JobTarget Logo

Director of Information Security in at Hollis Cobb Associates

NewJob Function: Information Technology
Hollis Cobb Associates
United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Description:

The Director of Information Security is a hands-on security leader to own and mature our information security program end to end. In this player-coach role, you will set security strategy and priorities, serve as the organization's primary authority on security risk, and personally engineer many of the controls that protect electronic protected health information (ePHI) and payment card data. You will be accountable for our compliance posture under the HIPAA Security Rule, our alignment with the NIST Cybersecurity Framework and NIST SP 800-53, and PCI DSS for our payment environments.

Requirements:

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Own the information security program, including its strategy, multi-year roadmap, budget recommendations, and success metrics, aligned with business and clinical priorities.
  • Design, deploy, and maintain security technologies including firewalls, EDR, SIEM, IDS/IPS, DLP, email security, and vulnerability management platforms across on-premises and cloud environments.
  • Implement and document technical safeguards required by the HIPAA Security Rule, including access controls, audit logging, integrity controls, and transmission security for systems that store or process ePHI.
  • Map security controls to the NIST Cybersecurity Framework and NIST SP 800-53, identify gaps, and drive remediation work with system owners.
  • Own PCI DSS compliance for cardholder data environments by maintaining network segmentation, hardening in-scope systems, managing quarterly ASV scans and annual assessments, and preparing evidence for QSA reviews or SAQs.
  • Lead the HIPAA security risk analysis and risk management process, maintaining a living risk register and communicating risk decisions clearly to leadership.
  • Manage vulnerability and patch programs.
  • Engineer and maintain identity and access management controls such as MFA, role-based access, privileged access management, and perform access reviews.
  • Own the incident response program, including the plan, playbooks, and tabletop exercises, and lead response efforts during security incidents, coordinating breach risk assessments with compliance and legal.
  • Prepare for and lead the organization through external audits, OCR inquiries, payer or partner security assessments, and customer security questionnaires.
  • Own the third-party risk management program, including security reviews of vendors and Business Associates and the security terms of Business Associate Agreements.
  • Contribute to security awareness efforts and advise IT staff on secure practices.
  • This role requires occasional travel.
  • Other duties as assigned.

QUALIFICATIONS

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


EDUCATION

BS in Computer Science, Management Information Systems, or a related field is preferred.

EXPERIENCE

Minimum of three years of combined experience in information security, compliance, technology audit, or a related field.


COMMUNICATION/ TEAMWORK SKILLS

Be able to establish priorities and successfully complete multiple assignments. Ability to work effectively both independently and also as part of a team. Possess excellent verbal and written communication skills. Strong analytical skills with the ability to collect, organize, analyze, and disseminate significant amounts of information with attention to detail and accuracy. Be able to organize complex work assignments for multiple clients and assure timely and accurate service delivery. Ability to work independently with minimal supervision.


TECHNICAL SKILLS

Required:

  • Working knowledge of the HIPAA Security Rule, the NIST CSF and SP 800-53, and PCI DSS v4.0 requirements.
  • Hands-on experience with security tools such as SIEM (e.g., Splunk, Microsoft Sentinel), EDR (e.g., CrowdStrike, Defender), next-generation firewalls, and vulnerability scanners (e.g., Tenable, Qualys, Rapid7).
  • Solid understanding of networking (TCP/IP, segmentation, VPNs), Windows and Linux administration, and Active Directory/Entra ID.
  • Experience securing cloud environments (AWS, Azure, or GCP).
  • Strong written communication skills, including the ability to produce clear documentation for auditors and explain risk to non-technical stakeholders.

Preferred:· Relevant certifications such as CISSP, CISM, GIAC (GSEC, GCIH, GCCC), CompTIA Security+/CASP+, HCISPP, or a cloud security certification.· Familiarity with HITRUST CSF.· Scripting or automation experience (PowerShell, Python, Bash) and familiarity with infrastructure-as-code.


BENEFITS OFFERED:

  • Medical
  • Health Savings Account for High Deductible Medical plan
  • Dental
  • Vision
  • Life Insurance
  • Disability Insurance
  • Retirement with Company Matching
  • Paid Time Off & Holidays
  • Employee Assistance Program
  • Referral Program

Illinois, Maryland, New Jersey and Virginia residents click below for compensation and benefits: https://www.holliscobb.com/state-specific-benefits/

Hollis Cobb is an Equal Opportunity Employer

Job Location

United States

Frequently asked questions about this position

Apply For This Position

Apply Now