> Markdown version of [/jobs/ext/3005653-director-information-cyber-security](https://www.wearedevelopers.com/jobs/ext/3005653-director-information-cyber-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Information & Cyber Security - **Company:** The Specialty Alliance - **Location:** Southlake, TX, United States - **Experience:** Expert - **Salary:** $175,000.0 - $245,000.0 - **Contract:** Permanent contract - **Skills:** User Authentication, Business Systems, Cloud Computing, Cyber Security, Information Systems, Desktop Computing, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Penetration Tools, Zero Trust Network Access, IT General Controls (ITGC), Information Technology - **Published:** September 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b50637e91d62ca4b ## About the Role * Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, Risk Management, Healthcare Administration, or a related field. * 10+ years of progressive experience in Governance, Risk & Compliance, Information Security, Internal Audit, or Cybersecurity. * 5+ years of leadership experience managing GRC, Compliance, Risk, or Security teams. * Experience within the healthcare, medical device, healthcare technology, payer, provider, or life sciences industry. * Demonstrated experience leading enterprise compliance and risk management programs. Candidates must possess strong working knowledge of: * HIPAA Privacy Rule, Security Rule, and Breach Notification Rule * NIST Cybersecurity Framework (CSF) * NIST Special Publication 800-53 * SOC 2 Trust Services Criteria and audit readiness * Sarbanes-Oxley (SOX), including IT General Controls (ITGCs) * Security governance and policy development * Audit management and regulatory examinations * Incident response governance, * Master's degree in Cybersecurity, Information Systems, Business Administration, Healthcare Administration, or related discipline. * Professional certifications such as: + Certified Information Systems Security Professional (CISSP) + Certified Information Security Manager (CISM) + Certified in Risk and Information Systems Control (CRISC) + Certified Information Systems Auditor (CISA) + Certified in Healthcare Privacy and Security (CHPS) + Healthcare Information Security and Privacy Practitioner (HCISPP) Key Competencies * Executive communication and presentation skills * Strategic leadership * Regulatory interpretation and implementation * Enterprise risk management * Analytical problem-solving * Cross-functional collaboration * Program and project management * Audit readiness and remediation * Policy development and governance * Change management, * Bachelor s degree in computer science or other technical/scientific discipline. * 10+ years related work including 5+ years as in security. * 2+ years in a dedicated information security role at a senior level including cybersecurity experience specializing in enterprise security optimization * Knowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST. * CISSP or equivalent certification required. Essential Skills and Experience: * Leadership: a demonstrated ability to lead people and get results through others. * Strategy and planning: an ability to think ahead and plan over a 12-24 month time span. * Demonstrated understanding of Information Security best practices. * Problem analysis and problem resolution at both a strategic and functional level. * Experience in developing and deploying security specific solutions including the automation of repeatable security tasks and controls * Experience with security vulnerability and penetration tools, remediation, and processes. * Strong customer orientation. * Must be willing to travel Performance Requirements: * Excellent communication skills, both written and verbal. * Proficient technical (computer) skills. * Ability to multi-task and prioritize. * Self-motivated with initiative. * Strong sense of ethics. * Ability to manage conflict and resolve problems. Equipment Operated: This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. ## Description In the performance of their respective tasks and duties all employees are expected to conform to the following: * Perform quality work within deadlines with or without direct supervision. * Interact professionally with other employees, customers and suppliers. * Work effectively as a senior contributor on all projects. * Work independently while understanding the necessity for communicating and coordinating team efforts with departments and organizations., The Identity and Access Management Director directs the strategy, governance, and operational execution of the enterprise Identity and Access Management (IAM) program to ensure secure, reliable, and compliant access to critical business systems, applications, and data. Leads the evolution of identity services, access governance, privileged access management, and authentication technologies to support organizational growth, regulatory requirements, and cybersecurity objectives. Partners with executive leadership, business stakeholders, infrastructure teams, application owners, and security functions to align identity capabilities with business priorities while enabling a secure and frictionless user experience. Drives the adoption of modern identity principles, including Zero Trust, automation, and cloud-based identity services, to strengthen the organization's security posture and operational efficiency., Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions., * Lead enterprise-scale Identity Access Management (IAM) transformation programs, providing strategic direction for Identity Governance Administration (IGA) and Privileged Access Management (PAM) initiatives across complex client environments * Oversee the design, architecture, and governance of IAM solutions leveraging Identity technologies to address identity lifecycle management, privileged access controls, compliance, and security requirements * Serve as the executive technical advisor and escalation point for complex identity governance, privileged access, application onboarding, and modernization challenges, driving successful outcomes and mitigating security and operational risks * Lead and mentor cross-functional teams of technical specialists while fostering delivery excellence, innovation, and growth across IAM programs * Partner with executive stakeholders, security leaders, application owners, and business executives to develop IAM roadmaps, align identity security strategies with business objectives, and establish leading practices for governance and risk management * Support business development efforts through solution development, proposal creation, thought leadership, and identification of opportunities to expand identity security, governance, and privileged access services within existing and prospective accounts * Act with integrity, professionalism, and personal responsibility to uphold a respectful and courteous work environment * Establish IAM frameworks, security policies, standards, and procedures aligned with organizational objectives. Regulatory Compliance * Lead compliance initiatives as they relate to IMA in the context of healthcare regulations, including HIPAA Privacy, Security, and Breach Notification Rules. * Ensure IAM compliance with applicable federal, state, and industry regulations affecting healthcare organizations. * Participate in internal and external compliance audits. * Participate in regulatory examinations and respond to audit findings. * Monitor regulatory changes and assess organizational impact. Security Frameworks & Controls * Develop and maintain security controls aligned with: + NIST Cybersecurity Framework (CSF) + NIST SP 800-53 + NIST SP 800-171 + SOC 2 Trust Services Criteria + Sarbanes-Oxley (SOX) IT General Controls (ITGCs) * Evaluate control effectiveness and recommend improvements in the context of IAM * Partner with IT and Security teams to ensure technical controls support regulatory and business requirements. Audit & Assurance * Participate and assist TSA GRC in internal and external audits including HIPAA, SOC 2, SOX, and customer security assessments. * Track remediation efforts through completion. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [APIs and Architecture for scaling omnichannel payments](https://www.wearedevelopers.com/videos/90-apis-and-architecture-for-scaling-omnichannel-payments) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)