IT Security Program Manager
Recovery Centers of America · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
Reporting to the manager of infrastructure under the IT OPS director, this role ensures Recovery Centers of America’s security posture remains compliant with HIPAA, HITECH, and NIST 800-53 standards while continuously improving the effectiveness of the organization’s security controls and risk management framework.
Responsibilities
- Manage the daily operations of RCA’s cybersecurity program under the guidance of the CISO.
- Coordinate and track the completion of internal and external security audits, including HIPAA, SOC 2, and NIST-based assessments.
- Maintain and monitor the Information Security Risk Register, ensuring timely resolution of identified issues and mitigation of critical findings.
- Lead tabletop exercises and incident response simulations to test and improve RCA’s preparedness and business continuity planning.
- Collaborate with RCA leadership and department heads to ensure that security policies and controls are understood and effectively implemented across all business units.
- Manage the third-party risk assessment program, ensuring that all vendors with access to PHI or critical systems undergo security evaluation and periodic reassessment.
- Review BAAs, security questionnaires, and compliance attestations; ensure corrective action for identified gaps.
- Partner with Procurement and Legal to integrate security requirements into new and existing vendor contracts.
- Work with the CISO to review, update, and publish information security policies, standards, and procedures in accordance with HIPAA, HITECH, and NIST frameworks.
- Develop dashboards and recurring reports to track security metrics, compliance posture, and program maturity for presentation to the CISO and executive leadership.
- Monitor and interpret changes to regulatory requirements, ensuring timely updates to RCA’s compliance program.
- Administer and optimize RCA’s KnowBe4 Security Awareness and Phishing Training Program.
- Track user engagement and training completion rates, and provide metrics and recommendations to leadership.
- Develop creative awareness campaigns to strengthen RCA’s security culture.
- Identify and track critical infrastructure vulnerabilities, working with IT and Infrastructure teams to ensure remediation and continuous monitoring.
- Oversee MDM security, ensuring appropriate device controls, encryption, and enforcement of mobile security policies.
- Support the CISO in analyzing threat intelligence, vulnerability trends, and endpoint security performance (e.g., CrowdStrike, firewall alerts).
- Ensure continuous compliance with HIPAA, HITECH, and NIST 800-53 / 800-171 requirements.
- Coordinate with Compliance, Legal, and Clinical leadership to ensure consistent risk management practices.
- Participate in post-incident reviews, documenting lessons learned and recommending process improvements.
Requirements
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field.
- Minimum of 5–7 years of progressive experience in cybersecurity, IT risk management, or audit within a regulated environment (preferably healthcare).
- At least 2 years in a program management or leadership role overseeing information security functions.
- Strong working knowledge of HIPAA, NIST 800-53, HITRUST, and security risk management frameworks.
- Understanding of endpoint protection, SIEM tools, MDM platforms (e.g., Intune), and vulnerability management solutions.
- Experience with vendor risk tools, audit tracking systems, and compliance reporting.
- Familiarity with Microsoft 365 Security Suite, KnowBe4, and GRC platforms.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills, with the ability to translate technical risks for non-technical stakeholders.
- Highly organized and detail-oriented, with the ability to manage multiple priorities simultaneously.
- Demonstrated ability to build cross-functional relationships and drive accountability.
- Passionate about RCA’s mission and maintaining the privacy and security of patient information.
Qualifications
- Certifications (preferred but not required): Security+, CISSP, CISM, CRISC, HCISPP, or equivalent security certification.
- PMP or similar project management certification is a plus.
Schedule
- This position is primarily remote.
- Limited travel is required.