IT Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+11 more
Job description
In the performance of their respective tasks and duties, all employees are expected to conform to the following:
- Perform quality work within deadlines with or without direct supervision.
- Interact professionally with other employees, customers, and suppliers.
- Work effectively as a team contributor on all assignments.
- Work independently while understanding the necessity for communicating and coordinating work efforts with other employees and organizations., The IT Security Manager is a working leader responsible for directly operating, configuring, and securing the organization’s cybersecurity infrastructure across a multi-site healthcare environment. This role is hands-on and execution focused, owning day to day security operations while building a scalable security program.
The ideal candidate has strong technical depth in XDR, MDR, SOC operations, SIEM administration, endpoint security, cloud security, and AI-enabled security tools. This individual will actively configure systems, investigate alerts, respond to incidents, and drive remediation efforts, not simply oversee them., * Act as primary owner of SIEM, XDR, and MDR platforms
- Monitor and tune alerting thresholds to reduce noise and improve detection accuracy
- Investigate security alerts, perform root cause analysis, and lead incident responses
- Conduct threat hunting using MITRE ATT&CK framework methodologies
- Manage endpoint detection and response (EDR) tools across all locations
- Maintain vulnerability scanning programs and coordinate patch remediation
Incident Response & Risk Mitigation:
- Lead real-time incident triage and containment activities
- Develop and maintain incident response playbooks
- Coordinate forensic investigations and external cybersecurity partners when required
- Document all incidents and produce executive summaries
AI & Emerging Technology Security:
- Evaluate and secure AI tools used in clinical, revenue cycle, and operational workflows
- Assess data leakage risks associated with generative AI platforms
- Implement monitoring controls for AI-driven automation systems
- Participate in AI governance initiatives and enforce approved AI usage policies
Identity, Network & Cloud Security:
- Manage identity and access management (IAM), MFA enforcement, and privileged access controls
- Implement and maintain Zero Trust architecture principles
- Oversee firewall rules, email security, and endpoint hardening
- Secure Microsoft 365, Azure, AWS, or other cloud environments
- Conduct periodic access reviews and audit log monitoring
Compliance & Healthcare Security:
- Maintain HIPAA Security Rule safeguards (Administrative, Physical, Technical)
- Support internal and external audits
- Conduct periodic security risk assessments
- Manage Business Associate Agreement (BAA) security reviews
Security Engineering & Continuous Improvement:
- Implement security automation workflows
- Improve mean time to detect (MTTD) and mean time to respond (MTTR)
- Run phishing simulations and security awareness campaigns
- Develop metrics dashboards for executive reporting
Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Information Systems, or related field, * 5-10 years of hands-on cybersecurity experience
- 3+ years in healthcare or highly regulated industry required
- Direct experience operating SIEM platforms (e.g., Splunk, Microsoft Sentinel)
- Hands-on experience with XDR/MDR platforms (e.g., CrowdStrike, Sentinel One, Microsoft Defender)
- Experience managing SOC workflows and alert triage
- Experience securing cloud environments (Azure, AWS, Microsoft 365)
- Strong understanding of HIPAA compliance requirements
Technical Skills & Certifications:
- SIEM configuration and log ingestion management
- XDR / MDR implementation and optimization
- SOC ticketing workflows and escalation procedures
- Vulnerability management tools (Tenable, Rapid7, Qualys)
- Email security and phishing detection
- IAM, SSO, MFA, and privileged access management
- Endpoint hardening and patch governance
- AI risk monitoring and governance controls
- Certifications: CISSP, CISM, CISA, CCSP, Security+, CRISC, CPHIMS, CHPS
Soft Skills:
- Excellent customer service and communication skills, with a patient, professional, and empathetic approach.
- Ability to prioritize tasks and manage time effectively in a busy environment.
- Strong problem-solving abilities and keen attention to detail., Physical Requirements: Must possess manual dexterity to operate office machines including computer and calculator; stooping and bending to handle files and supplies; and mobility to complete errands or deliveries. Includes handling of sharps and chemicals.
Benefits & conditions
Our competitive benefits package includes the following:
- Medical, Dental, and Vision insurance
- Short-term/Long-term disability
- Life and other voluntary plans
- 401(k) plan
- Employee Referral Program
- Paid Time-Off
- Company-Paid Holidays
About the company
Platinum Dermatology Partners is a network of high-quality dermatology clinics that focus on collaborative and innovative ideas to drive growth. We offer general dermatology, cosmetic, medical, plastic surgery, and cancer screening treatments. We have over 145 clinics, over 350 providers, and more than 2300 employees in clinics across Texas, Arizona, California, Nevada, and Florida. We are a rapidly growing company that allows our doctors to focus on providing exceptional care without worrying about the operational side of the business. Our core values focus on collaboration, ownership, respect, excellence, authenticity, and integrity. Our purpose is to empower the practice of exceptional dermatology.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
The Most Popular IT Jobs on the Market
Understanding and Mitigating Common Web Vulnerabilities