Chief Information Security Officer

Baptist Health Care

$150K — $180K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Information Security, Computer Science, Information Technology, Healthcare Informatics, or related field required; Master's Degree preferred.
  • Minimum 7 years of progressive experience in information security, cybersecurity, or technology leadership, with at least 5 years in a healthcare leadership role.
  • Professional certifications such as CISSP, CISM, CHPS, HCISPP, or CRISC are preferred.
  • Knowledge of state and federal information security laws, including HIPAA, NIST, and PCI.
  • Demonstrated communication, presentation, and facilitation skills.

Responsibilities

  • Builds and maintains a comprehensive information security program aligned with organizational policies.
  • Evaluates emerging security trends and applies appropriate tools to mitigate risks.
  • Leads the cybersecurity incident response program, including crisis management and recovery validation.
  • Collaborates with senior management to establish governance for the security program.
  • Conducts periodic risk assessments and develops security risk management plans.
  • Oversees vendor risk management and establishes cybersecurity requirements for third parties.
  • Presents cybersecurity risk reports to executive leadership and establishes security metrics.

Benefits

  • Opportunity to work with advanced cybersecurity frameworks and technologies in a healthcare setting.
  • Engagement with senior leadership and the board on critical cybersecurity issues.
  • Participation in shaping the cybersecurity strategy impacting patient care and organizational resilience.
  • Involvement in cross-departmental collaboration to enhance security across clinical and operational functions.
Full Job Description
Job Description

The Chief Information Security Officer (CISO) is responsible for the strategic leadership, governance, and
execution of Baptist Health Care's enterprise cybersecurity program. The CISO establishes and maintains a
comprehensive information security program designed to protect the confidentiality, integrity, and availability of
organizational information assets, technology systems, connected medical devices, and digital services while
enabling clinical, operational, and business objectives. The CISO leads cybersecurity strategy, cyber risk
management, regulatory compliance, security operations, incident response, business resilience, third-party
risk, and security awareness initiatives across the enterprise. The position works under the direction of the Vice President and Chief Information Officer with support from the General Counsel and Chief Compliance Officer.

Responsibilities

Essential Functions
• Builds a strategic and comprehensive information security program that defines, develops, maintains and implements policies and processes that enable consistent, effective information security practices which minimize risk and ensure the integrity, confidentiality and availability of information that is owned, controlled and processed within the organization. Ensures information security policies, standards, and procedures are up to date.
• Evaluates security trends, evolving threats, risks and vulnerabilities and applies tools to mitigate risk as necessary. Familiar with sourcing information from DHHS, AHCA, NIST, PCI, ISO, Joint Commission and other regulatory and standards bodies.
• Leads the organization's cybersecurity incident preparedness and response program, including cyber crisis management, ransomware readiness, incident response planning, tabletop exercises, recovery validation, and post-incident lessons learned activities.
• Collaborates with organization senior management, Privacy Officer, and Corporate Compliance officer to establish governance for the security program.
• Is responsible for initial and periodic information security risk assessment/analysis, mitigation and remediation. Responsible for development and implementation of security risk management plan. Ensure organization has audit controls to monitor activity on electronic systems that contain or use electronic protected health information.
• Ensure the organization has and maintains appropriate system use and disclosure / confidentiality statement.
• Participates in the development, implementation, and ongoing compliance monitoring of all BA's and business associate agreements, to ensure -security concerns, requirements, and responsibilities are addressed.
• Assists Privacy Officer as needed with breach determination and notification processes under HIPAA and applicable State breach rules and requirements.
• Maintains current knowledge of applicable federal and state security laws, licensing and certification requirements and accreditation standards.
• Serves as information security consultant to all departments for all data security related issues with understanding of advancing technologies including Encryption, Clinical Device Convergence, Bring-Your-Own-Device (BYOD), premise and with cloud-based computing.
• Attains all agreed to goals and objectives within specified time frames, as part of the organization's overall mission.
• Oversees third-party security assessments and vendor risk management programs. Establishes cybersecurity requirements for vendors, business associates, cloud providers, and strategic partners. Evaluates independent security attestations including HITRUST, SOC 2 Type II, ISO 27001, and NIST alignment.
• Present cybersecurity risk reports to executive leadership and board committees
• Establish security metrics and maturity benchmarks
• Effectively communicates departmental, organization, and industry information to staff.
• Develops cybersecurity standards for connected medical devices and clinical technologies. Partners with Clinical Engineering, Biomedical Services, and clinical leadership to manage cybersecurity risks associated with medical equipment.

Qualifications

Minimum Education

  • Bachelor's Degree in Information Security, Computer Science, Information Technology, Healthcare Informatics, or related field required. Master's Degree preferred.


Minimum Work Experience

  • Minimum 7 years of progressive information security, cybersecurity, risk management, or technology leadership experience, including at least 5 years in an information security leadership role within a complex healthcare environment.


Licenses and Certifications

  • Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Healthcare Privacy and Security (CHPS), Healthcare Information Security and Privacy Practitioner (HCISPP), and/or Certified in Risk and Information Systems Control (CRISC) are preferred.


Required Skills, Knowledge and Abilities

  • Knowledge and experience in state and federal information security laws, including but not limited to HIPAA, including NIST, PCI and all other applicable regulation.
  • Demonstrated organization, facilitation, written and oral communication, and presentation skills.
  • Self-starter who is results oriented, with a willingness and desire to work with and through others to accomplish departmental and organizations objectives.
  • A team player who is able to work well with all levels of the organization.
  • Politically savvy with a high tolerance for ambiguity and can work successfully in a matrix management model.
  • Proven organizational, leadership and consensus-building skills related to developing a shared vision among diverse stakeholders, systems-thinking, innovation, and the guiding and implementation of successful strategies and enterprises within a complex system in a competitive marketplace.


Similar Jobs

More Jobs at Baptist Health Care

More Healthcare Jobs

Find similar Chief Information Security Officer jobs: