HCA Healthcare

Director of IPS Risk Management

HCA Healthcare$125K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required
  • Master's degree preferred
  • 3+ years of leadership experience
  • 7+ years in IT, security, privacy, or healthcare
  • CISSP, CISA, and/or CRISC credentials preferred

Responsibilities

  • Develop and oversee cybersecurity risk management strategies
  • Ensure compliance with relevant regulations (e.g., HIPAA, PCI)
  • Implement and mature risk management roadmaps
  • Analyze and report on organizational risk positions
  • Collaborate with stakeholders for program governance
  • Mentor and guide team members towards achieving objectives
  • Foster communication and collaboration across departments

Benefits

  • Incentive eligibility
  • Professional development opportunities
  • Support for work/life balance
  • Open communication culture
Full Job Description
This position is incentive eligible.

Job Summary and Qualifications

The Director of Information Protection & Security (IPS) Risk Management leads the risk management function for IPS. In this critical leadership position, you will be responsible for developing and overseeing our organization's comprehensive cybersecurity risk management program. This role will be responsible for developing and implementing a robust cybersecurity risk management strategy aligned with industry best practices and evolving threats. To be successful in this role, the Director of Risk Management must be able to clearly communicate cyber risks to all levels of the organization.

This leader will be key in implementing a risk management program that results in the identification, prioritization, and reduction of cybersecurity and ensures compliance for all in-scope facilities. This trusted advisor will help raise the protection bar by building strong relationships with technical and non-technical stakeholders to make risk visible, facilitate well-informed decision, and drive accountability. The ability to clearly communicate and report cybersecurity risk, and manage organizational relationships, will be key to the success of this role. In addition, this role must be able to establish a outcome-driven metrics approach to risk management and utilize protection level agreements as a mechanism to establish risk thresholds.

This position is expected to promote a culture that supports operating with an acceptable level of risk, developing standardized risk management criteria including but not limited to threats, vulnerabilities, likelihood, impact, and maturity, establishing risk tolerance, planning risk analysis (e.g. Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining the risk register to prioritize risk reduction actions and activities is implemented. This position is also responsible for evolving the organization's current risk treatment framework. This position is also responsible for collaborating with Information Security on the development, configuration, and implementation of the Risk Management Archer GRC application.

This position requires a candidate who can, with minimal guidance, analyze business requirements and processes, understand colleague behaviors, facilitate and lead meetings with key stakeholders within the organization, provide industry expertise and knowledge in the identification and mitigation of organizational risk, and enable decision making to support the adherence to industry standards and federal regulations.

The Director of IPS Risk Management provides guidance, direction, and mentorship to staff members to support the overall team goals and deliverables. A qualified candidate must be a highly motivated self-starter and be committed to delivering quality outcomes that meet team and organizational goals.

What you will do in this role:

Quality

  • Work as part of the IPS department's leadership team to develop company requirements, strategies, priorities, processes, implementation plans, and assurance necessary to protect the company against information protection and security risks that could impact patients, employees, and the financial success of the business
  • Remain knowledgeable of legislative, regulatory, contractual, and other compliance requirements (e.g. HIPAA, PCI, SOX, Joint Commission) as well as departmental policies, standards, and procedures and participating in revision processes
  • Develop and lead the strategy to mature the risk management roadmap, create new roadmaps where needed, and ensure all roadmaps align with business objectives for the key focus areas
  • Provide periodic analysis of Company IPS-related risk position, based on analysis of current controls status and current threat landscapes
  • Monitor developments in related industries and communicate on the potential impact on or applicability to the organization
  • Ensure metrics are identified within risk management and remediation strategy that help demonstrate risk reduction and report progress to IPS leadership and company executive leadership
  • Develop risk register and be aware of associated remediation plans to respond to previously unidentified or inadequately addressed risk areas
  • Build rapport, credibility, and cohesion across IPS and other stakeholders across the enterprise
  • Partner with Internal Audit and IPS Leadership to ensure periodic reviews of the risk management program are performed to obtain independent assessments of the program's effectiveness
  • Partner with key stakeholders (e.g. Security Architects, DISAs) within IPS as well as with Internal Audit, Enterprise Risk Management, Legal, and ITG to ensure appropriate oversight and governance of the program
  • Ensure the team is involving all relevant stakeholders in major decisions; recognizing multiple agendas and making/communicating final decisions in ways that foster maximum ownership and minimum resistance


