Chief Information Security Off

location_onEgg Harbor Township, New Jersey, United Statesschedule2 days ago
apartmentWork style:On-site
trending_upExperience level:Executive
badgeEmployment:Full-time
schoolEducation:High school
Apply Nowopen_in_new

Job description

POSITION SUMMARY

The Chief Information Security Officer (CISO) is the enterprise executive accountable for protecting AtlantiCare’s patients, workforce, data, clinical operations, and reputation from cyber risk. Reporting to the EVP, Chief Information and Digital Officer, the CISO sets the vision, strategy, governance, and operating model for information security and cyber resilience across the health system. This leader translates complex threats, vulnerabilities, and regulatory obligations into clear business and patient-safety risk decisions for executive leadership and the Board.

The CISO leads the enterprise Information Security Program and team; establishes policy, architecture, controls, metrics, and accountability; and ensures readiness to prevent, detect, respond to, and recover from cyber incidents. Working across clinical, operational, technology, biomedical, legal, privacy, compliance, audit, emergency management, and vendor partners, the CISO embeds security by design while enabling AtlantiCare’s strategic, digital, cloud, data, and AI priorities. The role is both strategic and operational and requires sound judgment, calm leadership, executive presence, and the ability to influence outcomes across a complex, highly regulated environment.

KEY RESPONSIBILITIES

  • Enterprise strategy and governance: Develop and execute a multi-year information security and cyber resilience strategy, roadmap, operating model, and budget aligned with AtlantiCare’s strategic plan, enterprise risk appetite, and technology priorities.
  • Executive and Board advisory: Serve as the principal cyber risk advisor to executive leadership and the Board, presenting the organization’s risk posture, material threats, control maturity, investment priorities, risk-acceptance decisions, and program performance in clear business and patient-safety terms.
  • Risk ownership and accountability: Establish governance that enables business and technology leaders to identify, understand, mitigate, accept, and document cyber risk at the appropriate level.
  • Security program leadership: Lead the enterprise Information Security Program and ensure consistent, high-quality execution across governance, risk, compliance, architecture, engineering, operations, incident response, awareness, and third-party risk.
  • Team and partner leadership: Recruit, develop, motivate, and retain a high-performing security team; set clear accountabilities and performance expectations; and oversee managed security service providers, consultants, and dotted-line resources.
  • Policy and control framework: Maintain a practical, risk-based framework of policies, standards, procedures, and controls aligned with applicable laws, regulations, contractual obligations, and recognized practices including NIST CSF 2.0, HHS 405(d) HICP, and the HHS Healthcare and Public Health Cybersecurity Performance Goals.
  • Regulatory assurance: Partner with Legal, Compliance, Privacy, Audit, and operational leaders to maintain compliance with HIPAA, HITECH, the HIPAA Security Rule, and applicable federal and state requirements; oversee assessments, remediation plans, evidence, and regulatory readiness.
  • Security architecture and engineering: Establish security-by-design requirements across identity, network, endpoint, cloud, applications, data, integration, and emerging technologies, advancing zero trust, multifactor authentication, least privilege, privileged access management, segmentation, encryption, and secure configuration.
  • Clinical and medical-device security: Partner with clinical, Biomedical Engineering, Facilities, and operational leaders to protect connected medical devices and clinical technology through accurate inventories, risk-based segmentation, vulnerability management, lifecycle planning, downtime safeguards, and security requirements in procurement.
  • Threat and vulnerability management: Maintain awareness of the external threat environment and direct threat intelligence, exposure management, penetration testing, vulnerability prioritization, and remediation across technology and business owners.
  • Incident response and crisis leadership: Lead the response to significant cyber incidents, including ransomware, data compromise, and extended technology downtime; coordinate executive, clinical, operational, legal, privacy, communications, insurance, and law-enforcement activities; and ensure timely breach assessment, notification, and lessons learned.
  • Cyber resilience and recovery: Partner with Technology, Emergency Management, and clinical operations to align disaster recovery, business continuity, backup protection, recovery testing, downtime procedures, and tabletop exercises with critical business and patient-care priorities.
  • Third-party and supply-chain risk: Establish a lifecycle process to assess and manage cyber risk associated with vendors, business associates, cloud providers, software, services, and other ecosystem partners; ensure appropriate security requirements, contractual protections, monitoring, and concentration-risk decisions.
  • Digital, cloud, data, and AI enablement: Embed proportionate security review into technology intake, procurement, architecture, development, and project delivery. Partner with Data and Analytics, Privacy, Legal, and operational leaders to govern AI tools and models, including data protection, access, acceptable use, monitoring, and third-party risk.
  • Human risk and security culture: Build an enterprise security culture through role-based awareness, phishing simulations, executive and clinical education, targeted interventions for high-risk users, and a network of security champions.
  • Metrics and continuous improvement: Define meaningful key risk and performance indicators, including risk reduction, control coverage, resilience, vulnerability remediation, third-party exposure, and workforce behavior; use results to prioritize resources and improve program maturity.
  • External engagement: Maintain effective relationships with peers, Health-ISAC, cyber insurance partners, law enforcement, CISA, HHS, and other relevant agencies to strengthen preparedness, information sharing, and response.
  • Financial stewardship: Develop and manage the information security budget, investment portfolio, contracts, and vendor performance, ensuring resources are directed to the organization’s highest risks and most critical capabilities.
  • Professional leadership: Demonstrate sound judgment, integrity, urgency, discretion, customer focus, and composure under pressure. Communicate effectively with technical and nontechnical audiences and influence outcomes where formal authority may not exist.
  • Adhere to AtlantiCare policies and procedures and perform other duties as assigned.

