Director Information Security - Cybersecurity Operations

University of VirginiaCharlottesville, VA
43d$118,144 - $236,288

About The Position

The Director Information Security - Cybersecurity Operations will lead the cybersecurity operations team and oversee all aspects of the technical cybersecurity operational services. This role is accountable for ensuring that the appropriate technical security controls, processes, and services are in place and operating effectively to protect the networks, systems, and information assets and ensure that UVA Health is fully prepared to prevent, detect, respond to, and recover from cybersecurity incidents. The ideal candidate will have experience in IT security operations management including cyberdefense operational processes and management of the platforms on which they are built, as well as a strong technical background and success at advising and establishing solid security posture, pragmatic IT risk mitigation, advanced threat detection and response, incident response and digital forensics, cyber threat intelligence, application and platform security testing, DevSecOps, network and cloud security, endpoint security and hardening, and vulnerability and attack surface management. This role will grow and continuously improve the Cybersecurity Operations team and services to effectively and efficiently address the cyberdefense needs of the UVA Health system and minimize the risk to our patient, employee, and other critical data while balancing usability and the operational needs of health system users.

Requirements

  • Bachelor's degree in information security, computer science, or a related field required. Master's Degree is preferred.
  • 10 years of experience in information technology within a related area, with at least five years of progressive responsibility in a technology leadership role managing information security teams, healthcare preferred. Academic healthcare security operations, risk management, or access management preferred.
  • Strong understanding of information security concepts, protocols, industry best practices and regulatory requirements with knowledge of networking, enterprise applications, cloud computing, and information risk management and compliance frameworks preferred.
  • Ability to communicate via written and verbal communication in both formal and casual situations.
  • Demonstrated initiative and success in providing Information Security services, preferably in an academic healthcare setting.
  • Strong analytical and problem-solving skills.
  • Ability to work under pressure and handle multiple priorities.
  • One or more of the following professional certifications or equivalent is required: Certified Information System Security Professional (CISSP) Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA) Global Information Assurance Certifications (SANS/GIAC) Offensive Security Certified Professional (OSCP)

Responsibilities

  • Lead the strategy development and execution of multiple elements of a comprehensive enterprise-wide Information Security Program aligned with organizational goals and regulatory requirements.
  • Design and execute multi-year road maps to transform information security capabilities and collaborate with health system entities to align critical security measures with key business initiatives.
  • Drive innovation and lead organizational change initiatives to enhance security posture and operational resilience. Acts as a change agent for new technologies and processes that reduce risk and enhance security within Health IT.
  • Develop and manage the information security budget, ensuring optimal allocation of resources to meet strategic objectives.
  • Develop and maintain a culture of security that emphasizes the responsibilities of all health system employees to help protect sensitive information, systems, and networks.
  • Provide visionary leadership to the Information Security team, fostering a culture of accountability, innovation, and continuous improvement.
  • Apply deep expertise in cybersecurity operations, regulatory compliance, and risk management to guide enterprise operations and decision-making.
  • Directs and manages Information Security Department actions and operations. Leads multiple teams through the prioritization and implementation of service improvement projects.
  • Directs the design and implementation of solutions that are secure, scalable, reliable, and cost-effective and aligned with the Information Security mission to reduce risk while enhancing productivity.
  • Determine the value and ROI of security projects, and prioritizes scheduling and implementation to ensure the efficient utilization of resources.
  • Develop staff as needed to ensure current and future team skills and capabilities are aligned with the planned departmental growth and transformation.
  • Serve as a senior authority and strategic advisor on information security, influencing executive leadership and cross-functional stakeholders.
  • Champion effective communication and collaboration across departments to embed security into business processes and technology initiatives.
  • Tracks implementations to ensure service and financial targets are met according to agreed timelines.
  • Oversees and negotiates service level agreements (SLAs) with internal and external stakeholders.
  • Directs relationships with vendors to ensure that vendors meet agreed performance objectives, SLAs, and deliverables in a timely manner and within budget guidelines.
  • Interacts with major suppliers, overseeing RFPs, contracts, and service agreements.
  • Oversees the creation and maintenance of policies, procedures, and guidelines to ensure efficient service operation and protect the organization's computing infrastructure and data.
  • Collaborates with Legal, Privacy, and Compliance teams to ensure compliance with relevant laws, regulations, and policies.
  • Advocates for changes in other Health IT departments to ensure compliance with security policies.
  • Cultivate and mentor high-performing security professionals, building leadership capacity and technical expertise across the team.
  • Perform other director-level duties as assigned to support the mission and strategic direction of the organization.
  • Apply deep expertise in cybersecurity operations, regulatory compliance, and risk management to guide enterprise operations and decision-making.
  • Keep abreast of emerging technologies, risks, and industry trends.
  • Assists in the recruitment, hiring, training, and development of Information Security staff, ensuring the team possesses the necessary skills and knowledge to fulfill the department's mission.

Benefits

  • Comprehensive Benefits Package: Medical, Dental, and Vision Insurance
  • Paid Time Off, Long-term and Short-term Disability, Retirement Savings
  • Health Saving Plans, and Flexible Spending Accounts
  • Certification and education support
  • Generous Paid Time Off

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Director

Industry

Educational Services

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service