Summa Health

Chief Information Security Office (CISO)

Summa Health$202K — $302K *
Akron, OH 44312In-Person
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, Business Administration, or related field; advanced degree preferred.
  • Over 10 years in information security, including 5+ years in a senior leadership role with delivery accountability.
  • Healthcare experience with understanding of EHR platforms, HL7/FHIR, and clinical workflows essential for security design.
  • Three current certifications are required, including one in cloud security; preferred certifications listed in details.
  • Advanced knowledge of cybersecurity governance frameworks and risk management processes.
  • Familiarity with emerging technologies such as generative AI and their associated risks.

Responsibilities

  • Develop and implement the enterprise cybersecurity strategy for Summa Health System and SummaCare.
  • Direct accountability for cybersecurity architecture and implementation across the organization.
  • Manage and mitigate cybersecurity risks to align with business objectives and regulatory requirements.
  • Maintain technical currency on emerging cyber threats, including AI and cloud platforms.
  • Ensure HIPAA Security compliance and readiness for regulatory audits.
  • Oversee vendor risk management and ensure compliance with contractual security requirements.
  • Evaluate and integrate safeguards for new technologies while addressing data protection and regulatory risks.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • Basic Life and Accidental Death & Dismemberment insurance.
  • Short-Term and Long-Term Disability coverage for financial security.
  • Retirement Savings Plan with competitive options.
  • Flexible Spending Accounts for healthcare and dependent care costs.
  • Employee Assistance Program (EAP) to support employee well-being.
  • Education Assistance to encourage professional growth and development.
  • Identity Theft Protection to enhance personal security.
  • Pet Insurance to support loving pet owners.
Full Job Description
Chief Information Security Officer (CISO)

Full-time / Benefits eligible

Location 1077 Gorge Blvd, Akron, OH 44310

Summary:

Under general direction of the CIO, the CISO is a senior executive accountable for building, owning, and delivering Summa Health System's enterprise cybersecurity program across both the health system and the SummaCare health plan. This is a delivery role: the CISO authors strategy, holds direct accountability for architecture and implementation, and manages cybersecurity risk to acceptable levels aligned with business objectives.

The CISO maintains ongoing technical currency - including on the AI threat surface, cloud platforms, and emerging attack vectors - and applies it pragmatically in support of patient care, business operations, and regulatory obligations. The dual provider-and-payer mandate is defining: the CISO must be fluent in HIPAA Security Rule compliance, OCR audit readiness, and health plan obligations including Ohio Department of Insurance requirements, and serves as designated Information Security Official for Summa Health pursuant to 45 CFR Subchapter C, Section 164.308(a)(2).

Minimum Qualifications:

1. Formal Education Required:

Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, Business Administration, or related field - or equivalent combination of education and experience. Advanced degree (MS, MBA, or equivalent) preferred.

2. Experience and Training Required:

Ten (10) + years of progressive information security experience, with at least five (5) in a senior leadership role carrying direct delivery accountability - not solely advisory or governance. Healthcare experience required, with demonstrated understanding of EHR platforms (Epic preferred), HL7/FHIR, EDI, and clinical workflow constraints affecting security program design.

3. Certifications required:

Three (3) current, non-lapsed certifications, with at least one being a cloud security certification or recognized equivalent. Accepted certifications listed below under Certifications preferred.

4. Certifications preferred:

ISC2 Certified Information Systems Security Professional (CISSP), ISC2 Certified Cloud Security Professional (CCSP), ISACA Certified Information Security Manager (CISM), ISC2 Healthcare Information Security and Privacy Practitioner (HCISPP)

5. Other Skills, Competencies and Qualifications:

Advanced knowledge of how cybersecurity capabilities support foundational business and clinical/operational workflows, including EHR platforms, interoperability standards (HL7/FHIR, EDI 834/837), and hybrid on-premises and cloud environments (IaaS, PaaS, SaaS).

Advanced knowledge of cybersecurity governance frameworks (NIST CSF, HITRUST, HIPAA Security Rule, PCI DSS, COBIT, ITIL), information assurance principles (confidentiality, integrity, availability, authenticity, non-repudiation), and risk management processes including cyber threats, vulnerabilities, incident response, IT Change Management, and Business Continuity.

Advanced knowledge of third-party and vendor risk management (outsourced service assessment, contractual security requirements, Business Associate oversight); and IT budget, planning, forecasting, and financial management to justify security investments by risk reduction and business impact.

Working knowledge of emerging technology risk domains - including analytics, generative AI, and agentic AI workflows - and the ability to evaluate and integrate safeguards for data protection, misuse, and regulatory risk.

6. Level of Physical Demands:

Sedentary: Exerts up to ten pounds of force occasionally and/or a negligible amount of force frequently.

$97.02/hr - $145.53/hr

The salary range on this job posting/advertising is base salary exclusive of any bonuses or differentials. Many factors, such as years of relevant experience and geographical location are considered when determining the starting rate of pay. We believe in the importance of pay equity and consider internal equity of our current team members when determining offers. Please keep in mind that the range that is listed is the full base salary range. Hiring at the maximum of the range would not be typical.

Summa Health offers a competitive and comprehensive benefits program to include medical, dental, vision, life, paid time off as well as many other benefits.

  • Basic Life and Accidental Death & Dismemberment (AD&D)
  • Supplemental Life and AD&D
  • Dependent Life Insurance
  • Short-Term and Long-Term Disability
  • Accident Insurance, Hospital Indemnity, and Critical Illness
  • Retirement Savings Plan
  • Flexible Spending Accounts - Healthcare and Dependent Care
  • Employee Assistance Program (EAP)
  • Identity Theft Protection
  • Pet Insurance
  • Education Assistance
  • Daily Pay

#LI-AW1

About Summa Health

Summa Health is a non-profit healthcare system based in Akron, Ohio. The system was founded in 1989 and has since grown to become one of the largest healthcare providers in the region. Summa Health operates several hospitals, outpatient centers, and other healthcare facilities throughout Northeast Ohio. The system provides a wide range of services, including primary care, specialty care, and emergency care. Summa Health is committed to providing high-quality, patient-centered care and has received numerous awards and recognitions for its clinical excellence and patient satisfaction.
Learn more about Summa Health
Size
7,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Summa Health

More Healthcare Jobs

Find similar Chief Information Security Office (CISO) jobs: