Jobs · Information Technology

Director, Cyber Security Risk Management, Infrastructure Protection

Community Health Systems · United States · 4 days ago
RemoteRemoteInformation TechnologyFull-time

Job Summary

As a member of the Cybersecurity organization, the Cyber Security Director, Infrastructure Protection leads the strategy, implementation and continuous improvement of critical cybersecurity programs, ensuring the successful delivery and operations of infrastructure security controls and processes across the CHS Enterprise. The Director is responsible for leading, managing, and developing a team of cybersecurity managers and professionals driving the success of critical initiatives and programs. This role collaborates with Cyber Architecture, IT and other stakeholders to assess risks, define strategies, and deliver business and functional requirements and applicable use-cases of focus areas in order to implement and govern processes and controls that reduce risk and exposure to the organization.

About the Role

The Infrastructure Protection department within the Cybersecurity Risk Management (CSRM) organization ensures successful delivery and operations of critical security controls across the CSH Enterprise related to Network Protection, Endpoint Protection and Cloud Security. The Director, Infrastructure Protection leads all facets of the program. The role has responsibility for the overall strategic direction of the program, including the people, processes and technologies involved.

Responsibilities

  • Lead the planning, development, and strategic implementation of multiple cybersecurity programs across the organization.
  • Oversee and guide a team of managers and engineers, ensuring leadership in mentorship, performance management, and fostering a high-performance culture.
  • Collaborate with cross-functional leaders, ensuring cybersecurity strategies align with business objectives and regulatory requirements at a broader level.
  • Direct organization-wide risk assessments, overseeing the identification and management of cybersecurity risks across all systems and data environments. Present risk mitigation strategies to senior leadership, including measurable metrics that demonstrate program effectiveness and security posture improvements.
  • Lead initiatives to optimize cybersecurity processes, driving organization-wide improvements in efficiency and effectiveness.
  • Serve as a key advisor across the organization, aligning security programs with operational needs and strategic business goals. Develop and manage cross-departmental relationships to ensure cybersecurity capabilities evolve to meet both current and future business requirements. Partner closely with enterprise-wide teams to deliver critical cybersecurity initiatives, ensuring on-time and high-quality delivery.
  • Communicate complex cybersecurity concepts and strategies to executives, external partners, and non-technical teams. Ensure comprehensive compliance with all regulatory, legal, and internal security standards, keeping cybersecurity policies up to date with industry best practices. Deliver regular performance reports to senior leadership, highlighting key metrics, risks, and improvements.
  • Lead high-impact cybersecurity projects, coordinating multiple teams and stakeholders to meet organizational goals. Manage vendor relationships, negotiating and ensuring third-party solutions meet strategic cybersecurity objectives.

Qualifications

  • Bachelor's Degree in Information Security, Computer Science, Information Technology, or a related field required.
  • Master's Degree in Cyber Security, Computer Science, Information Systems, or other related field preferred.
  • 8-10 years of progressive experience in cybersecurity or information security roles required.
  • 4-6 years of leadership experience managing cybersecurity teams and programs required.
  • Experience leading enterprise risk assessments, regulatory compliance initiatives, and security operations in a complex environment preferred.

Skills and Abilities

  • Expert knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001), regulatory standards, and risk management practices.
  • Strong leadership and team development skills.
  • Excellent verbal and written communication skills, including the ability to convey complex security issues to non-technical stakeholders.
  • Prowess in building cross-functional partnerships and influencing organizational strategy.
  • Strong analytical, critical thinking, and problem-solving abilities.
  • Ability to manage multiple priorities and large-scale projects simultaneously.

Knowledge, Skills And Abilities

  • Industry certifications such as Security+, GSEC, SSCP, CISM, CISSP, GIAC, OSCP, or ITIL Certifications preferred.

Similar jobs