Jobs and Careers
CA

Director of Information Security and Technology

CareRev
Remote- United States, United StatesRemotefull_timeVerifiedPosted 31 Jan 2024
💰 $298,320/yr($165,440/yr – $298,320/yr)

About the role

CareRev is a technology platform empowering healthcare professionals to take control of their careers. CareRev provides a direct line between healthcare facilities and local clinical talent, cutting out the middleman and enabling professionals to work where and when they want. Together, we’re building the local, resilient, flexible healthcare workforce of the future. CareRev serves over 32 major metropolitan areas nationwide at over 70 hospitals and health systems, and over 540 outpatient centers and skilled nursing facilities. More than 22,000 clinical professionals (and growing!) are included in CareRev’s network. For more information, visit www.carerev.com or follow us on LinkedIn.

The Director of Information Security and Technology sets the long-term strategy and oversees all aspects of CareRev security including applications, employees, operations, and infrastructure. As a people leader, this role establishes strategic goals and direction for a team of leaders and individual contributors that implement and operate these cyber security programs. The Director will have a broad mandate, working closely with the Executive Leadership Team, the Audit Committee of the Board of Directors, internal teams and departments, and will be expected to drive change as an evangelist of Security throughout the company.

What You’ll Do: 

  • Develop, implement, and manage a strategic, comprehensive enterprise technology security and risk management program to ensure that information assets are secured.
  • Establish strategic goals and direction for the teams supporting cybersecurity and IT programs and goals. Set long-term strategy for cyber security governance, including policy development and management, standards adherence, and framework adoption.
  • Develop strategy for building compliance programs that ensure continuous adherence to all internal as well as external, regulatory requirements such as HIPAA and SOC2.
  • Industry certifications such as CISSP, CISM, or CISA are highly desirable.
  • In-depth knowledge of security frameworks, standards, and regulations (e.g., ISO 27001, NIST, GDPR).
  • Provide support to Sales/Growth department with frequent customer, partner, and prospect discussions related to IT, security, PII, and related topics.  
  • Develop people through effective performance management and ongoing feedback, focusing on fostering strategic and systems thinking, development of talent, and succession planning across teams and disciplines.
  • Shape culture of both the Security, IT teams and the company as a whole through action, presence, and reinforcement of behaviors.
  • Develop, implement and manage a strategic, comprehensive enterprise technology security and risk management program to ensure that information assets are secured.
  • Develop, maintain and publish up-to-date technology security policies, standards and guidelines.
  • Work with business units to facilitate IT risk assessment and risk management processes.
  • Create, communicate and manage a risk-based process for technology vendor risk management.
  • Own the communication plan, metrics (Lattice Grow, KPIs, OKRs), and mechanisms that share the current and evolving state of all cybersecurity and IT programs and initiatives. Participate in all efforts related to information security awareness training and effectiveness, including the definition of and tracking against security metrics.
  • Cultivate relationships with all critical stakeholders to ensure ongoing projects follow established security policies.
  • Procurement oversight in coordination with Legal, Business Systems/Integration, Finance
  • Direct the day-to-day operations of the IT and Security team
  • Responsible for the timely resolution of internal and external technology related customer issues.  
  • Lead Incident response team when enacted, coordinate with stakeholders and department heads as appropriate to minimize damage. Fill out incident response and lead efforts to enact any lessons learned.
  • Conduct quarterly access reviews of critical information storing systems according to SOC 2 standards.
  • Responsible for New hire User Provisioning , and equipment procurement, in addition to Termination and equipment retrieval processes
  • Lead educational efforts to establish a culture of process improvement through data-driven, decision making
  • Financial responsibility for the IT and Security team budgets and headcount planning
  • Mentorship, leadership, and coaching for all IT and Security team members
  • Recruiting, talent management, performance management, budget management, partnering with technology subject matter experts, and working with senior stakeholders across the o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CareRev

View company profile →