Jobs and Careers
SU

Director Threat Management

Surescripts
United StatesRemotefull_timeVerifiedPosted 8 Jan 2025
💰 $236,100/yr($193,100/yr$236,100/yr)

About the role

Surescripts serves the nation through simpler, trusted health intelligence sharing, in order to increase patient safety, lower costs and ensure quality care. We deliver insights at critical points of care for better decisions — from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between providers.
 

Job Summary:

The Director, Threat Management helps carry out the strategy of a proactive information security program by leading through effective identification and mitigation of the cyber threats that are posed to the Surescripts network. The Director, Threat Management oversees the implementation and management of cutting-edge tools and methodologies to detect, analyze and respond to emerging threats in real-time. The Director, Threat Management leads the Blue Team (incident response) and the Red Team (internal penetration testing) along with the Manager, Threat management to identify vulnerabilities and suspicious activities before they escalate to critical incidents. This leader directs the Incident Response team in collaboration with the Crisis Management Team. The Director, Threat Management provides critical insights into global threats, trends, cybercrime tactics and potential attack vectors specific to the healthcare industry.   

The role requires technical competence and business acumen to foster and maintain strong relationships with business units. The Director, Threat Management requires constant up-to-date familiarity with Threat Management tactics, techniques, and procedures (TTPs) across all lines of business in complex environments. The Director, Threat Management also contributes to the company information security strategy and risk management roadmap. 

Responsibilities:

  • Oversee and proactively coordinate the organization’s cybersecurity efforts under the direction of the CISO

  • Identify, respond to and mitigate cyber threats before they become critical incidents.

  • Contain, mitigate and remediate incidents to ensure that the response times are minimized.

  • Combine strategic vision with operational oversight to ensure the organization is adequately protected against a wide range of cyber threats.

  • Manage overall cyber security risks as they pertain to Surescripts and its customers.

  • Oversee the Threat Management operations:

    • Threat detection

    • Vulnerability Management

    • Insider Threat Detection

    • Data Loss Prevention

  • Lead the Incident Response Teams:

    • Perform regular tabletop exercises

    • Ensure the right tools are leveraged for incident response

    • Ensure ongoing staff development

    • Collaborate with Legal and outside counsel as needed

    • Collaborate with outside incident response teams as needed

  • Develop and maintain up-to-date Incident Response Plans

  • Post incident reviews and root cause analysis in a centralized location for collaboration with key stakeholders

  • Collaborate with cross-functional partners and external partners

  • Evaluate and implement security technologies.

  • Ensure regulatory compliance.

  • Prepare for audits and reporting of the Threat Management Program

  • Establish, monitor and report Threat Management program metrics and reporting.

  • Develop staff skills and competencies. Identify training needs and opportunities

  • Engage when needed for merger and acquisition activities to ensure risks are mitigated effectively.

  • Lead a team of internal and external penetration testers to ensure proper application, internal and external penetration testing is scheduled to meet the needs of the business, information security compliance and contractual requirements.  

  • Ensure service provider contracts contain language acceptable to monitoring and enforcement across provided services and accessible data.  

  • Focus on active threat monitoring while adhering to, and not overstepping, privacy requirements.  

  • Baseline accounts and systems to identify deviation from expected behavior and investigate as required.  

  • Plan and execute regular tabletop drills of Threat Management incident response and postmortem exercises with a focus on measurable improvement and benchmarking to show progress (or deficiencies requiring additional attention).  

  • Develop metrics and scorecards to measure risk to the organization, as well as effectiveness and efficiency of threat analysts.  Manage career development for a team of analysts, including training and mentoring, conducting performance rev

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Surescripts

View company profile →