Job Summary
Key Responsibilities
Strategy & Leadership
• Define and execute the hospital’s cyber security strategy across infrastructure, applications, and cloud
• Establish security principles and standards aligned with clinical and operational realities
• Act as the primary cyber security advisor to CIO, CISO, and clinical leadership
• Build, lead, and mentor security architects, engineers, and operational teams
Infrastructure & Platform Security Ownership
• Own security posture for:
o Network, endpoint, server, and cloud environments
o Identity and access management
o Backup, disaster recovery, and ransomware resilience
• Drive zero-trust adoption while accounting for legacy and clinical systems
• Ensure medical devices and shared clinical workstations are governed under a risk-based model
Application & Digital Security Leadership
• Govern security for clinical and enterprise applications, including EHR and third-party platforms
• Establish secure development and deployment standards across internal and vendor-built systems
• Oversee application risk assessments, threat modeling, and remediation prioritization
• Ensure secure integrations, APIs, and data flows across the hospital ecosystem
Risk, Compliance & Resilience
• Own cyber risk management aligned with healthcare regulations and frameworks (HIPAA, HITRUST, NIST)
• Lead audit readiness, regulatory responses, and executive risk reporting
• Drive ransomware preparedness, incident response, and recovery planning
• Partner with legal, compliance, and privacy teams on breach response and regulatory obligations
Operational Excellence & Metrics
• Define security KPIs and executive dashboards tied to risk reduction and business outcomes
• Prioritize investments based on risk, patient safety, and operational impact
• Oversee vulnerability management, patching strategy, and third-party risk programs
• Ensure SOC capabilities align with hospital threat landscape
Required Qualifications
• 12+ years of cyber security experience with progressive leadership responsibility
• Proven experience leading cyber security in healthcare or similarly regulated environments
• Strong background across infrastructure, application, and cloud security
• Ability to communicate cyber risk in plain language to executives and clinicians
• Experience managing budgets, teams, and security roadmaps