vmware Programming Languages

Job description

We have an opportunity at our corporate offices in Chicago for an IT Security, Director I (Hybrid) on our Information Technology team. This is a hybrid position reporting into our Chicago, IL office, requiring 3 days a week in the office.

This role is responsible for providing subject matter expertise on the strategy, research, design, implementation, and operation of technical and process security controls. Develops strong relationships across the AMA’s IT department and with business unit teams; serves as a trusted advisor to assess security risk in technology selection with appropriate balance that supports business outcomes. Responsibilities include data security, collaboration with the security operations team, and maintaining the broad suite of information security infrastructure, and all associated contracting, policy, and regulatory compliance implications. Maintain cybersecurity and related regulatory expertise to research, prepare, and maintain strategic roadmaps incorporated into the Information Security Program. Lead or assist with security incidents and compliance investigations and produce timely and clear reporting to both technical and senior business leader audiences. Serves as primary backup for the Director IT Security., System/Network/Application Security Strategy

  • Research, design, evaluate, and test the security and regulatory compliance of AMA applications, systems, and networks to ensure the operational effectiveness of technical controls implemented by the organization; purpose-built security tools such as data loss prevention, logging and event management, enterprise encryption systems and also security controls embedded in enterprise systems and applications such as authentication and access controls

  • Responsible for the effective use of AMA cybersecurity systems including enhancements, upgrades, and lifecycle management through relationships with product and service vendors

  • Responsible for the technical integration of security components within the AMA’s environment to optimize the value and control benefits including ease of use, effectiveness, and breadth of coverage

Technology and Regulatory Risk Management

  • Assess technical risks in the AMA’s environment both pre and post-production through the AMA’s Software Development Lifecycle (SDLC) and Change & Release

  • Management Boards; propose information security strategy and program improvements, communicate identified risks and recommend solutions

  • Manage the research, appropriate response, and remediation of malicious and inappropriate activity; ensure consistency of the risk assessment approach across the organization

  • Prepare policy updates; research and recommend short and long-term improvements to maintain strong security posture relative to enterprise architecture standards, data integration/data access, cloud strategy, and AI implementations

  • Collaborate in developing, recommending and implementing the AMA’s information security policies, and governance frameworks; this includes aligning security initiatives with business goals and ensuring compliance with industry standards and regulations

  • Ensures compliance with relevant laws, regulations, and frameworks, such as PCI, GDPR, NIST, or ISO standards, and manages security audits and assessments
  • Co-manage new software, data, and service provider products and contract reviews
  • Responsible for staying current on threats and best practices in the field of cybersecurity

Service Delivery

  • Manage continuous process improvement to identify technical or process enhancements in the delivery of IT Security services to increase service quality

  • Prioritize improvements on a cost/benefit basis, communicating opportunities to management.
  • Serve as an escalation point in the fulfillment of IT Security service requests

Project Management

  • Manage IT Security-led projects following the AMA’s applicable project governance processes, including Software Development Life Cycle; ensure successful project outcomes, such as completing projects within time and budget tolerances

  • Mentor security and infrastructure team members, including analysts, engineers, and managers, related to information security strategies and threat prevention techniques.

May include other responsibilities as assigned

Requirements

  1. Minimum 10+ years engineering/design experience with a mix of the following security platforms is required: network and application-layer firewalls and secure network design; infrastructure and application-layer vulnerability management, security information and event management (SIEM); Security, Orchestration, Automation and Response (SOAR), data loss prevention (DLP); enterprise encryption solutions for database, file systems and data in motion; Internet/Web Gateway; end point security controls (such as anti-virus, anti-malware XDR, host-based firewall, and full disk encryption solutions); and intrusion detection and prevention systems. Knowledge of Attack and Penetration methodologies, tools, and techniques

  2. Minimum 5 years conducting infrastructure and application project design reviews Engineering/design experience with a mix of the following infrastructure technologies is required: Microsoft/Azure (Azure AD, ADFS, M365, Sharepoint 2019, Windows Server2019-2022, Windows 10-11); Red Hat Linux, VMware, AWS EC2, S3, IAM

  3. Demonstrated industry leadership capabilities, and recognized as a subject expert in the information security field.

  4. Knowledge of security scanning and analyzing tools; Commercial Application and Infrastructure/Operating System and Opensource Vulnerability scanning/management, and freeware/commercial Wireshark, NMAP, Burp Suite, Nikto, Qualys, Tenable, Snyk, Wiz

  5. Polished verbal and written communication, interpersonal, analytical, and organizational skills, attention to detail, and a high level of integrity are required

  6. Strong business acumen. Ability to understand the organization’s various business functions and their objectives
  7. Experience with project management and software development lifecycle methodologies preferred.
  8. Professional IT Security and IT Audit certifications such as CISSP,CISM, CEH, CISA, and/or technical certifications preferred

  9. Experience with IT Infrastructure Library (ITIL) - particularly incident, change, release, and/or problem management preferred
  10. Experience with IT security standards, such as CIS Top 20, ISO 27001, NIST CSF, NIST 800-53, HITRUST, MITRE, OWASP,CWE/SANS Top 25 Programming Errors, and attestation reports such as SOC 1/2/3 and technology risk management methodologies, such as NIST 800-30 preferred.

  11. Experience with compliance standards such as PaymentCard Industry (PCI),Sarbanes Oxley (SOX) and Health Insurance Portability & Accountability Act (HIPAA) preferred

  12. Bachelor’s Degree in Computer Science or related discipline strongly preferred. Master’s Degree in Computer Science or related discipline a plus

Additional Technical Background Experience with:

  1. Cloud-based security tools (CloudTrail, WAF, Security Center, etc.)
  2. Source code management tools (GitHub, BitBucket, etc.)
  3. Code scanning tools (Dynamic, Static and Opensource)
  4. Vulnerability Management solutions(Qualys, Tenable, Wiz)

Knowledge of:

  1. User authentication such as Zero Trust concepts, SAML and OAuth-based SSO architectures and IDP integrations, MFA, Virtual Private Networks (VPNs), TLS, PAM, corporate wifi, device identity, 802.1x port-based authentication, server identification, authentication of web applications, S/MIME Email Signing, is desirable

  2. Programming languages (.Net, Java, JavaScript, Angular, Drupal, Python, etc.) Web services, API, REST, RPC Infrastructure as Code (CloudFormation, Terraform) preferred Administration of Azure suite, including; Azure Active Directory, Conditional Access, Intune, Mobile Application Management, Microsoft Cloud App Security, and/or advanced Azure security services like Azure Security Center, Advanced DDoS Protection, Azure Firewall, and Azure WAF

  3. Administration of AWS security services and related best practices: GuardDuty, Cognito, Inspector, Detective and advocate AWS Identity & Access Management (IAM)

  4. Operating systems: Windows, Mac, Linux, WVD, VDI, and Jump Boxes/Bastion Servers
  5. Network routing and communication frameworks, protocols, and technologies such as OSI, TCP/IP v4 & v6, RIP, OSPF, VPN, HTTPS, TLS, and SSH is required.

  6. Working knowledge of SQL, LDAP, and/or regex is a plus.

About the company

The American Medical Association (AMA) is the nation’s largest professional Association of physicians and a non-profit organization. We are a unifying voice and powerful ally for America’s physicians, the patients they care for, and the promise of a healthier nation. To be part of the AMA is to be part of our Mission to promote the art and science of medicine and the betterment of public health.

At AMA, our mission to improve the health of the nation starts with our people. We foster an inclusive, people-first culture where every employee is empowered to perform at their best. Together, we advance meaningful change in health care and the communities we serve.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all