Director of Information Security | PAM Health Corporate
PAM HealthAbout the role
Overview
The Director of Information Security is responsible for leading PAM Health’s security program, ensuring the protection of systems, data, and compliance with HIPAA security standards. This role oversees day-to-day security operations, risk management, incident response, vendor partnerships, and the development of cybersecurity policies and procedures. The position works closely with leadership and the (v)CISO to strengthen PAM Health’s security posture through continuous improvement, monitoring, and employee education. Additionally, they provide strategic guidance, lead security initiatives, and foster a culture of safety, compliance, and collaboration across the organization.
Responsibilities
Position Responsibilities
- Responsible for all tasks associated with the operations of the PAM Health security program including day-to-day security management, event response, security maturity, vendor management, communication and education, etc.
- Responsible for the HIPAA Security compliance program including compliance analysis, remediation projects, and communication.
- Responsible for the PAM Health Security Risk Management program.
- Work with (v)CISO to develop ongoing improvement initiatives to PAM Health security profile.
- Regular communication with leadership regarding security program status and initiatives.
- Manage, maintain and communicate policies and procedures related to information security.
- Designs, develops and tests cybersecurity features, as microservices and cross platform shareable components with high quality design
- Designs, implements, and maintains cybersecurity policies and procedures such as data access controls, acceptable use of technology, password management, and incident reporting procedures
- Translates technical cybersecurity requirements into clear, actionable policies that employees can understand and follow
- Monitors and audits compliance of cybersecurity policies to identify gaps
- Reviews existing cybersecurity policies post security incidents to identify improvements
- Manages multi-functional team coordination, opportunity screening, benefit/cost analysis, vendor selection, schedule and budget oversight, management of consultants/contractors, issue resolution, and reporting.
- Conducts network monitoring and intrusion detection analysis using various computer network defense tools, such as intrusion detection/prevention systems, firewalls and host-based security systems
- Conducts log-based and endpoint-based threat detection to detect and protect against threats coming from multiple sources
- Deploys cloud-centric detection to detect threats related to cloud environments and services used by the organization
- Correlates activity across assets (endpoint, network, apps) and environments (on-premises, cloud) to identify patterns of anomalous activity
- Reviews alerts and data from sensors, and documents formal, technical incident reports
- Works with threat intelligence and/or threat-hunting teams
- Supports the creation of business continuity/disaster recovery plans, including conducting disaster recovery tests, publishing test results and making changes necessary to address deficiencies
- Works with security information and event management (SIEM) to manage/tune the system, create/manage the detection content and actively watch for alerts
- Correlates network, cloud and endpoint activity across environments to identify attacks and unauthorized use
- Researches emerging threats and vulnerabilities to aid in the identification of incidents
- Provides users with incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary
- Performs security standards testing against computers before implementation to ensure security
- Provides regular training sessions on intrusion detection and prevention systems, security incident response procedures, threat intelligence analysis, log analysis, etc. within the team
Leadership
- Inclusiveness: Promotes cooperation, fairness and equity; shows respect for people and their differences; works to understand perspectives of others; demonstrates empathy; brings out the best in others and in his/her team
- Managing Staff: Coaches, evaluates, develops, and inspires staff; sets expectations; recognizes achievements
- Stewardship and Resource Management: Demonstrates accountability and sound judgment in managing company resources; appropriate understanding of confidentiality and company values; adheres to and supports company policies, procedures and safety guidelines
- Problem-Solving: Identifies problem
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s