Service

  • Lead the team in providing risk-based security perspective through consulting and collaboration
  • Lead the team in facilitating and guiding business decisions and solutions

People

  • Accountable for the successful completion of organizational objectives through team members
  • Establish mutual objectives and targets for team members
  • Mentor team members, including developing and monitoring their personal development plans, and provide feedback via the annual performance review process
  • Promote a culture of collaboration, work/life balance, and open communication
  • Encourage new ways of thinking and problem solving
  • Create a team environment where members embrace change and adopt new practices
  • Stay engaged with team members through 1:1s, rounding, and performance review activities


Growth

  • Monitor developments in related industries and communicate on the potential impact on or applicability to the organization
  • Build rapport, credibility, and cohesion within IPS and with other stakeholders across the enterprise
  • Participate in educational opportunities to build and maintain team knowledge of evolving risk, information security, and privacy concepts


Finance

  • Responsible for ensuring proposed future work efforts/projects are appropriately captured with labor and spend estimates and submitted for leadership prioritization and funding


What qualifications you will need:

  • Bachelor's degree required
  • Master's degree preferred
  • 3+ year(s) of leadership experience
  • 7+ years of experience in information technology, information security, privacy, and/or healthcare
  • CISSP preferred
  • CISA preferred
  • CRISC preferred

About HCA Healthcare

HCA Healthcare Careers

Join the dedicated team at HCA Healthcare, a leading provider in the medical field, and be part of a company known for its exceptional care and commitment to innovation. At HCA Healthcare, we offer a variety of job opportunities that allow professionals to grow their careers in a supportive and diverse environment.

Work You’ll Do

At HCA Healthcare, you will contribute to a culture that values patient care above all. Our team members are equipped with the skills and resources needed to provide outstanding healthcare services. With positions ranging from nursing to administrative roles, HCA Healthcare is actively hiring and offers a dynamic workplace where leadership and professional growth are encouraged.

Innovate and Lead

Join a team where innovation is at the heart of everything we do. HCA Healthcare is a place where you can lead efforts to improve patient outcomes using the latest technologies and practices in the healthcare industry. Our leadership is committed to fostering a culture of diversity and inclusion, ensuring all team members can thrive.

Professional Growth and Development

HCA Healthcare believes in nurturing the growth of its employees through robust professional development and training programs. Whether you are just starting your career or are a seasoned professional, we provide the tools and training necessary to advance your skills and take on new challenges. Explore our wide range of career paths and find the position that best suits your skills and passions.

Benefits and Culture

Our employees enjoy a range of benefits designed to support their physical, financial, and emotional well-being. From comprehensive health insurance to retirement plans and employee wellness programs, HCA Healthcare takes care of its team. Our inclusive culture and commitment to work-life balance make HCA Healthcare a desirable place to work.

Internship and Networking Opportunities

For those new to the healthcare field, HCA Healthcare offers internship programs that provide real-world experience and a pathway to full-time employment. Additionally, our extensive professional network allows for endless networking opportunities, helping you to build relationships and advance your career.

Join Our Team

Search open positions that match your skills and interests. We look for passionate, curious, creative, and solution-driven team players. Ready to start your journey with HCA Healthcare? Prepare your resume, sharpen your interview skills, and apply today to become part of a team that’s dedicated to improving lives.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work at HCA Healthcare.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at HCA Healthcare. Explore the possibilities with HCA Healthcare, where your career is nurtured, and your contributions are valued. Join us in our mission to deliver high-quality patient care through innovative practices and a compassionate approach.
Learn more about HCA Healthcare
Size
204,000 employees
Market Cap
$67.9 billion
Industry
Net Income
$3.7 billion
Founded
1968
5 Year Trend
+7.2%
Revenue
$51.5 billion
NASDAQ

Similar Jobs

More Jobs at HCA Healthcare

More Information Technology Jobs

Find similar Director of IPS Risk Management jobs: