Director, Security Governance
When you join the growing BILH team, you're not just taking a job, you’re making a difference in people’s lives. The Director of Security Governance, Risk & Compliance leads and manages the Governance Risk and Compliance (GRC) function and partners with the IT Security Leader to manage an organization-wide information risk management program, security compliance program, and security awareness campaign.
Responsibilities
- Leads IT Security Governance, Risk and Compliance program.
- Collaborates with IT Security Leader on building a culture focused on proactive risk management and security best practices.
- Leads IT Security Steering Committee, infusing information security governance procedures that foster resiliency, raise awareness, govern policy, and review security-related activities.
- Provides clear risk-mitigating directives for projects with IT components.
- Develops, implements, and executes BILH-wide information security training and awareness programs; provides professional and technical training and direction for internal team members as well as external staff.
- Facilitates and participates in annual internal/external audits using industry-standard security methods to help strengthen internal security controls, procedures, and policies.
- Investigates security incidents, develops remediation plans, and works with appropriate stakeholders to implement resolutions.
- Serves as a lead advisor on security matters to ensure appropriate levels of security are integrated into process designs and architecture; demonstrates ability to be a respected information security advisor to senior management and the IT Shared Service team.
- Works with the IT Security team in the development and acceptance of IT policies and procedures; ensures program standards follow applicable State and Federal regulatory requirements.
- Stays current with all relevant IT security and compliance issues, technologies, and requirements, as well as emerging best practices in IT program management, planning, and governance; maintains professional and technical knowledge by attending industry workshops, conferences, and participating in personal and professional networks.
- Has authority to direct and support employees' daily work activities, including hiring, termination, corrective action, and performance reviews.
Direct Reports: 2-3
Requirements
- Bachelor's degree required; Master's degree or Law degree preferred.
- More than 10 years of related work experience, including 3-5 years of supervisory/management experience.
- At least 10 years of varied information technology management experience, with five years directly related to IT program management, planning, and computer, information, and network security assessment, administration, and management.
- Experience in the healthcare industry is essential, along with knowledge of program management, information security technology, medical records, patient privacy, and confidentiality.
- Project planning and project management experience.
- Advanced technical computer skills as required for technical support specific to the functional area and related systems.
Pay
Annual base salary range: $176,800.00 USD - $205,920.00 USD. Actual compensation is determined based on factors such as seniority, education, training, relevant experience, relevant certifications, geography of work location, and job responsibilities.
Additional Information
As a healthcare organization, Beth Israel Lahey Health requires all staff to be vaccinated against influenza (flu) as a condition of employment.