Associate Director, Cyber Defense

The Ohio State University
•Onsite

About The Position

The Associate Director, Cyber Defense is responsible for the strategic vision, governance, and maturation of the medical center's defensive security capabilities. Reporting directly to the OSUWMC Chief Information Security Officer (CISO), this role provides executive and operational oversight across four core pillars: governing our partner-led Managed Security Operations Center (mSOC), directing the enterprise Vulnerability Management program (encompassing IT, IoT, and medical IoT/mIoT devices), architecting a Threat Intelligence capability, and scaling the Incident Response (IR) function. A primary focus of this role is establishing strategic alignment and seamless collaboration between OSUWMC departments, the OSU Office of Technology and Digital Innovation (OTDI), and external security vendors. The Associate Director ensures threat-driven defense by maintaining runbooks, optimizing vendor performance against SLAs, and spearheading active, measurable iterative controls validation of the Information Security and Privacy Control Requirements (ISPCR). As a key member of the Information Security leadership team, this position requires an elevated level of autonomy, significant executive decision-making authority, and a proven track record of directly leading, mentoring, and growing technical cybersecurity teams. The Associate Director serves as a people leader responsible for driving staff engagement, fostering technical growth, and cultivating a high-trust team culture, alongside extensive experience steering third-party partners and cross-functional technical teams within a highly matrixed environment.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent combination of education and experience.
  • 7 years of progressive leadership experience in cybersecurity operations or engineering, with personnel management or supervisory experience leading technical teams.

Nice To Haves

  • Experience operating cybersecurity programs in highly regulated environments such as healthcare, higher education, government, or other critical infrastructure sectors.
  • Master’s degree in Cybersecurity, Business Administration (MBA), Healthcare IT, or a related field.
  • Active industry-standard certifications such as: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM)
  • Working knowledge of NIST Cybersecurity Framework (CSF), NIST 800-53, MITRE ATT&CK, CIS Controls, and healthcare-specific security guidance.
  • Proven experience establishing governance frameworks for and holding third-party managed service providers (MSSP/mSOC) accountable via strict SLAs.
  • Demonstrated success building, structuring, or significantly maturing cybersecurity functions (specifically Incident Response frameworks or Threat Intelligence programs) from the ground up.
  • Hands-on experience leading incident command structures and coordinating responses to enterprise-wide security incidents, breaches, or advanced threats.
  • Familiarity with modern vulnerability management concepts (risk-based prioritization vs. raw CVSS scoring) across enterprise and clinical environments.
  • Exceptional relationship management skills with a track record of translating complex technical threats into quantifiable business risk for senior medical center and university leadership.

Responsibilities

  • Governing partner-led Managed Security Operations Center (mSOC)
  • Directing the enterprise Vulnerability Management program (encompassing IT, IoT, and medical IoT/mIoT devices)
  • Architecting a Threat Intelligence capability
  • Scaling the Incident Response (IR) function
  • Establishing strategic alignment and seamless collaboration between OSUWMC departments, the OSU Office of Technology and Digital Innovation (OTDI), and external security vendors
  • Ensuring threat-driven defense by maintaining runbooks, optimizing vendor performance against SLAs, and spearheading active, measurable iterative controls validation of the Information Security and Privacy Control Requirements (ISPCR)
  • Leading, mentoring, and growing technical cybersecurity teams
  • Driving staff engagement, fostering technical growth, and cultivating a high-trust team culture
  • Steering third-party partners and cross-functional technical teams within a highly matrixed environment
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service