Jobs · Information Technology · Texas

Executive Director IT Security & CISO

JPS Health Network · Fort Worth, TX · 2 days ago
Information TechnologyFull-time

Job Summary

The Executive Director IT Security & CISO provides strategic leadership for the organization's enterprise information security and cyber resilience program. Reporting to the SVP Chief Information Officer, this role serves as the HIPAA Security Official and is accountable for cybersecurity strategy, governance, architecture, operations, identity and access management, data protection, incident response, regulatory compliance, and third-party risk management.

Essential Job Functions & Accountabilities

  • Develops and executes the enterprise information security strategy and multi-year roadmap, defines the enterprise cybersecurity risk appetite in coordination with executive leadership and the Board, and ensures alignment with clinical, operational, and financial priorities.

  • Establishes and maintains the information security governance framework covering policies, standards, procedures, exceptions, and control ownership, and directs alignment with the NIST Cybersecurity Framework, NIST 800-53, and HITRUST.

  • Serves as the designated HIPAA Security Official with overall final responsibility for the security of electronic protected health information. Reports information security posture, risk, and program performance to the CEO, SVP Chief Information Officer, executive leadership, and the Board, and leads ongoing cybersecurity education to strengthen executive and Board risk literacy.

  • Pairs with the IT Security Risk Manager in the Office of Legal Affairs as the independent second-line risk oversight function, receives independent risk review findings, and drives remediation to closure.

  • Directs security architecture across cloud, on-premises, hybrid, and as-a-service environments and owns the Zero Trust roadmap across identity, network, workload, endpoint, and device domains.

  • Directs the enterprise Identity and Access Management program through the IAM Manager, including role-based access, access certification, multi-factor authentication, single sign-on, and Privileged Access Management.

  • Directs security operations, security engineering, endpoint protection, vulnerability management, patch management, threat detection, and coordinates with Managed Security Service Providers through the Security Manager.

  • Directs enterprise data protection strategy covering classification, encryption, key management, Data Loss Prevention, backup and recovery security controls, and controls for inter-organization, intra-organization, and extra-organization clinical data movement.

  • Directs the insider threat program and partners with the Office of Legal Affairs, Compliance, and Research on data governance for secondary data use, analytics, and artificial intelligence model training.

  • Owns the enterprise cybersecurity incident response program including plan development, playbook maintenance, tabletop and functional exercises, and leads the technical response to active incidents in partnership with the Office of Legal Affairs, which owns HIPAA breach notification to the Office for Civil Rights and affected individuals.

  • Pairs with Clinical Operations and IT Infrastructure to validate downtime procedures, disaster recovery readiness, and cyber-related business continuity plans so that patient care continues during technology disruptions and informs Due Care standards for the cyber insurance program managed by the Office of Legal Affairs.

Qualifications

  • Bachelor's Degree in Cybersecurity, Information Systems, Computer Science, Business Administration, Health Informatics, or related field of study from an accredited college or university.

  • 10 plus years of information security experience; to include experience protecting complex clinical, business, and infrastructure environments in a healthcare setting, operating within a county, public, academic, safety net, or federally qualified health center environment, and experience building or maturing a security program with full budget accountability.

  • 5 plus years of progressive leadership experience working in an information security role within a healthcare provider, health system, academic medical center, or similarly regulated environment; to include experience leading enterprise incident response for a material cybersecurity event.

  • One of the following certifications: Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) required.

Similar jobs

Director of IT Security

ETAP SoftwareIrvine, CA· 2 mo ago
Information Technology$138k–$230k/yrapply on aveva.wd3.myworkdayjobs.com