Director, Information Security
Core
Senior leadership role responsible for building, maturing, and operating a comprehensive security program across governance, risk, compliance, threat management, identity, cloud security, and incident response.
Role type
Director, Information Security
Builds
Comprehensive security program and organizational risk posture
Domain
Healthcare technology / Information Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Programmatic authority, risk register management, KPI definition, team leadership, proactive process design, incident response leadership, ISO 27001/SOC 2 compliance, vendor risk management, AI/LLM governance, vulnerability management, IAM strategy, cloud security baselines, DR/BCP strategy
Preferred skills
Rapidly changing environment management, AI/LLM guardrails, Azure cloud security standards
Technologies
Azure, Okta, Entra ID, ISO/IEC 42001
Responsibilities
Own organizational risk register and drive resource decisions; Define security success metrics and track KPIs for leadership; Lead and grow security team across five operational pillars; Shift security function from reactive to proactive; Serve as primary security authority for risk-based decisions; Lead incident response operations and post-incident reviews; Oversee ISO 27001/SOC 2 compliance and audit readiness; Govern vendor risk management; Establish AI/LLM adoption guardrails; Direct vulnerability management and penetration testing; Set IAM strategy and governance; Define cloud security baselines and embed security in DevOps; Own DR/BCP strategy and testing; Brief executive leadership on security posture; Represent security program during M&A due diligence
Seniority
Director, senior leadership with full programmatic authority