WORK ENVIRONMENT

This position requires sitting at a desk or computer a majority of the day, with frequent speaking, reaching, and reading. This position requires occasional lifting up to 20 lbs. This position requires availability outside normal business hours, including evenings, weekends, and holidays, to lead the response to significant security incidents.

REPORTING RELATIONSHIP

This position reports to the EVP, Chief Information and Digital Officer, provides regular cyber risk reporting to executive leadership and the Board, and supervises Information Security staff as assigned.

QUALIFICATIONS

EDUCATION: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Business, Health Informatics, or a related field, or equivalent relevant experience, required. Master’s degree preferred.

LICENSE/CERTIFICATION: CISSP or CISM strongly preferred; CRISC, CISA, CCSP, HCISPP, or comparable security, risk, cloud, or healthcare credentials are desirable.

EXPERIENCE: Ten or more years of progressive cybersecurity, information security, technology risk, or related experience, including at least five years leading teams, enterprise programs, or significant security functions. Health care experience and demonstrated knowledge of HIPAA, HITECH, the HIPAA Security Rule, health information privacy, and the operational and patient-safety implications of cyber events are required.

The successful candidate will have experience advising executives or boards; leading incident response and recovery; managing regulatory, audit, and third-party risk; establishing security architecture and controls across network, identity, endpoint, cloud, application, data, and medical-device environments; and developing multi-year strategy, budgets, metrics, and talent. Experience evaluating AI-enabled platforms and securing major digital or clinical transformation programs is strongly preferred.

Skills mentioned


Health Tech, Healthcare
Egg Harbor Township, New Jersey, United States

AtlantiCare is an award-winning, integrated healthcare system headquartered in Egg Harbor Township, New Jersey. As the largest healthcare provider in southeastern New Jersey, its dedicated team of over 6,500 professionals serves communities across five counties—Atlantic, Burlington, Camden, Cape May, and Ocean—through a comprehensive network of more than 100 locations. The organization's history traces back to the founding of the Atlantic City Hospital in 1898, with AtlantiCare itself being established in 1993. Its core mission is to make a difference in health and healing, one person at a time, driven by a forward-thinking vision of building healthy communities. This commitment is reflected in its wide array of services, which include acute and chronic care, preventive services, and health information services. The system is composed of several key entities, including the AtlantiCare Regional Medical Center (ARMC), the AtlantiCare Foundation, the AtlantiCare Physician Group, and AtlantiCare Health Solutions, an accountable care organization. ARMC is a 628-licensed-bed teaching hospital with two main campuses and is home to the region's only cancer institute, heart institute, and neonatal intensive care unit. Recognized for its commitment to quality and workplace culture, AtlantiCare has been named one of Modern Healthcare's Best Places to Work, and its nursing staff has achieved the prestigious Magnet® designation. Looking to the future, AtlantiCare has launched VISION 2030, an ambitious six-year plan to redefine healthcare delivery. This initiative involves significant investments in technology, including a partnership with Oracle Health to leverage AI and enhance digital infrastructure, and a clinical training affiliation with Drexel University College of Medicine to cultivate the next generation of healthcare professionals.

Apply for this job

Use the application link supplied with this listing to apply to AtlantiCare. Check the destination before entering personal information.

Apply Nowopen_in_new