Vice President of Information Security

WELLDYNE

• $175K — $210K *
Healthcare
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, IT, computer science, risk management or related field; OR equivalent experience.
  • 12+ years progressive experience in information security, security operations, or related disciplines.
  • 7+ years in leadership roles overseeing security teams and complex programs.
  • Proven track record in developing and executing enterprise security strategies and budgets.
  • Experience leading significant cybersecurity incidents and reporting to senior executives.
  • Ability to influence across complex, regulated environments and oversee security personnel.

Responsibilities

  • Own and maintain the enterprise information security strategy and roadmap.
  • Manage enterprise cybersecurity risk management program including risk identification and assessment.
  • Prepare cybersecurity risk reports for executive leadership and governance bodies.
  • Develop and manage the annual information security budget and investments.
  • Lead and develop internal information security personnel and define staffing needs.
  • Oversee security architecture governance for cloud, infrastructure, and emerging technologies.
  • Direct security operations and coordinate responses to cybersecurity incidents.

Benefits

  • Leadership role in shaping enterprise security strategy and governance.
  • Opportunity to work with executive leadership and Board of Directors.
  • Directly influence the growth and capability of the security team.
  • Engagement with a variety of stakeholders across the organization.
  • Involvement in cutting-edge technologies and emerging threats in cybersecurity.
Full Job Description
Summary
The Vice President, Information Security is a senior enterprise leader responsible for translating business strategy and organizational risk priorities into a comprehensive, measurable information security program. The role owns enterprise security strategy and roadmap execution, cyber risk governance, security budget planning, security assurance, architecture governance, security operations oversight, provider and vendor security governance, and executive decision support.
The Vice President provides leadership across the full security lifecycle, from prevention and architecture through detection, incident response, remediation, assurance, and executive reporting. The role directly manages internal security personnel, establishes clear accountability across internal teams and service providers, and builds the capabilities, operating model, and talent required to mature the enterprise security program.

The role may serve as the organization's designated HIPAA Security Officer, subject to formal organizational appointment, and is responsible for coordinating the administrative, physical, and technical safeguards required to protect electronic protected health information in partnership with Privacy, Compliance, Legal, Technology, Operations, and business leadership.

