Jobs and Careers
ST

IT Security Governance Lead

Stony Brook University
Stony Brook, United Statesfull_timeVerifiedPosted 28 Jul 2026
💰 $117,116/yr($87,019/yr$117,116/yr)

About the role

IT Security Governance Lead

 

Position Summary

 

Stony Brook Medicine is seeking an IT Governance Lead to drive enterprise identity governance, access control, and cloud security strategy. This senior role is responsible for defining and enforcing authorization models, identity governance frameworks, and privileged access controls across cloud and hybrid environments, including clinical platforms such as Oracle Health (Cerner).

 

This position serves as the information security authority for “who gets access and why,” ensuring alignment with Zero Trust principles, least privilege, and regulatory requirements (HIPAA, NYS, SUNY, NIST) while partnering with Systems and Engineering teams for operational execution.

 

Duties of an IT Governance Lead may include the following but are not limited to:

 

  • Establish and enforce cloud access governance policies (RBAC/ABAC)
  • Design and oversee authorization models across cloud platforms (OCI and hybrid environments)
  • Define and govern access controls for enterprise clinical systems (e.g., Oracle Health / Cerner)
  • Lead access certification reviews and enforce least privilege principles
  • Govern Privileged Access Management (PAM/PIM) strategy and controls
  • Monitor identity risk signals and privileged account activity
  • Align identity governance with HIPAA, NYS, SUNY, and NIST frameworks
  • Partner with Architecture, Cloud, Application, and Clinical IT teams to ensure secure design
  • Enforce segregation of duties (SoD) and access controls
  • Determining who should have access and under what conditions
  • Defining access control policies and governance standards
  • Driving risk-based access decisions and control enforcement
  • Ensuring audit readiness and regulatory compliance, including clinical system access

 

Collaboration with SBMIT Systems

  • Conditional Access & MFA
    • Defining governance & policy
  • Access Provisioning
    • Defines roles and approval requirements
  • Access Reviews
    • Owns certification process
  • Identity Incident Response
    • Leads investigation and strategy
  • Logging & Monitoring
    • Defines requirements and reviews anomalies

Operations

  • Separation of authentication (Systems) and authorization (InfoSec)
  • Independent governance over privileged and sensitive access, including clinical systems
  • Enforced segregation of duties
  • Scalable governance model supporting cloud and healthcare platforms (OCI/Cerner)

 

 

 

 

Qualifications

 

Required Qualifications:  

 

  • Bachelor’s degree in Technology (Computer Science, InfoSec, or related field.
  • 5+ years of experience in Identity & Access Management (IAM), or Identity Governance such as:
    • Identity Governance & Administration (IGA)
    • RBAC / ABAC models
    • PAM/PIM solutions
    • Cloud platforms (OCI, Azure, AWS, or GCP)

Preferred Qualifications: 

 

  • Direct experience with Oracle Cloud Infrastructure (OCI) and Oracle Health (Cerner) access models

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Stony Brook University

View company profile →