Overview
We are seeking an experienced Cybersecurity Director to join our team in Franklin, TN.
Location: This position is based at Acadia Healthcare's corporate office in Franklin, TN. The first 90 days in this role will be fully in-person to ensure comprehensive onboarding and training.
After the initial period, the position will transition to a hybrid model, with 2 days remote and 3 days in the office each week.
PURPOSE STATEMENT:
The Cybersecurity Director is responsible for leading and managing Acadia’s cybersecurity strategy, programs, and initiatives to protect the confidentiality, integrity, and availability of its information assets. This role involves developing and implementing comprehensive cybersecurity strategies, overseeing the security posture, managing cybersecurity teams, and ensuring compliance with regulatory requirements and industry standards.
Responsibilities
ESSENTIAL FUNCTIONS:
Cybersecurity Strategy and Planning:
Develop and implement a comprehensive cybersecurity strategy aligned with the organization's business goals.
Define cybersecurity policies, standards, and procedures.
Identify emerging threats and vulnerabilities and proactively address them.
Security Operations:
Oversee the day-to-day operation of the cybersecurity function.
Monitor and analyze security alerts and incidents, responding promptly to mitigate threats.
Implement security controls and technologies to protect against cyber threats.
Team Management:
Lead and mentor a team of cybersecurity professionals, including security analysts, engineers, and specialists.
Set performance goals and conduct regular performance reviews.
Recruit and onboard new talent as needed.
Risk Management:
Conduct regular risk assessments and vulnerability assessments.
Develop and maintain a risk management framework.
Recommend and implement risk mitigation strategies.
Compliance and Governance:
Ensure compliance with relevant regulatory requirements and industry standards (e.g., HIPAA, etc.).
Monitor and report on compliance status to senior management and external stakeholders.
Mergers and Acquisitions (M&A):
Actively participate in due diligence processes for M&A activities, assessing the cybersecurity posture of potential acquisition targets.
Develop integration plans for cybersecurity, ensuring the smooth transition of security controls and policies during mergers or acquisitions.
Identify and address cybersecurity risks associated with M&A transactions.
Vendor Risk Management:
Establish and maintain a comprehensive vendor risk management program.
Evaluate and assess the cybersecurity practices and controls of third-party vendors and service providers.
Define risk assessment criteria and conduct vendor risk assessments regularly.
Work with vendors to remediate identified security gaps or vulnerabilities.
Monitor vendor compliance with cybersecurity requirements and contractual agreements.
Cyber Insurance Management:
Collaborate with insurance providers to assess and procure cyber insurance coverage tailored to the organization's needs.
Maintain a comprehensive understanding of the organization's cyber insurance policies and coverage.
Ensure accurate documentation and reporting of cybersecurity incidents to facilitate insurance claims.
Review and update cyber insurance policies as needed to adapt to evolving risks.
Assist in the claims process and provide necessary documentation to expedite settlements.
Security Awareness and Training:
Promote a culture of cybersecurity awareness throughout the organization.
Conduct security training and awareness programs for employees.
Incident Response and Recovery:
Develop and maintain an incident response plan.
Lead incident response efforts in the event of a security breach.
Coordinate with legal, HR, and law enforcement as needed.
Budget Management:
Manage the cybersecurity budget, ensuring efficient allocation of resources.
Track and report on budget expenditures.
Vendor Management:
Collaborate with third-party vendors and service providers to enhance cybersecurity capabilities.
Evaluate and select cybersecurity technologies and tools.
Performance Metrics:
Define and track key performance indicators (KPIs) for the cybersecurity function.
Regularly report on cybersecurity metrics to senior management.
OTHER FUNCTIONS: