Baptist Health Care logo

Chief Information Security Officer

Baptist Health Care
Posted 1 hour ago
United StatesHybridEngineering & Development
Is this job info correct?

The Chief Information Security Officer (CISO) is responsible for the strategic leadership, governance, and execution of Baptist Health Care's enterprise cybersecurity program. The CISO establishes and maintains a comprehensive information security program designed to protect the confidentiality, integrity, and availability of organizational information assets, technology systems, connected medical devices, and digital services while enabling clinical, operational, and business objectives. The CISO leads cybersecurity strategy, cyber risk management, regulatory compliance, security operations, incident response, business resilience, third-party risk, and security awareness initiatives across the enterprise. The position works under the direction of the Vice President and Chief Information Officer with support from the General Counsel and Chief Compliance Officer.

Essential Functions

  • Builds a strategic and comprehensive information security program that defines, develops, maintains and implements policies and processes that enable consistent, effective information security practices which minimize risk and ensure the integrity, confidentiality and availability of information that is owned, controlled and processed within the organization. Ensures information security policies, standards, and procedures are up to date. Establishes security metrics and maturity benchmarks.
  • Leads the organization's cybersecurity incident preparedness and response program, including cyber crisis management, ransomware readiness, incident response planning, tabletop exercises, recovery validation, and post-incident lessons learned activities.
  • Collaborates with organization senior management, Privacy Officer, and Corporate Compliance Officer to establish governance for the security program. Assists Privacy Officer as needed with breach determination and notification processes under HIPAA and applicable State breach rules and requirements.
  • Evaluates security trends, evolving threats, risks and vulnerabilities and applies tools to mitigate risk as necessary. Maintains responsibility for initial and periodic information security risk assessment/analysis, mitigation and remediation. Develops and implements security risk management plan. Ensures organization has audit controls to monitor activity on electronic systems that contain or use electronic protected health information.
  • Participates in the development, implementation, and ongoing compliance monitoring of all business associate's and agreements, to ensure security concerns, requirements, and responsibilities are addressed. Ensures the organization has and maintains appropriate system use and disclosure/confidentiality statement.
  • Serves as information security consultant to all departments for all data security related issues with understanding of advancing technologies including Encryption, Clinical Device Convergence, Bring-Your-Own-Device (BYOD), premise and with cloud-based computing.
  • Oversees third-party security assessments and vendor risk management programs. Establishes cybersecurity requirements for vendors, business associates, cloud providers, and strategic partners. Evaluates independent security attestations including HITRUST, SOC 2 Type II, ISO 27001, and NIST alignment. Presents cybersecurity risk reports to executive leadership and board committees.
  • Develops cybersecurity standards for connected medical devices and clinical technologies. Partners with Clinical Engineering, Biomedical Services, and clinical leadership to manage cybersecurity risks associated with medical equipment.
  • Attains all agreed to goals and objectives within specified time frames, as part of the organization’s overall mission.
  • Maintains responsibility for department’s operational excellence; ensures department delivers quality services in accordance with applicable policies, procedures, and professional standards.
  • Manages team members, which includes orientation, development and evaluation of team members, and monitoring the provision of delivering quality services. Participates in the recruiting, interviewing, and selecting of team members following policies, guidelines and applicable laws. Evaluates team member’s performance relative to job goals and requirements. Provides coaching to staff, recommends education programs, and ensures adherence to internal policies and standards.
  • Maintains responsibility for the fiscal management of department and assures proper utilization of organization’s financial resources.
  • Effectively communicates departmental, organization, and industry information to staff.


Minimum Education

  • Bachelor's Degree Computer Science, Cybersecurity, Health Informatics, Information Technology, Related field Required or
  • Four years of related experience in lieu of bachelor’s degree Required
  • Master's Degree Computer Science, Cybersecurity, Health Informatics, Information Technology, Related field Preferred


Minimum Work Experience

  • 7 years Progressive information security, cybersecurity, risk management, or technology experience. Required
  • 5 years Information security leadership role within a complex healthcare environment. Required


Licenses and Certifications

  • Certified Information Professional (CIP) AIIM International Upon Hire Preferred
  • Certified Information Security Manager (CISM) ISACA Upon Hire Preferred
  • Certified in Healthcare Privacy and Security (CHPS_AHIMA) American Health Information Management Association Upon Hire Preferred
  • Healthcare Information Security and Privacy Practitioner (HCISPP) ISC2 Upon Hire Preferred
  • Certified in Risk and Information Systems Control (CRISC) ISACA Upon Hire Preferred


Required Skills, Knowledge and Abilities

  • Knowledge and experience in state and federal information security laws, including but not limited to HIPAA, NIST, PCI and other applicable regulation; licensing and certification requirements; and accreditation standards
  • Demonstrated organization, facilitation, written and oral communication, and presentation skills.
  • Self-starter who is results oriented, with a willingness and desire to work with and through others to accomplish departmental and organizations objectives.
  • Team player who is able to work well with all levels of the organization.
  • Politically savvy with a high tolerance for ambiguity and can work successfully in a matrix management model.
  • Proven organizational, leadership and consensus-building skills related to developing a shared vision among diverse stakeholders, systems-thinking, innovation, and the guiding and implementation of successful strategies and enterprises within a complex system in a competitive marketplace.
  • Familiar with sourcing information from DHHS, AHCA, NIST, PCI, ISO, Joint Commission and other regulatory and standards bodies.

Similar jobs