Jobs and Careers
PO

Director, Cyber & Information Security - Identity & Threat Management

Point32Health
United Statesfull_timeVerifiedPosted 5 Sept 2024

About the role

Who We Are

Point32Health is a leading health and wellbeing organization, delivering an ever-better personalized health care experience to everyone in our communities. At Point32Health, we are building on the quality, nonprofit heritage of our founding organizations, Tufts Health Plan and Harvard Pilgrim Health Care, where we leverage our experience and expertise to help people find their version of healthier living through a broad range of health plans and tools that make navigating health and wellbeing easier.

We enjoy the important work we do every day in service to our members, partners, colleagues and communities. To learn more about who we are at Point32Health, click here.

Job Summary

The Director, Cyber & Information Security - Identity & Threat Management, will report into the Chief Information Security Officer (CISO) for Point32Health. The Director leads Cyber & Information Security managers and/or security leaders to oversee and help to ensure that core programs are effectively implemented. This role is integral in driving the organization’s Cyber & Information Security strategy and objectives. The Director, Cyber & Information Security is considered a leader within the IT Department and is expected to work collaboratively to identify, influence, and enhance areas of improvement across the organization.

Key Responsibilities/Duties – what you will be doing

  • Manage a team of managers/senior leaders responsible for overseeing the core pillars of Cyber & Information Security
  • Develop and implement policies, standards, and guidelines that continuously increase the organization’s Cyber & Information Security program maturity 
  • Communicate potential security concerns/exposures with recommended improvements 
  • Lead communication and collaboration efforts with the business and IT to ensure quality solutions are delivered 
  • Evangelize the objective to embed security behaviors and principles into the Point32Health culture through active engagement, education, awareness, and partnership 
  • Develop operational excellence in anticipation and response to evolving threats and opportunities to improve cyber and information security 
  • Identify business risk and communicate risk to appropriate leadership 
  • Collaborate with stakeholders to define and implement technical and non-technical controls designed to cyber risk objectives and legal / regulatory obligations. 
  • Maintain the risk repository to continually identity, prioritize, and mitigate cyber and information security related risk issues 
  • Participate in various forums and groups across Point32Health to understand the risk environment and to provide recommends that effectively incorporate security objectives while balancing the business impact of recommendations provided
  • Facilitate adoption of leading security practices to remain in compliance with regulations and to support our continuous monitoring and improvement goals
  • Maintain up-to-date knowledge of the cyber and information security industry, including awareness of new or revised security capabilities, improved security processes, threat scenarios, trends, etc.
  • Identify/recommend tools, processes, software, and protocols to advance or replace current security practices, services, or technologies to meet strategic objectives.
  • Other duties and projects as assigned.

Qualifications – what you need to perform the job

EDUCATION, CERTIFICATION AND LICENSURE: 

  • Bachelor’s degree in Cyber Security, Computer Science, Risk Management, or related field preferred or equivalent experience


EXPERIENCE (minimum years required):

  • 10+ years combined IT, cyber/information security, risk, audit, compliance, with increasing responsibility
  • 5+ years in cybersecurity or field(s) related to the programs for which the role is responsible for
  • 5+ years in a leadership role, preferably with at least 2 of those years overseeing other managers
  • Experience in leading or sponsoring implementation of technical security solutions within large organizations
  • Experience developing and implementing process-based security controls, processes, and capabilities
  • Experience in engaging with and managing vendors responsible for implementing processes and/or IT solutions
  • Experience creating and maintaining security requirements, guidelines, and procedure documents
  • Extensive knowledge and experience i

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Point32Health

View company profile →