Director, Information Security
Abarca HealthAbout the role
What you’ll do
In a few words…
Abarca is igniting a revolution in healthcare. We built our company on the belief that with smarter technology we are redefining pharmacy benefits, but this is just the beginning…
As Director, Information Security, you will manage the tactical implementation and execution of the company’s security policy, standards, guidelines, and procedures designed to discover, analyze, and communicate information security challenges to senior information security management leveraging the NIST Risk Management Framework (RMF). This position will report to the Director, Information Security and will be responsible for the day-to-day operations of the Information Security program company-wide that supports the long-term strategic information security roadmap. The Senior Manager, Information Security will be responsible to hire, train, supervise, and mentor cyber security professionals, and oversee a variety of initiatives and activities tied to the company’s Information Security program, including risk management activities, development of policies, procedures, and standards, supporting technology acquisition and integration activities, incident response life-cycle (Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity), and overall alignment to multiple security and compliance frameworks. Collaborating with internal and external customers, business units, internal teams, and primary stakeholders, you will create and execute tactics that support and implement the long-term strategic information security roadmap.
The fundamentals for the job…
- Collaborate and partner with the CISO on the Information Security Strategic Roadmap.
- Manage the day-to-day tactical execution of the overall information security program.
- Use and enforce agile concepts and iterative sprints to deliver Information Security initiatives.
- Drive automation into operational processes to improve efficiency and sustainability.
- Develop and enhance the information security program in accordance with relevant industry compliance requirements and frameworks.
- Design, implement, track and report key metrics to measure the Information Security Program performance. Take corrective actions as needed to meet program performance objectives and key results.
- Collaborate in the development of policies, standards, guidelines, and procedures to assess, balance, and minimize risks and ensure the confidentiality, integrity, and availability of systems and data.
- Work directly with stakeholders to facilitate information risk assessment and risk management processes that enable the organization to cost-effectively achieve and maintain an acceptable level of loss exposure using frameworks such as NIST 800-37/30, FAIR, ISO 27005, OCTAVE, etc.
- Identify, remediate, and report information security risks utilizing a risk register.
- Provide strategic risk guidance for IT projects, including the evaluation and recommendation of technical controls.
- Provide meaningful visibility, guidance, insight, and analysis to information security leadership and the company’s Senior Leadership Team with respect to information security risks and mitigations.
- Support the company’s “Cloud First” initiative by integrating security controls and continually assessing the security posture of cloud resources by conducting audits to ensure alignment with compliance requirements and industry best practices.
- Enforce Role Based Access Control (RBAC) and least privilege throughout all technology assets.
- Oversee the integration of security scanning into the SDLC by enhancing static and dynamic analysis of all first- and third-party code. Help advance “Shift Left” initiatives.
- Create partnerships with other business units (e.g. Software Engineering, Enterprise Architecture, etc.) to enable a security champions program to foster a security first mindset.
- Oversee the vulnerability management program to ensure a risk-based approach is used for vulnerability remediation across all technology assets.
- Oversee the coordination and execution of 3rd party penetration testing activities.
- Manage the team’s Incident Response Program and activities to ensure a timely and effective response to incidents following a standard life cycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity).
- Create and manage enterprise information security and risk management awareness training programs.
- Oversee the formal training for all staff on relevant security best practices.
- Create and execute policy and audit plans in coordination with internal stakeholders, includin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s