Remote job
Vice President, Information Security and IT
Job details
About this role
Role overview A growing healthcare organization is hiring a Vice President of Information Security and IT to stand up and lead both functions in a player-coach capacity. The role blends executive strategy with hands-on program leadership across cybersecurity, AI governance, and corporate IT, operating in a fast-moving, regulated environment where priorities shift quickly.
Responsibilities - Define the multi-year strategy and annual plans for cybersecurity and corporate IT, aligning with business goals, regulatory obligations, and the enterprise risk picture. - Build and run the HIPAA Security Rule program, including risk analysis, data classification, safeguards for ePHI, remediation, and ongoing audit readiness. - Mature capabilities across threat detection and response, identity security, vulnerability management, product and cloud security, vendor risk, security awareness, and physical security standards. - Stand up AI governance in partnership with Legal, Privacy, Compliance, Product, and Engineering, covering acceptable use, tool approval, risk assessment, and monitoring. - Embed security into software and cloud platforms through close work with Product, Engineering, and Platform teams covering APIs, integrations, and production systems. - Lead major incident response, cyber resilience, and recovery planning alongside business continuity owners, and report to executives and the Board on risk posture. - Run HITRUST, SOC 2, and other audits, customer security assessments, and regulatory reviews while managing security and IT budgets, vendors, and team performance.
Requirements - Significant cybersecurity experience including senior leadership of an enterprise-wide security program. - Direct, hands-on cybersecurity leadership inside a HIPAA-regulated healthcare organization with deep familiarity protecting ePHI as a covered entity or business associate. - A track record of building or improving a security program in a startup, scale-up, or similarly fast-moving company with shifting priorities and constrained resources. - Strong technical depth in cloud security, identity and access management, product and application security, incident response, vendor risk, and resilience. - Experience partnering with Product and Engineering in cloud-based software environments, and with HITRUST, SOC 2, healthcare audits, and enterprise customer security reviews. - Background leading corporate IT for a distributed workforce, including business applications, endpoints, identity, employee support, and IT service delivery. - Practical experience with AI governance, business applications, automation, integrations, and APIs, plus strong team leadership, budgeting, vendor management, and executive communication skills.
Nice to have - Practical exposure to using AI and automation to streamline business workflows company-wide.
Benefits and work setup - Standard health and wellness coverage plus alternative medicine benefits. - Flexible paid time off, paid holidays, and up to 16 weeks of paid parental leave, plus two days of paid paw-ternity leave. - 401k program, transportation perks, and education reimbursement.