Job Summary The Senior Director of Information Security is responsible for developing, leading, and overseeing the organization's global information security and IT compliance programs. This role ensures that IT systems and data are secure, compliant, and aligned with regulatory and industry standards. The ideal candidate will bring deep expertise in NIST cybersecurity frameworks, HITRUST CSF certification, ISO/IEC 27001 and other cybersecurity frameworks, laws and regulations. Duties & Responsibilities Security Strategy & Leadership
- Develop and execute the enterprise-wide IT security strategy aligned with business goals.
- Lead the security operations function, overseeing incident response, threat management, and vulnerability remediation.
- Drive adoption of a risk-based, defense-in-depth security architecture across IT systems, applications, and cloud services.
Compliance & Risk Management
- Lead and maintain compliance programs for NIST CSF, HITRUST, ISO 27001, PCI DSS and other relevant data protection laws and regulations.; oversee certification and audit processes.
- Serve as the primary liaison with external auditors and regulatory bodies during compliance assessments.
- Monitor, assess, and report on security and compliance risks to executive leadership and the board.
- Develops and implements information security and disaster recovery programs in accordance with organizational information security standards.
Governance & Policy
- Develop and maintain security and compliance policies, standards, and procedures based on industry best practices.
- Ensure alignment with legal, regulatory, and contractual obligations including HIPAA, GDPR, and other data privacy laws.
Team Management & Collaboration
- Build, lead, and mentor a team of security and compliance professionals.
- Oversee and collaborate with IT, Legal, HR, Product, Engineering and other key business leaders to embed security and compliance into daily operations.
- Promote a culture of security awareness and continuous improvement throughout the organization.
Minimum & Preferred Qualifications and Experience Minimum Qualifications
- 10+ years of experience in IT security and/or compliance, including 5+ years in a leadership role.
- Industry certifications such as CISSP, CISA, CISM, CRISC, and/or ISO 27001 Lead Implementer/Auditor.
- Deep knowledge and practical experience with NIST (800-53, CSF), HITRUST CSF, and ISO/IEC 27001.
- Proven experience leading certification/audit readiness, gap assessments, remediation, and ongoing compliance monitoring.
- Strong understanding of risk management principles, security architecture, identity management, and incident response.
- Excellent communication and stakeholder management skills, including the ability to translate technical risks to business impact.
- Hands-on experience with security solutions; Endpoint Protection, Firewall, Intrusion Prevention and Detection, Advance Malware Protection, SIEM, Encryption, Data Loss Prevention, Identity Management, etc.
Preferred Qualifications
- Experience in regulated industries such as healthcare or medical technology (e.g., HIPAA, FDA 21 CFR Part 11).
- Familiarity with security in cloud environments (AWS, Azure, etc.) and SaaS governance.
Education Bachelor's degree required, preferably in Computer Science, Engineering or related field. Master's degree preferred. Compensation The anticipated salary range for this position is $220,000 - $260,000 plus benefits. Actual placement within the range is dependent on multiple factors, including but not limited to skills, education, and experience. This position also qualifies for up to 25% annual bonus based on Company, department, and individual performance. Physical requirements/Work Environment This position primarily works in an office environment. It requires frequent sitting, standing and walking. Daily use of a computer and other computing and digital devices is required. May stand for extended periods when facilitating meetings or walking in the facilities. Some local travel is necessary, so the ability to operate a motor vehicle and maintain a valid Driver's license is required. The physical demands of the position described herein are essential functions of the job and employees must be able to successfully perform these tasks for extended periods. Reasonable accommodations may be made for those individuals with real or perceived disabilities to perform the essential functions of the job described.
|