Essential Duties and Responsibilities
  • Enterprise Security Strategy and Roadmap
    • Own and maintain the enterprise information security strategy, multi-year capability roadmap, annual priorities, and measurable objectives aligned to business strategy, regulatory obligations, technology transformation, and the organization's risk profile.
    • Translate enterprise objectives into security capabilities, investment priorities, staffing plans, operating models, and measurable outcomes.
    • Advise executive leadership on emerging threats, material security risks, strategic tradeoffs, and investments required to maintain an appropriate security posture.
    • Ensure security is engaged early in material cloud, infrastructure, application, data, AI, vendor, integration, and enterprise transformation initiatives.
  • Enterprise Cyber Risk Ownership and Governance
    • Own the enterprise cybersecurity risk-management program, including risk identification, assessment, treatment recommendations, escalation, exception governance, and ongoing monitoring.
    • Establish risk thresholds, decision criteria, escalation standards, and governance practices consistent with approved enterprise risk policies and business risk-owner accountability.
    • Provide clear, evidence-based cyber risk reporting to executive leadership and governance bodies, including trends, material exposures, remediation status, and treatment options.
    • Partner with Compliance, Privacy, Legal, Quality, Internal Audit, Enterprise Risk, and business leaders on HIPAA, HITRUST, PCI DSS, SOC, contractual, pharmacy, client, and regulatory security obligations.
    • Maintain defensible risk, exception, remediation, assurance, and governance records in approved systems.
  • Board, Audit Committee, and Executive Reporting
    • Prepare and present cybersecurity posture, material risks, incidents, program maturity, strategic priorities, and investment needs to executive leadership and, as requested, the Board of Directors, Audit Committee, or other governing committees.
    • Develop executive and board-level metrics that connect security performance, control effectiveness, incidents, provider performance, and remediation outcomes to enterprise risk and resilience.
    • Provide concise decision packages that clearly identify the issue, business impact, available treatment options, recommended actions, accountable owners, and residual risk.
  • Security Budget and Investment Ownership
    • Own development and management of the annual information security budget, including personnel, technology, managed services, consulting, assessments, and strategic investments.
    • Develop multi-year security investment forecasts tied to the security roadmap, risk reduction priorities, regulatory requirements, and business growth.
    • Monitor security spend, vendor value, contract performance, and return on security investments; recommend reallocation or corrective action when outcomes do not meet expectations.
    • Partner with Finance, Procurement, Technology, and executive leadership on business cases, sourcing decisions, renewals, and material security investments.
  • Security Leadership and Personnel Management
    • Directly lead and develop internal information security personnel, including goal setting, performance management, coaching, succession planning, workload prioritization, and capability development.
    • Define the security organizational model, role clarity, staffing requirements, sourcing strategy, and skills needed to support the enterprise security program.
    • Create a culture of accountability, sound judgment, continuous improvement, and effective partnership with Technology, Operations, Product, Compliance, Privacy, Legal, Quality, and business teams.
    • Provide leadership continuity for the information security function and ensure appropriate delegation, escalation, and decision coverage.
  • Security Architecture and Engineering Governance
    • Lead risk-based security architecture governance for material cloud, infrastructure, application, identity, endpoint, network, data, integration, vendor, AI, and emerging-technology initiatives.
    • Establish reusable security patterns, standards, decision criteria, exception processes, and architecture-review practices.
    • Provide senior review and challenge of architecture diagrams, data flows, access models, logging strategies, resilience, encryption, data protection, and vendor capabilities.
    • Ensure accountable solution design and implementation ownership remains with Technology, Product, Operations, and delivery teams while Security establishes requirements and validates material risk.
  • Security Assurance, Controls, and Remediation
    • Own the enterprise security assurance operating model, including evidence, testing, validation, acceptance, and closure standards.
    • Direct independent validation of control implementation, remediation, corrective actions, and closure evidence.
    • Identify systemic weaknesses, recurring findings, unsupported closure claims, aging actions, and control-quality trends; escalate based on materiality.
    • Ensure material remediation and preventive actions are assigned, tested, evidenced, and tracked to closure.
  • Security Operations, Incident Response, and Resilience
    • Provide executive leadership for security operations, threat monitoring, vulnerability management, identity security, endpoint security, logging, detection, and response capabilities, whether delivered internally or through service providers.
    • Lead or provide senior security leadership during material cybersecurity incidents, coordinating technical response, executive communications, third-party resources, legal and regulatory stakeholders, corrective actions, and lessons learned as appropriate to the incident command model.
    • Maintain readiness for material incidents, provider failures, audit issues, control breakdowns, and urgent enterprise-risk decisions.
    • Ensure post-incident corrective actions address root causes and are validated through evidence and testing.
  • Vendor and Third-Party Security Governance
    • Own the security governance model for strategic security providers and material third-party technology relationships.
    • Set expectations for technical quality, evidence, service levels, corrective actions, roadmap execution, risk reduction, and measurable outcomes.
    • Challenge incomplete analysis, repeat failures, unsupported conclusions, missed commitments, and provider performance that does not meet organizational expectations.
    • Oversee security-provider scorecards, service reviews, corrective-action plans, executive escalations, and material security-related sourcing decisions.
    • Direct technical security due diligence and risk review for material third-party relationships and ensure identified risks are appropriately treated and tracked.
  • HIPAA Security Officer Responsibilities
    • When formally designated, serve as the HIPAA Security Officer and oversee the organization's HIPAA Security Rule program for electronic protected health information.
    • Coordinate the development, implementation, maintenance, and oversight of security policies, procedures, safeguards, risk analysis, risk-management activities, and security incident processes applicable to electronic protected health information.
    • Partner with the Privacy Officer, Compliance, Legal, Human Resources, Technology, Operations, and business leadership to ensure security responsibilities are integrated into the organization's broader HIPAA compliance program.
    • Report material HIPAA security risks, control deficiencies, incidents, and remediation status through established governance and escalation channels.
  • Decision Rights and Accountability Boundaries
    • May establish information security standards, assurance requirements, architecture-governance practices, security operating procedures, and control-validation criteria within approved enterprise policy and authority.
    • May require additional evidence, testing, corrective action, security review, or risk analysis before recommending closure or implementation of material technology changes.
    • May escalate material cyber risk, unresolved control deficiencies, provider-performance concerns, overdue commitments, and security investment needs to executive governance.
    • May recommend risk treatment, safeguards, investment priorities, exceptions, and conditions for implementation.
    • Does not independently accept material business risk unless expressly delegated through an approved enterprise authority model; accountable business risk owners retain final risk-treatment or acceptance authority where required.
    • Does not replace accountable Technology, Product, Operations, Compliance, Privacy, Legal, Quality, Internal Audit, provider, or business owners.

