Information Security Specialist Principal
Children's Hospital of PhiladelphiaAbout the role
SHIFT:
Day (United States of America)Seeking Breakthrough Makers
Children’s Hospital of Philadelphia (CHOP) offers countless ways to change lives. Our diverse community of more than 20,000 Breakthrough Makers will inspire you to pursue passions, develop expertise, and drive innovation.
At CHOP, your experience is valued; your voice is heard; and your contributions make a difference for patients and families. Join us as we build on our promise to advance pediatric care—and your career.
CHOP does not discriminate on the basis of race, color, sex, national origin, religion, or any other legally protected categories in any employment, training, or vendor decisions or programs. CHOP recognizes the critical importance of a workforce rich in varied backgrounds and experiences and engages in ongoing efforts to achieve that through equally varied and non-discriminatory means.
Summary
This role requires a proven leader in enterprise vulnerability program management who can design, operate, and continuously mature a comprehensive vulnerability lifecycle across clinical, corporate, and cloud environments. The ideal candidate brings hands-on expertise with Rapid7, InsightVM, and ServiceNow Vulnerability Response to drive risk-based prioritization, automated workflows, and executive-level reporting. You will partner closely with IT, cloud, and application teams to translate scan results into actionable remediation plans, enforce SLAs, and align vulnerability management practices with NIST, HIPAA, and organizational risk frameworks—ensuring measurable risk reduction and sustained compliance across the enterprise.
This department works approximately 80% remotely, 20% on site in our Philadelphia offices on an as-needed basis.
A Brief Overview
- Demonstrates specialized & comprehensive knowledge in Information security management practices, disciplines, regulations, industry standards, related frameworks, project management principles, and methodologies, security engineering concepts, security operations model; industry standards around architecture principles.
- Demonstrates exceptional skills in managing multiple projects and priorities in order to meet strategic goals and timelines.
- Exhibits the ability to plan, manage and implement highly complex enterprise architecture and security implementations, enhancements or modifications that require in-depth knowledge across multiple technical areas and business segments.
- Exhibits exceptional understanding of emerging regulatory and healthcare issues in order to develop internal and external checks and controls to ensure proper governance, security and quality of information assets.
- Demonstrates exceptional troubleshooting and collaborative skills required to identify, analyze and resolve complicated security issues.
- Demonstrates advanced proficiency in creating detailed documentation, perform budget planning and oversight, and providing input on CHOP infrastructure strategic planning, technology standards, and information security and risk practices.
- Exhibits ability to communicate effectively with clients, colleagues, vendors, management and the ability to translate complex technical solutions into non-technical requirements documents.
- Performs planning, development, implementation, and delivery of enterprise architecture and engineering principles for new, existing and future strategic and operational activities.
- Demonstrates the ability to provide technical expertise and consultation to the CIO, CTO, CISO, executive leadership and other business and clinical leaders.
What you will do
- A Principal Information Security Specialist has similar responsibilities to Information Security Specialist III personnel. However, a Principal Information Security Specialist is deemed to be the subject matter expert and in-house advisor on complex problems and issues. A Principal Information Security Specialist also:
- Works independently to initiate assignments and draws upon extensive professional knowledge and experience to make independent judgments regarding analysis, evaluation, development, and implementation of enterprise long-term solutions and operating initiatives to ensure that enterprise architectural objectives are aligned with organizational needs and strategic goals.
- Optimizes information management approaches through an understanding of evolving business needs and technology capabilities and ensures that projects do not duplicate functionality or diverge from each other and business and DTS strategies.
- Shapes, designs, and plans specific service lines in product area and manages the risks associated with information and DTS assets through appropriate standards and security pol
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s