IT Security Director

Axa Equitable Life Insurance Company
New York, NY, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$166,400.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Microsoft Azure Cyber Security Disaster Recovery Identity and Access Management Network Security Security Information and Event Management Software Vulnerability Management Workflow Management Systems Data Logging Cloud Platform System Epic Security
+1 more
CIS Benchmarks

Job description

Client Advisory & Engagement

  • Lead security assessments for the organization, identifying gaps, risks, and improvement opportunities across infrastructure, applications, cloud environments, and organizational processes.
  • Present findings and recommendations to technical and non-technical stakeholders with clarity and confidence.
  • Serve as a trusted advisor on security architecture, compliance requirements, and best-practice frameworks relevant to healthcare organizations.

Security Engineering & Operations

  • Implement, configure, and manage security controls across Active Directory, Azure, IAM, endpoint protection, network security, and cloud environments.
  • Oversee or support Epic Security administration, access governance, and template/role design.
  • Develop and execute vulnerability management processes, including scanning, remediation planning, and reporting.
  • Support or lead incident response activities, including triage, containment, investigation, documentation, and breach notification coordination.

Governance, Risk & Compliance

  • Conduct ongoing risk assessments, threat/vulnerability analyses, and control evaluations aligned with healthcare regulatory requirements (e.g., HIPAA, HITECH) and industry frameworks.
  • Develop, maintain, and implement security policies, standards, and procedures.
  • Support audit readiness and audit response activities.
  • Lead or contribute to Disaster Recovery and Business Continuity planning, testing, and program management.

Program Leadership & Continuous Improvement

  • Design and oversee security program components such as monitoring, logging, SIEM use cases, DLP, identity governance, and access review processes.
  • Drive continuous improvement initiatives across security operations, compliance workflows, and client service delivery.
  • Deliver or coordinate security awareness training and promote a culture of security across our Health Network.
  • Collaborate with leadership to ensure alignment between security strategy, operational execution, and requirements.

Requirements

Do you have experience in Teamwork?, We are seeking a Senior or Principal-level IT Security Lead who can operate at the intersection of hands-on engineering, strategic advisory, and leadership execution.

This role is responsible for assessing, implementing, and managing comprehensive security programs -spanning technical controls, governance, risk, compliance, and incident response.

The ideal candidate brings deep technical expertise, strong leadership communication skills, and the ability to translate complex security requirements into practical, scalable solutions., * 7+ years of experience in Information Security, with a blend of engineering, consulting, and program leadership responsibilities.

  • Team player with strong collaboration skills, a positive attitude, and solution-oriented mindset.
  • Demonstrated ability to communicate complex concepts to business stakeholders, department heads, operating as a service provider to deliver value.
  • Strong understanding of healthcare regulatory requirements and security frameworks (HIPAA, NIST CSF, CIS Controls, SOC 2, etc.).
  • Hands-on experience with IAM, Azure security, AD hardening, endpoint security, vulnerability management, and incident response.
  • Experience with Epic Security.
  • Industry-standard certifications strongly preferred: CISSP, CISM, HCISPP, Security+, CEH, or equivalent.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all