Minimum Qualifications
  • Bachelor's degree in cybersecurity, information technology, computer science, risk management, business, or a related field, or equivalent education and relevant experience.
  • At least 12 years of progressive experience across information security, security operations, architecture, engineering, assurance, cyber risk, incident response, IT audit, or related disciplines.
  • At least 7 years of leadership experience with responsibility for security teams, complex security programs, enterprise risk, architecture governance, security operations, or strategic providers.
  • Demonstrated experience developing and executing enterprise security strategy, multi-year roadmaps, budgets, staffing plans, metrics, and investment priorities.
  • Demonstrated experience leading significant cybersecurity incidents and communicating material cyber risk to senior executives.
  • Demonstrated experience presenting cybersecurity matters to executive leadership; Board or Audit Committee exposure strongly preferred.
  • Demonstrated ability to lead security personnel, challenge providers, influence across organizational boundaries, and operate effectively in a complex regulated environment.
  • Broad working knowledge of cloud, identity, endpoint, network, application, vulnerability management, logging and detection, data protection, incident response, resilience, third-party security, and security architecture controls.
  • Strong working knowledge of healthcare security and privacy obligations, including HIPAA and protection of PHI/ePHI.
  • Preferred Qualifications
  • Experience in healthcare, pharmacy, pharmacy benefit management, specialty pharmacy, or another highly regulated industry.
  • Experience with HITRUST, PCI DSS, SOC reporting, NIST CSF, NIST 800-53, ISO 27001, or comparable frameworks.
  • Experience with AWS and Microsoft environments, cloud security, security architecture governance, and provider-based operating models.
  • Relevant certification such as CISSP, CISM, CRISC, CCSP, SABSA, AWS Security, Microsoft Security, or comparable credential.
  • Prior experience serving as, supporting, or operating in close partnership with a HIPAA Security Officer, CISO, or equivalent enterprise security executive.

Expected Outcomes
  • A clear, measurable enterprise security strategy and multi-year roadmap aligned to business priorities and risk.
  • Improved visibility and accountability for enterprise cyber risk, control effectiveness, remediation, and security investment.
  • Consistent executive, Board, and Audit Committee reporting that supports informed risk and investment decisions.
  • A disciplined security budget and investment model tied to measurable capability and risk-reduction outcomes.
  • A mature internal security leadership team with clear accountability, development plans, and reduced dependency on individual leaders or providers.
  • Stronger provider and third-party accountability, evidence quality, remediation validation, and service performance.
  • Earlier security engagement in material initiatives and fewer avoidable late-stage security issues.
  • Reliable incident readiness, response leadership, corrective-action governance, and organizational resilience.
  • A defensible, sustainable security governance and HIPAA security program appropriate for a regulated healthcare organization.

Similar Jobs

More Jobs at WELLDYNE

More Healthcare Jobs

Find similar Vice President of Information Security jobs: