Manager, Information Security
QualDerm Partners · Brentwood, TN · 2 wk ago
On-siteInformation TechnologyFull-time
About the Role
Our organization operates a network of healthcare facilities and is investing in building out a mature, right-sized information security program to protect patient data, clinical operations, and business systems across all sites. We are seeking a Manager, Information Security to own the company's overall security posture end-to-end.
Responsibilities
- Security Strategy & Program Ownership:
- Own and evolve the company's overall information security strategy, roadmap, and maturity model.
- Act as the senior-most day-to-day security leader, briefing leadership on risk posture, incidents, and program progress.
- Define, track, and report on security KPIs/metrics (risk reduction, vulnerability remediation SLAs, incident response times, control coverage).
- Build and manage information security tooling, staffing, and third-party assessments.
- Hands-On Security Architecture & Engineering:
- Design and implement security architecture across identity, network, endpoint, cloud (Azure), and application layers.
- Own technical implementation and tuning of core security tooling: SIEM/SOAR, EDR/XDR, vulnerability management, email security, DLP, CASB, and identity/access management (Azure AD/Entra ID, PAM, MFA/conditional access).
- Design and enforce network and cloud security architecture in partnership with IT Infrastructure & Cloud teams.
- Lead vulnerability management and penetration testing programs.
- Governance, Risk & Compliance:
- Own compliance posture for HIPAA and applicable state/federal regulations.
- Conduct enterprise risk assessments, third-party/vendor security reviews, and manage business associate agreements (BAAs).
- Develop, maintain, and test incident response, disaster recovery, and business continuity plans.
- Serve as key point of contact for security audits, regulatory inquiries, and cyber insurance.
- Incident Response & Threat Management:
- Lead detection, response, and remediation for security incidents.
- Own threat intelligence monitoring and proactive threat hunting.
- Maintain and improve security monitoring and alerting environment.
- Security Awareness & Culture:
- Design and lead company-wide security awareness and phishing simulation programs.
- Partner with HR, Compliance, and clinical leadership to embed security practices into workflows.
- Build collaborative relationships with stakeholders to drive security adoption.
- Cross-Functional Partnership:
- Partner with IT Infrastructure & Cloud teams on initiatives like Azure migrations, site launches, and M&A integrations.
- Participate in technical due diligence for M&A and de-novo site launches.
- Advise on secure design practices for applications, data, and clinical systems.
Requirements
- Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
- 8+ years of progressive information security experience, including hands-on roles like Security Architect or Engineer.
- 2+ years in a security leadership role, owning strategy and program direction.
- Deep experience with identity/access management, network security, endpoint/EDR, cloud security (Azure preferred), vulnerability management, and SIEM.
- Experience building or maturing a security program from the ground up.
- Working knowledge of healthcare regulatory frameworks (HIPAA, HITECH); HITRUST or SOC 2 experience a plus.
- Experience leading incident response and coordinating with legal/executive teams.
- Strong communication skills, translating technical risk for non-technical stakeholders.
Preferred Qualifications
- Certifications: CISSP, CISM, CCSP, or Microsoft Certified: Azure Security Engineer Associate.
- Experience in multisite healthcare delivery organizations.
- Experience with M&A security due diligence and integration.
- Familiarity with EHR/clinical systems and their security requirements.
- Prior experience as the most senior security leader in an organization.
Benefits
- Competitive pay and comprehensive health coverage (Medical, Dental, Vision).
- Generous 401(k) plan with company match.
- Paid Time Off (PTO) and paid holidays.
- Company-paid life insurance and disability protection.
- Additional wellness plans and Employee Assistance Program (EAP).
- Exclusive employee discounts and referral bonus program.
QualDerm Partners is an equal opportunity employer committed to diversity and inclusion. Applicants must be authorized to work in the United States on a full-time basis.