> Markdown version of [/jobs/ext/542734-director-of-information-security-risk](https://www.wearedevelopers.com/jobs/ext/542734-director-of-information-security-risk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security & Risk - **Company:** Children's Hospital Association - **Location:** Lenexa, KS, United States (Remote available) - **Experience:** Experienced - **Salary:** $113,000.0 - $204,000.0 - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Big Data, Software as a Service, Cloud Computing, Cloud Database, Cloud Engineering, Cyber Security, Information Systems, Data Governance, Data Security, Fraud Prevention and Detection, Identity and Access Management, Information Security Management, Intrusion Detection and Prevention, Network Security, Machine Learning, Enterprise Data Management, Cloud Platform System, Delivery Pipeline, Information Technology, Data Analytics, Machine Learning Operations - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d371e93376276a4c ## About the Role Do you have experience in Senior leadership?, Do you have a Bachelor's degree?, Any combination of education and experience providing the required skill and knowledge is qualifying. * Bachelor's degree in computer science, Information Security, or related field. * Minimum 8 years in IT/Cybersecurity, with 3-5+ years in leadership roles within a SaaS, cloud-native, or technology-driven environment. * Strong understanding of data protection and privacy principles, risk management, and security compliance expectations. * Extensive experience with AWS or Azure security, IAM, data encryption, and network security. * Knowledge of risks related to AI/ML development pipelines and big data infrastructure. * Deep understanding of relevant security and privacy frameworks and requirements (e.g., HIPPA, HITRUST, HITECH, NIST, ISO 27001, SOC 2, and applicable privacy regulations). * CISSP, CISM, or CCSP certifications are highly preferred. ## Description The Director of Information Security & Risk is a senior strategic leader responsible for overseeing, securing, and continuously advancing the organization's enterprise information security program. This role provides governance and risk leadership across the organization, with a strong focus on risk management frameworks, security governance and controls, protection of cloud-based data assets, and securing AI/ML systems and data analytics pipelines. Owns the design, scalability, and maturity of the enterprise security program, ensuring the protection of sensitive information, compliance with regulatory and contractual requirements, and the secure growth of cloud-based platforms, products, and services. * Develop and execute a multi-year information security and risk management strategy aligned with organizational objectives, regulatory regulations, and recognized security frameworks. * Oversee the development, implementation, and maintenance of the enterprise security policy, standards, guidelines, and procedures. Translate legal, regulatory, and contractual requirements into enforceable technical security standards. * Draft and enforce the Enterprise Information Security Policy (EISP) framework, ensuring it evolves alongside AI advancements and Cloud scale. * Lead enterprise risk assessments, identifying and mitigating security risks associated with data analytics (Enterprise & Member Facing data), third-party cloud vendors, and new technology adoption. * Proposes security policies, procedures, initiatives, and standards specific to regulatory compliance, loss and fraud prevention, and breach prevention in both security and privacy. * Lead the strategy for securing hybrid/cloud environments and AI/ML model security, including training data protection and model inference monitoring. * Oversee data governance, classification, and secure data-sharing models for enterprise data platforms. * Manage annual compliance audits (SOC 2 Type II and NIST risk audit). * Identifies and addresses exposures to accidental or intentional destruction, disclosure, modification, or interruption of information that may cause regulatory compliance issues or serious financial and/or information loss. * Creates and maintains security system architecture design documentation. * Stays current on new IT security trends and understands potential threats and control techniques * Identify risks across the technology stack and lead incident response teams to detect, analyze, and mitigate threats. * Understands business needs, security risks and the company's risk tolerance and balance between them in a way that ensures business continuity and regulatory compliance. * Manage security operations, including 24x7 monitoring, threat detection, and incident response, leading post-incident forensics and remediation. * Coordinates active penetration tests; discovers vulnerabilities in information systems and identifies and implements solutions to resolve them. * Provide enterprise leadership by partnering with IT, business, legal, and risk stakeholders to embed Security by Design across cloud, AI, and analytics development lifecycles. * Develop and manage the information security budget, ensuring effective prioritization, scalability, and efficient use of resources. * Communicate security strategy, risk posture, and performance metrics to executive leadership through regular updates and dashboards. * Lead organization-wide security awareness and training programs to foster a strong culture of security and shared accountability. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Fireside Chat: Deep Learning, Deep Impact: Harnessing AI for Language Innovation](https://www.wearedevelopers.com/videos/612-fireside-chat-deep-learning-deep-impact-harnessing-ai-for-language-innovation) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Prompt Injection, Poisoning & More: The Dark Side of LLMs](https://www.wearedevelopers.com/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)