IT Security Governance Lead

Stony Brook UniversityStony Brook, NY
$87,019 - $117,116

About The Position

Stony Brook Medicine is seeking an IT Governance Lead to drive enterprise identity governance, access control, and cloud security strategy. This senior role is responsible for defining and enforcing authorization models, identity governance frameworks, and privileged access controls across cloud and hybrid environments, including clinical platforms such as Oracle Health (Cerner). This position serves as the information security authority for “who gets access and why,” ensuring alignment with Zero Trust principles, least privilege, and regulatory requirements (HIPAA, NYS, SUNY, NIST) while partnering with Systems and Engineering teams for operational execution.

Requirements

  • Bachelor’s degree in Technology (Computer Science, InfoSec, or related field.
  • 5+ years of experience in Identity & Access Management (IAM), or Identity Governance such as:
  • Identity Governance & Administration (IGA)
  • RBAC / ABAC models
  • PAM/PIM solutions
  • Cloud platforms (OCI, Azure, AWS, or GCP)

Nice To Haves

  • Direct experience with Oracle Cloud Infrastructure (OCI) and Oracle Health (Cerner) access models
  • Experience supporting or securing enterprise healthcare/clinical systems (e.g., Oracle Health / Cerner, Epic, or similar)
  • Experience governing access to clinical workflows, sensitive patient data, and provider roles
  • Familiarity with Microsoft Entra ID / Azure AD governance
  • Experience with Zero Trust architectures and conditional access
  • Relevant certifications (CISSP, CISM, CRISC, CCSP)
  • Understanding of HIPAA Security Rule
  • Understanding of NIST frameworks (800-53, 800-207)

Responsibilities

  • Establish and enforce cloud access governance policies (RBAC/ABAC)
  • Design and oversee authorization models across cloud platforms (OCI and hybrid environments)
  • Define and govern access controls for enterprise clinical systems (e.g., Oracle Health / Cerner)
  • Lead access certification reviews and enforce least privilege principles
  • Govern Privileged Access Management (PAM/PIM) strategy and controls
  • Monitor identity risk signals and privileged account activity
  • Align identity governance with HIPAA, NYS, SUNY, and NIST frameworks
  • Partner with Architecture, Cloud, Application, and Clinical IT teams to ensure secure design
  • Enforce segregation of duties (SoD) and access controls
  • Determining who should have access and under what conditions
  • Defining access control policies and governance standards
  • Driving risk-based access decisions and control enforcement
  • Ensuring audit readiness and regulatory compliance, including clinical system access
  • Collaboration with SBMIT Systems
  • Conditional Access & MFA: Defining governance & policy
  • Access Provisioning: Defines roles and approval requirements
  • Access Reviews: Owns certification process
  • Identity Incident Response: Leads investigation and strategy
  • Logging & Monitoring: Defines requirements and reviews anomalies
  • Operations: Separation of authentication (Systems) and authorization (InfoSec)
  • Independent governance over privileged and sensitive access, including clinical systems
  • Enforced segregation of duties
  • Scalable governance model supporting cloud and healthcare platforms (OCI/Cerner)

Benefits

  • generous leave
  • health plans
  • state pension
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service