Jobs · Information Technology · New York

IT Security Governance Lead

Stony Brook Medicine · Stony Brook, NY · 4 days ago
Information Technology$87k–$117k/yrFull-time

About the role

The IT Governance Lead position at Stony Brook Medicine is responsible for driving enterprise identity governance, access control, and cloud security strategy. This senior role ensures alignment with Zero Trust principles, least privilege, and regulatory requirements (HIPAA, NYS, SUNY, NIST) while partnering with Systems and Engineering teams for operational execution.

Responsibilities

  • Establish and enforce cloud access governance policies (RBAC/ABAC)
  • Design and oversee authorization models across cloud platforms (OCI and hybrid environments)
  • Define and govern access controls for enterprise clinical systems (e.g., Oracle Health / Cerner)
  • Lead access certification reviews and enforce least privilege principles
  • Manage Privileged Access Management (PAM/PIM) strategy and controls
  • Monitor identity risk signals and privileged account activity
  • Align identity governance with HIPAA, NYS, SUNY, and NIST frameworks
  • Partner with Architecture, Cloud, Application, and Clinical IT teams for secure design
  • Enforce segregation of duties (SoD) and access controls
  • Determine who should have access and under what conditions
  • Define access control policies and governance standards
  • Drive risk-based access decisions and control enforcement
  • Ensure audit readiness and regulatory compliance, including clinical system access
  • Collaborate with Stony Brook MIT Systems Conditional Access & MFAD
  • Define governance & policy
  • Define roles and approval requirements
  • Own access reviews
  • Own certification process
  • Own identity incident response
  • Lead investigation and strategy
  • Define requirements and reviews anomalies
  • Own operations separation of authentication (Systems) and authorization (InfoSec)
  • Own scalable governance model supporting cloud and healthcare platforms (OCI/Cerner)

Qualifications

  • Bachelor’s degree in Technology (Computer Science, InfoSec, or related field)
  • 5+ years of experience in Identity & Access Management (IAM), or Identity Governance such as: Identity Governance & Administration (IGA), RBAC / ABAC models, PAM/PIM solutions, Cloud platforms (OCI, Azure, AWS, or GCP)

Preferred Qualifications

  • Direct experience with Oracle Cloud Infrastructure (OCI) and Oracle Health (Cerner) access models
  • Experience supporting or securing enterprise healthcare/clinical systems (e.g., Oracle Health / Cerner, Epic, or similar)
  • Experience governing access to clinical workflows, sensitive patient data, and provider roles
  • Familiarity with Microsoft Entra ID / Azure AD governance
  • Experience with Zero Trust architectures and conditional access
  • Relevant certifications (CISSP, CISM, CRISC, CCSP)
  • Understanding of HIPAA Security Rule and NIST frameworks (800-53, 800-207)

Similar jobs

IT Governance & Strategy Lead

NTT DATA North AmericaArlington, VA· Today
Information Technology$113k–$188k/yrapply on careers.services.global.ntt

IT Governance

ISACA Bosnia and Herzegovina ChapterLinwood, KS· 1 wk ago
Information Technology$108k/yrapply on isaca.org

Lead IT Governance Analyst

Capio GroupSacramento, CA· 1 mo ago
RemoteInformation Technology$135k–$140k/yrapply on capiogroup.applytojob.com