Deputy CISO

Availity
•Remote

About The Position

Availity is seeking a charismatic and accomplished technology leader to join the security leadership team as a Deputy CISO. Reporting to the CISO, the Deputy CISO will manage a team of 5 direct reports with a globally diverse matrix organization. Areas of focus for this role include Identity Access Management, Risk and Governance, Data Governance, Catastrophic Recovery, and Fraud Prevention. This role sits uniquely in a triangle of leadership reporting to the CISO and partnered with a Deputy CISO whose focus areas include Application Security, Security Operations, and Offensive Security. Drawing on the appropriate experiences in leadership roles in healthcare information security, the Deputy CISO will be responsible for establishing and maintaining the enterprise vision, strategy, architecture, and a multi-year information security roadmap that assures the company’s information assets and those of its customers are adequately protected. A key element of this role is communicating security at a strategic level to executive management, the Audit and Compliance Board, and the Board of Directors and evangelizing information security across the business to drive adoption of security best practices. Sponsorship, in any form, is not available for this position. Location: Remote US

Requirements

  • Bachelor's Degree in computer science, engineering, or a related field; (graduate degree preferred).
  • 10+ years of IT and/or business leadership experience
  • 5+ years of information security/cybersecurity experience
  • Proven experience delivering quality solutions in a SaaS environment
  • Understanding of Cloud, SaaS, and IoT architectures, and their implications on information security strategy, with previous experience in creating appropriately secure operating environments in the Cloud
  • Proven experience leading globally diverse teams and working closely with C-suite executives
  • A proven track record in developing information security policies and procedures, and successful execution
  • Extensive knowledge of business risk, risk assessment and risk-based decision making
  • Able to communicate security and risk-related concepts to both technical and non-technical audiences (in business terms), including board level
  • Proven ability to address and present information to a Board of Directors and/or Executive leadership team
  • A natural influencer and coalition builder; passionate about building high performing teams
  • Ability to inspire and motivate cross-functional, interdisciplinary teams to achieve tactical and strategic goals; an innovative leader, problem solver and consultant
  • Ability to evangelize IT security to make it a critical part of business operations; build trust and respect for the security function
  • Excellent written and verbal communication, interpersonal and collaborative skills
  • Experienced with contract and vendor negotiations
  • Experienced in incident and crisis management with the ability to effectively prioritize and execute tasks in high-pressure situations
  • Knowledge of security, risk and control frameworks and standards such as HITRUST, ISO 27001 and 27002, SANS-CAG, NIST, FISMA, COBIT, COSO and ITIL
  • Technical acumen including but not limited to: OSI, IT infrastructure, Cloud, application development languages, tools and frameworks, database technologies, web technologies, next gen mobile, network architecture, enterprise architecture, and directory services
  • Security technology acumen and experience including but not limited to: firewall, intrusion detection, cyber-attack tools and defenses, encryption, certificate authority, web filtering, anti-malware, anti-phishing, identity and access management, multi factor authentication
  • Professional certifications, such as a CISSP, CISM, CISA
  • Ability to travel 10-15%
  • Healthcare technology industry experience including payer and provider spaces is a plus

Responsibilities

  • Lead a team of 5 direct reports with a matrix organization of 35-40 globally diverse associates
  • Develop and implement a strategic, long-term information security strategy and roadmap to ensure that Availity’s information assets, and those of its customers under management at Availity, are adequately protected
  • Work with senior leaders across the business to assess and communicate acceptable levels of risk
  • Identify, evaluate and report on information security risks, practices and projects to the Executive Committee and the Board of Directors, and provide subject matter expertise on security standards and best practices e.g. FFIEC, Dodd-Frank, SOX, PCI, etc.
  • Develop, mentor, and manage a high performing staff of information security professionals
  • Develop the Board’s understanding of security beyond a ‘compliance-only’ view
  • Lead the development of up-to-date information security policies, procedures, standards and guidelines, and oversee their approval, dissemination, and maintenance
  • Ensure that the security management program is compliant with applicable laws, regulations, and contractual requirements
  • Act as the champion for the enterprise information security program and foster a security-aware culture
  • Oversee the evaluation, selection and implementation of information security solutions that are innovative, cost-effective, and minimally disruptive
  • Partner with enterprise architects, infrastructure, and applications teams to ensure that technologies are developed and maintained according to security policies and guidelines
  • Manage regular intrusion detection and vulnerability reporting, internal and external IT audit groups reviews, and the coordination of all required fixes
  • Develop business metrics to measure the effectiveness of the security management program, and increase the maturity of the program over time
  • Monitor the industry and external environment for emerging threats and advise relevant stakeholders on appropriate courses of action.
  • Liaise with law enforcement and other advisory bodies as necessary to ensure that the organization maintains a strong security posture
  • Oversee incident response planning and the investigation of security breaches, and assist with any associated disciplinary, public relations and legal matters
  • Oversee and lead the creation, communication and implementation of a process for managing vendor risk and other third-party risk
  • Lead due diligence and post integration activities related to information security for all M&A activity

Benefits

  • competitive salary
  • bonus structure
  • generous HSA company contribution
  • healthcare
  • vision
  • dental benefits
  • 401k match program
  • unlimited PTO for salaried associates
  • 9 paid holidays
  • reimbursement up to $250/year for gym memberships, participation in racing events, weight management programs, etc.
  • education reimbursement
  • Paid Parental Leave for both moms and dads, both birth parents and adoptive parents.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service