IT Security Director
hace 2 días
Garden City
Responsibilities Client Advisory & Engagement • Lead security assessments for the organization, identifying gaps, risks, and improvement opportunities across infrastructure, applications, cloud environments, and organizational processes., • Present findings and recommendations to technical and nontechnical stakeholders with clarity and confidence., • Serve as a trusted advisor on security architecture, compliance requirements, and bestpractice frameworks relevant to healthcare organizations. Security Engineering & Operations • Implement, configure, and manage security controls across Active Directory, Azure, IAM, endpoint protection, network security, and cloud environments., • Oversee or support Epic Security administration, access governance, and template/role design., • Develop and execute vulnerability management processes, including scanning, remediation planning, and reporting., • Support or lead incident response activities, including triage, containment, investigation, documentation, and breach notification coordination. Governance, Risk & Compliance • Conduct ongoing risk assessments, threat/vulnerability analyses, and control evaluations aligned with healthcare regulatory requirements (e.g., HIPAA, HITECH) and industry frameworks., • Develop, maintain, and implement security policies, standards, and procedures., • Support audit readiness and audit response activities., • Lead or contribute to Disaster Recovery and Business Continuity planning, testing, and program management. Program Leadership & Continuous Improvement • Design and oversee security program components such as monitoring, logging, SIEM use cases, DLP, identity governance, and access review processes., • Drive continuous improvement initiatives across security operations, compliance workflows, and client service delivery., • Deliver or coordinate security awareness training and promote a culture of security across Medisys Health Network., • Collaborate with leadership to ensure alignment between security strategy, operational execution, and requirements. Qualifications • 7+ years of experience in Information Security, with a blend of engineering, consulting, and program leadership responsibilities., • Team player with strong collaboration skills, a positive attitude, and solution-oriented mindset., • Demonstrated ability to communicate complex concepts to business stakeholders, department heads, operating as a service provider to deliver value., • Strong understanding of healthcare regulatory requirements and security frameworks (HIPAA, NIST CSF, CIS Controls, SOC 2, etc.)., • Handson experience with IAM, Azure security, AD hardening, endpoint security, vulnerability management, and incident response., • Experience with Epic Security., • Industrystandard certifications strongly preferred: CISSP, CISM, HCISPP, Security+, CEH, or equivalent.