Jobs · Information Technology · Tennessee

Manager, Information Security

QualDerm Partners · Brentwood, TN · 2 wk ago
On-siteInformation TechnologyFull-time

About the Role

Our organization operates a network of healthcare facilities and is investing in building out a mature, right-sized information security program to protect patient data, clinical operations, and business systems across all sites. We are seeking a Manager, Information Security to own the company's overall security posture end-to-end.

Responsibilities

  • Security Strategy & Program Ownership:
    • Own and evolve the company's overall information security strategy, roadmap, and maturity model.
    • Act as the senior-most day-to-day security leader, briefing leadership on risk posture, incidents, and program progress.
    • Define, track, and report on security KPIs/metrics (risk reduction, vulnerability remediation SLAs, incident response times, control coverage).
    • Build and manage information security tooling, staffing, and third-party assessments.
  • Hands-On Security Architecture & Engineering:
    • Design and implement security architecture across identity, network, endpoint, cloud (Azure), and application layers.
    • Own technical implementation and tuning of core security tooling: SIEM/SOAR, EDR/XDR, vulnerability management, email security, DLP, CASB, and identity/access management (Azure AD/Entra ID, PAM, MFA/conditional access).
    • Design and enforce network and cloud security architecture in partnership with IT Infrastructure & Cloud teams.
    • Lead vulnerability management and penetration testing programs.
  • Governance, Risk & Compliance:
    • Own compliance posture for HIPAA and applicable state/federal regulations.
    • Conduct enterprise risk assessments, third-party/vendor security reviews, and manage business associate agreements (BAAs).
    • Develop, maintain, and test incident response, disaster recovery, and business continuity plans.
    • Serve as key point of contact for security audits, regulatory inquiries, and cyber insurance.
  • Incident Response & Threat Management:
    • Lead detection, response, and remediation for security incidents.
    • Own threat intelligence monitoring and proactive threat hunting.
    • Maintain and improve security monitoring and alerting environment.
  • Security Awareness & Culture:
    • Design and lead company-wide security awareness and phishing simulation programs.
    • Partner with HR, Compliance, and clinical leadership to embed security practices into workflows.
    • Build collaborative relationships with stakeholders to drive security adoption.
  • Cross-Functional Partnership:
    • Partner with IT Infrastructure & Cloud teams on initiatives like Azure migrations, site launches, and M&A integrations.
    • Participate in technical due diligence for M&A and de-novo site launches.
    • Advise on secure design practices for applications, data, and clinical systems.

Requirements

  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
  • 8+ years of progressive information security experience, including hands-on roles like Security Architect or Engineer.
  • 2+ years in a security leadership role, owning strategy and program direction.
  • Deep experience with identity/access management, network security, endpoint/EDR, cloud security (Azure preferred), vulnerability management, and SIEM.
  • Experience building or maturing a security program from the ground up.
  • Working knowledge of healthcare regulatory frameworks (HIPAA, HITECH); HITRUST or SOC 2 experience a plus.
  • Experience leading incident response and coordinating with legal/executive teams.
  • Strong communication skills, translating technical risk for non-technical stakeholders.

Preferred Qualifications

  • Certifications: CISSP, CISM, CCSP, or Microsoft Certified: Azure Security Engineer Associate.
  • Experience in multisite healthcare delivery organizations.
  • Experience with M&A security due diligence and integration.
  • Familiarity with EHR/clinical systems and their security requirements.
  • Prior experience as the most senior security leader in an organization.

Benefits

  • Competitive pay and comprehensive health coverage (Medical, Dental, Vision).
  • Generous 401(k) plan with company match.
  • Paid Time Off (PTO) and paid holidays.
  • Company-paid life insurance and disability protection.
  • Additional wellness plans and Employee Assistance Program (EAP).
  • Exclusive employee discounts and referral bonus program.

QualDerm Partners is an equal opportunity employer committed to diversity and inclusion. Applicants must be authorized to work in the United States on a full-time basis.

Similar jobs

Manager, Information Security

StellarusCalifornia, United States· 1 mo ago
Information Technology$123k–$185k/yrapply on ecge.fa.us2.oraclecloud.com