Manager, Cybersecurity
Westerville, OH - USA
Job Summary
The Manager Cybersecurity is responsible for leading COPCs cybersecurity program protecting the confidentiality integrity and availability of clinical financial and administrative systems across all COPC practice sites. This position oversees security operations threat detection and incident response vulnerability management identity and access management and security awareness training and manages the analysts and engineers who support these functions. Using sound judgment and technical expertise the Manager translates enterprise risk into actionable controls partners with IT Compliance and clinical leadership to safeguard patient data and support HIPAA and SOC compliance and helps mature COPCs security posture as the organization grows. The role serves as a key escalation point during security incidents and is accountable for maintaining a defensible well-documented cybersecurity program across a multi-site healthcare enterprise.
ESSENTIAL FUNCTIONS AND RESPONSIBILITIES
To perform this job successfully an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Develop implement and continuously mature COPCs cybersecurity program including policies standards and procedures aligned to recognized frameworks such as NIST CSF and SOC.
Lead day-to-day security operations overseeing SIEM endpoint detection and response (EDR) firewalls and intrusion detection/prevention systems to identify triage and respond to threats in real time.
Own and continuously improve COPCs security incident response plan; lead investigation containment eradication and recovery efforts for security incidents and coordinate tabletop exercises to validate readiness.
Manage the vulnerability management program including recurring vulnerability scanning patch prioritization coordination of penetration testing and tracking of remediation across servers endpoints network devices and cloud environments.
Lead and develop a high-performing team which includes interviewing and selection of new employees onboarding coaching training professional development conflict resolution and disciplinary action and follow-up. Ensure completion of performance reviews and related actions for direct and indirect reports and address personnel processes/issues including conflict management goal attainment and disciplinary action (as needed).
Lead and mentor Cybersecurity team members while ensuring consistency and accountability across COPC ensuring scope deliverables and budgets achieve expectations; foster a culture of accountability collaboration continuous improvement and innovation.
Partner with IT infrastructure network applications and EHR teams to embed security requirements into system design cloud migrations integrations and new technology deployments across all COPC practice sites.
Administer identity and access management controls including privileged access management multi-factor authentication periodic access reviews and enforcement of least-privilege principles across clinical and business systems.
Own third-party and vendor risk management including security assessments of business associates and vendors handling protected health information and ensure Business Associate Agreements reflect appropriate security obligations.
Ensure ongoing compliance with HIPAA SOC and other applicable regulatory and payer security requirements; support internal and external security audits risk assessments and regulatory inquiries.
Design implement and measure the effectiveness of COPCs security awareness training while managing a regular phishing simulation program for all workforce members.
Partner with the CIO to manage the security tooling budget and licensing while evaluating emerging security technologies to recommend investments that reduce organizational risk.
Maintain data loss prevention encryption and secure backup controls and participate actively in business continuity and disaster recovery planning and testing.
Prepare and present security metrics risk assessments and program updates to IT leadership executive stakeholders and the Compliance Committee.
Serve as a subject matter expert and primary escalation point for security-related questions and incidents across the organization including escalation of urgent matters to the CIO; provide after-hours response as needed.
Other duties as assigned.
QUALIFICATIONS
A. Education Licensures Certifications & Experience
Required: Bachelors degree in Computer Science Information Security Information Technology or a related field; or equivalent combination of education and experience.
Required: 5 years of progressive experience in information security or cybersecurity roles.
Required: Current CISSP or CISM certification (CISSP preferred).
Required: 2 years in a leadership team-lead or supervisory capacity.
Required: Experience working in healthcare or another highly regulated industry.
Preferred: Masters degree in Cybersecurity Information Systems or related field.
Preferred: Additional certifications such as CISA CCSP CEH or CompTIA Security.
B. Knowledge Skills & Abilities
Strong knowledge of security frameworks and standards such as NIST CSF SOC HITRUST CSF ISO 27001 and healthcare-specific regulations including HIPAA and HITECH.
Hands-on experience with SIEM EDR/XDR firewalls IDS/IPS vulnerability scanning tools and cloud security services (e.g. AWS or Azure security tooling).
Demonstrated experience leading incident response for security events including forensic investigation containment and remediation.
Working knowledge of identity and access management network security architecture and encryption technologies.
Experience conducting or overseeing risk assessments security audits and penetration testing engagements.
Ability to evaluate multiple security technologies and platforms and recommend the right solution for a given risk or problem.
Ability to learn new technologies threats and business concepts quickly in a fast-evolving field.
Extensive knowledge of best practices regarding security policies procedures and controls in a healthcare environment.
Experience gathering documenting prioritizing and tracking security requirements and remediation efforts.
Must recognize and evaluate problems and refer to the appropriate channels for action.
Strong analytical organizational and problem-solving skills with sound judgment under pressure.
Demonstrated ability to lead mentor and develop a technical team.
Translates technical risk into business terms for non-technical executive clinical and operational stakeholders.
Effective written and verbal communication skills with a strong customer service orientation and the ability to work with stakeholders at all levels of the organization.
Ability to manage multiple priorities projects and vendors simultaneously in a fast-paced environment.
High degree of integrity and discretion in handling sensitive and confidential information.
Ability to remain current on the evolving cybersecurity threat landscape and emerging technologies and to communicate implications to leadership.
Required Experience:
Manager
About Company
Central Ohio Primary Care is the largest physician-owned primary care group in the United States. We have a broad team of over 350 internists, family physicians, pediatricians, and specialists serving Columbus and other Central Ohio locations.