Information Security Officer (ISO)

Capital Health (US)Lawrenceville, GA
Onsite

About The Position

The Information Security Officer (ISO) serves as the executive leader responsible for protecting Capital Health’s digital environment and building organizational resilience against cyber threats. This role defines the organization’s cybersecurity strategy, safeguarding the confidentiality and availability of patient data, clinical systems and connected medical technologies by establishing clear policies and governance that align with healthcare regulations and industry standards. The ISO also acts as a principal advisor to leadership, working across clinical, legal and technical teams to embed security into daily operations and build a culture of digital trust. Additionally, the role oversees risk management and business continuity planning to ensure the organization can defend against emerging threats and quickly resume serving the community in the event of a disruption.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, Business, Engineering, or related field required.
  • Ten years of progressive experience in cybersecurity, with a proven track record of building and maturing enterprise-level security programs.
  • Direct experience leading security initiatives in healthcare or another highly regulated environment, with a deep understanding of operational needs and regulatory rules.
  • Significant experience architecting and securing complex digital environments – including cloud-native platforms, DevSecOps pipelines, clinical systems and APIs - to ensure safety and security are built into the design from the start.
  • Extensive experience acting as a trusted advisor to executive leadership, boards and governance committees on cyber risk and digital trust.

Nice To Haves

  • Master’s degree preferred.
  • Preferred certifications include: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), HCISPP or healthcare-specific security certification and cloud security certifications (Azure, AWS, or equivalent).

Responsibilities

  • Define and execute the enterprise cybersecurity strategy and multi-year roadmap to ensure protection stays ahead of evolving threats
  • Act as the principal advisor to the Board and leadership, providing clear reporting on cyber risk, resilience and maturity
  • Establish the policies, standards and accountability frameworks that govern how data and systems are protected across the health system
  • Lead the enterprise cybersecurity risk program, ensuring that risks are identified, prioritized and managed in line with healthcare regulations
  • Partner with Clinical Engineering to secure medical devices (BioMed) and connected technologies that directly impact patient care
  • Oversee the design of secure environments, ensuring “security-by-design” is built into cloud platforms and infrastructure
  • Integrate security into the software development lifecycle, ensuring internally developed applications are secure from the start
  • Drive the maturity of DevSecOps practices, integrating security into CI/CD pipelines and automation frameworks
  • Strengthen identity management and privileged access controls to enforce a “least-privilege” approach across the enterprise
  • Improve visibility and control over sensitive data (PHI, PII and PCI) across all clinical and operational platforms
  • Strengthen and elevate the organization’s ability to detect and respond to incidents through advanced monitoring and automation
  • Lead enterprise-wide incident response planning and coordinate executive communication during cybersecurity events
  • Oversee disaster recovery and business continuity planning to guarantee that clinical services can resume quickly after a disruption
  • Establish vendor security governance, ensuring partners and cloud services meet strict security and contractual standards
  • Partner with Procurement to embed cybersecurity into vendor selection, onboarding and Business Associate Agreements (BAAs)
  • Establish governance and security standards for Artificial Intelligence (AI), automation and intelligent agents
  • Ensure the secure exchange of data across EHR systems, cloud services and enterprise integration platforms
  • Partner with Legal and Compliance teams to maintain alignment with HIPAA, NIST and DNV accreditation expectations
  • Perform other duties as assigned

Benefits

  • Medical Plan
  • Prescription drug coverage & In-House Employee Pharmacy
  • Dental Plan
  • Vision Plan
  • Flexible Spending Account (FSA) - Healthcare FSA, Dependent Care FSA
  • Retirement Savings and Investment Plan
  • Basic Group Term Life and Accidental Death & Dismemberment (AD&D) Insurance
  • Supplemental Group Term Life & Accidental Death & Dismemberment Insurance
  • Disability Benefits – Long Term Disability (LTD)
  • Disability Benefits – Short Term Disability (STD)
  • Employee Assistance Program
  • Commuter Transit
  • Commuter Parking
  • Supplemental Life Insurance - Voluntary Life Spouse, Voluntary Life Employee, Voluntary Life Child
  • Voluntary Legal Services
  • Voluntary Accident, Critical Illness and Hospital Indemnity Insurance
  • Voluntary Identity Theft Insurance
  • Voluntary Pet Insurance
  • Paid Time-Off Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service