What are the responsibilities and job description for the Director, Risk Management position at Point32Health?
Cyber and Information Security Director
The focus area for this Director will be leading the organization's ability to effectively respond to and recover from events that result in interruption of Point32Health's business operations.
Key Responsibilities:
- Developing and implementing a strategy and practices that will ensure that the organization is prepared for events that may result in extended interruption of technology systems, applications, or business operations.
- Setting requirements and providing education to business and technology stakeholders about their roles in supporting the organization's business continuity, disaster recovery, and incident/crisis management disciplines.
- Development, maintenance, and adoption of a single incident/crisis management framework across the organization - all hazard/threat types.
- Leading tabletop and simulation exercises to help ensure preparedness and to proactively identify and address opportunities for improvement.
- Anticipate the impact of core systems, applications, facilities, and vendor relationships being unavailable and implement plans that will reduce the impact of those events.
The Director, Cyber & Information Security, will report into the Chief Information Security Officer (CISO) for Point32Health. The Director leads Cyber & Information Security managers and/or security leaders to oversee and help to ensure that core programs are effectively implemented.
This role is integral in driving the organization's Cyber & Information Security strategy and objectives. The Director, Cyber & Information Security is considered a leader within the IT Department and is expected to work collaboratively to identify, influence, and enhance areas of improvement across the organization.
Main Objectives:
- Manage a team of managers/senior leaders responsible for overseeing the core pillars of Cyber & Information Security
- Develop and implement policies, standards, and guidelines that continuously increase the organization's Cyber & Information Security program maturity
- Lead communication and collaboration efforts with the business and IT to ensure quality solutions are delivered
- Evangelize the objective to embed security behaviors and principles into the Point32Health culture through active engagement, education, awareness, and partnership
- Develop operational excellence in anticipation and response to evolving threats and opportunities to improve cyber and information security
- Identify business risk and communicate risk to appropriate leadership
- Collaborate with stakeholders to define and implement technical and non-technical controls designed to cyber risk objectives and legal / regulatory obligations
- Maintain the risk repository to continually identity, prioritize, and mitigate cyber and information security related risk issues
- Participate in various forums and groups across Point32Health to understand the risk environment and to provide recommends that effectively incorporate security objectives while balancing the business impact of recommendations provided
- Facilitate adoption of leading security practices to remain in compliance with regulations and to support our continuous monitoring and improvement goals
- Maintain up-to-date knowledge of the cyber and information security industry, including awareness of new or revised security capabilities, improved security processes, threat scenarios, trends, etc.
- Identify/recommend tools, processes, software, and protocols to advance or replace current security practices, services, or technologies to meet strategic objectives
Other duties and projects as assigned.
Requirements:
- Bachelor's degree in Cyber Security, Computer Science, Risk Management, or related field preferred or equivalent experience
- 10 years combined IT, cyber/information security, risk, audit, compliance, with increasing responsibility
- ~5 years in cybersecurity or field(s) related to the programs for which the role is responsible for
- ~Experience in leading or sponsoring implementation of technical security solutions within large organizations
- ~ Experience in engaging with and managing vendors responsible for implementing processes and/or IT solutions
- ~ Experience creating and maintaining security requirements, guidelines, and procedure documents
- ~ Requires the ability to identify risk within complex, interrelated programs; Ability to communicate effectively across multiple levels of the organization including managing through cross-business area or business unit prioritization discussions
- Strong relationship building skills; Ability to influence all levels of staff and senior management in the decision-making process
- Deep understanding of IT infrastructure, program portfolio management, application design, and secure software development lifecycle (SDLC) methodologies
Commitment to Diversity, Equity & Inclusion
Point32Health is committed to making diversity, equity, and inclusion part of everything we do—from product design to the workforce driving that innovation. Our DEI strategy is deeply connected to our core values and will evolve as the changing nature of work shifts. Programming, events, and an inclusion infrastructure play a role in how we spread cultural awareness, train people leaders on engaging with their teams and provide parameters on how to recruit and retain talented and dynamic talent. We welcome all applicants and qualified individuals, who will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.