Information Security Manager (ISM/HIPAA Security Officer)
Role details
Job location
Tech stack
Job description
The Information Security Manager (referred to as ISM hereafter) owns, develops, implements, and continuously improves the organization's Information Security Program to protect internal information systems, sensitive data, and electronic Protected Health Information (ePHI).
This position serves as the organization's designated HIPAA Security Officer, responsible for implementing and managing the technical and administrative safeguards required under the HIPAA Security Rule. The Information Security Manager is the organization's technical security authority, accountable for cybersecurity governance, risk assessments, security operations, incident response readiness, and the administration and oversight of enterprise security technologies.
This is both a strategic and hands-on role within a lean IT environment, providing leadership, governance, monitoring, and direct operational support across Microsoft 365 technologies (Entra ID, SharePoint, Teams, OneDrive, Purview) and related cybersecurity platforms such as Arctic Wolf and Netwrix.
The ISM represents the organization in collaboration with the Health Center Controlled Network (HCCN), Primary Care Association (PCA), and peer Federally Qualified Health Centers (FQHCs) to address evolving cybersecurity risks, regulatory requirements, and emerging technologies.
Collaboration
The ISM collaborates closely with the Quality Improvement & Compliance Director, HIPAA Privacy Officer, Risk Manager, Information Technology leadership, General Counsel, and Executive Leadership to ensure alignment of information security, regulatory compliance, HIPAA privacy, and enterprise risk management activities.
Requirements
-
Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)., * Minimum of 5 years of progressive experience in cybersecurity or information security roles; 7+ years preferred.
-
At least 2 years in a security leadership, governance, healthcare security, or HIPAA Security capacity (3+ years preferred).
-
Experience in a HIPAA-regulated healthcare environment strongly preferred.
-
Experience with MDR platforms (e.g., Arctic Wolf) and Microsoft 365 security tooling preferred.
Benefits & conditions
Pulled from the full job description
-
403(b) matching
-
403(b)
-
AD&D insurance
-
Health insurance
-
Paid time off
-
Vision insurance
-
Dental insurance, * Completion of the annual HIPAA Security Risk Analysis and documented mitigation plan.
-
Percentage of high-risk vulnerabilities remediated within defined SLA timelines.
-
Mean time to detect and respond to security incidents.
-
Phishing simulation program coverage, frequency, and year-over-year improvement trend.
-
Security program maturity (e.g., NIST CSF tier progression measured via annual assessment).
-
Year-over-year reduction in residual risk on the cybersecurity risk register.
-
Completion of security roadmap milestones against the multi-year security program plan.
-
Incident response performance - percentage of incidents handled per playbook and timely closure of post-incident corrective actions.
-
Completion of scheduled tabletop exercises and documented remediation of identified gaps.
At Community Health Alliance, we are committed to supporting our employees both personally and professionally by offering a comprehensive and competitive benefits package.
Our team members enjoy benefits that include:
- Competitive Wage:100,000-125,000
- 100% company paid employee medical insurance and 90% paid vision and dental on the first of the month following 60 days from date of hire.
- Paid Time Off:
- PTO 15 days/year and increased after one years of service: pro-rated based on FTE status
- 8 paid holidays per year
- CHA paid pension plan at 5% of earnings after one year of service; no employee match
- Additional 403(b)retirement annuity plan for employee to save; no employer match
- CHA provides a $10,000 Accidental Death & Dismemberment policy for each benefit-eligible employee at no cost to the employee.
We are proud to invest in our employees by providing meaningful benefits, professional development opportunities, and a workplace dedicated to helping you build a rewarding career while making a difference in the communities we serve.