Director, IT Security
HealthEdgeAbout the role
Overview
Position Overview:
The Director, IT Security will lead and manage a team responsible for safeguarding the company's healthcare data, infrastructure, and platforms. Reporting to the CISO/Head of IT, you will contribute to and execute the strategy for the highest standards of product security, enterprise architecture, cloud security, vulnerability management, third party risk management, and the monitoring of compliance with industry standards and regulatory requirements such as HIPAA and HITRUST. This role is critical in protecting sensitive healthcare data and ensuring the security of HealthEdge and our customers.
About Center of Excellence:
Centers of Excellence (COE) are teams whose primary goal is to provide expertise in a specific field. COEs will usually provide support through training, research, and skilled leaders. In the case of HealthEdge, our Centers of Excellence incorporate the Human Resources, IT, Legal and Financial fields, all of which provide support to our Product divisions and allows the enterprise to move forward and achieve its goals.
Your Impact:
Leadership and Team Management:
Lead, mentor, and develop a team of security professionals, fostering a culture of enthusiasm and accountability for continually raising the bar. You’ll drive results via clear objectives and promote autonomy, emphasizing identification of challenges and creative ideation to elevate business value.
Contribute to the design and execution of a comprehensive security strategy in alignment with the company’s overall cybersecurity goals, while ensuring we’re as nimble as the threat actors we defend against daily. Being adept at long-term planning and the ability to scale is crucial.
Leverage your propensity for bridge building and your passion for continual improvement to provide the highest quality user experience for HealthEdge’s employees.
Embrace and promote change agility not only within the Security Team, but throughout the broader organization. Transform existing processes and evolve growth in a manner that seamlessly provides the best employee experience, particularly with SDLC, product security, and enterprise design engineering.
Adopt an educator’s headspace, empower our employees to understand what we’re up against and build processes for our employees to embody a “see something, say something” ethos.
Security Tooling and Automation:
Drive the evaluation, implementation, and management of security tools and technologies that enhance the company’s security posture; application security, SDLC automation, JIT, CSPM, DSPM, access control, infra as code, vulnerability management platforms, observability, and more.
Bring our AI-First objectives to bear. Continually be on the lookout for emerging GenAI and Agentic AI capabilities that enhance efficiency and efficacy. Be a SME in requirements gathering, stakeholder management, and adoption while balancing associated risk and regulatory requirements.
Optimize business investments in tooling via a “whole is greater than the sum of its parts” mentality. Recognize when we can leverage automation to fill gaps, add efficiencies, and ensure our tooling is operating as expected. Iterate.
Leverage your enterprise security and regulatory experience to partner with and contribute to other functions within the Security, IT, and PMO teams.
Vulnerability Management and Risk Mitigation:
Own the Vulnerability Management strategy throughout HealthEdge. Ensure best in practice capabilities to identify and remediate application and infrastructure vulnerabilities. Lead penetration testing initiatives, driving related mitigations until completion.
Develop relationships with stakeholders and empower a Shift Left function throughout the business. Empower our technical owners with the most efficient means of protecting what’s in their purview. Build a consumable and easily accessible means for business leadership to understand the health of our ecosystem.
Partner with our GRC Team to assess and to incorporate rigor into our Risk Management program, ensuring risk registries and associated oversight are baked into our SOPs. Integrate and automate.
Own Third Party Risk, ensuring our stakeholders are aware of how insecure partnerships can harm the business. Provide and maintain an easily accessible means for our employees to engage the Security Team to perform diligence. Partner with our GRC team to incorporate rigor into our risk reviews and maintain continuous monitoring.
Stakeholder Communication and Reporting:
Be the go-to person and best practices champion
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s