Enterprise Information Security Manager
Are you passionate about making a difference in people's lives? Do you enjoy working in a service-oriented industry? If so, this opportunity may be the right fit for you!
This role is responsible for overseeing and coordinating Enterprise Information Security, including Enterprise Governance, Compliance, Business Continuity, Risk Management, and Cybersecurity. Additionally this role would be responsible for the overall Information Security posture of the company and works with various locations and departments to improve all aspects of Information Security. Lastly this role will be responsible for setting the vision for the security program in alignment with all applicable regulatory rules and global best practices, development of the security program and overseeing program execution and ongoing health.
This role...
- Develops, manages, and sets the vision for the Information Security Program.
- Designs the strategy and architecture for security programs.
- Ensures security architecture deliverables reflect and support business, technical, operational, and compliance objectives.
- Recruits and manages the Cybersecurity & Information Assurance teams.
- Develops and maintains detailed Security Architecture Plans.
- Centralizes Threat Intelligence and 360-degree Vulnerability and Risk Management, and produce detailed risk reports and Risk Treatment Plans.
- Maintains awareness of Cybersecurity & Information Assurance industry trends, evaluate new solutions and techniques, and ensure awareness of emerging threats through multiple channels.
- Creates and ensures adherence to security requirements for cloud and on-prem infrastructure, user endpoints, application stacks, SDLC & CI / CD pipelines, and 3rd party SaaS.
- Works with and influence project teams and business contacts in regard to security controls, risk mitigation techniques related to information security.
- Directs initiatives related to Information Security strategic planning.
- Sets and manages budget for Information Security.
- Promotes awareness of Information Security Best Practices.
- Ensures that Information Security is adequately represented across all lines of businesses.
- Prioritizes and delegate Risk Assessment activities and ensure completion of POAMs.
- Oversees newly implemented technologies and coordinate internal / external audits.
- Defines Secure Application Development Best Practices and Processes.
- Owns Audit application architectures and environments to ensure security standards are effective.
- Ensures compliance of the Information Security programs with all Regulatory, Contractual, Association, and Client requirements.
- Partners with IT organization on the development, planning, and execution of major security initiatives.
- Provides direction for Enterprise Risk Management, Business Continuity and Disaster Recovery Efforts, Policies and Procedures, and Record Retention & Destruction.
- Leads compliance efforts consisting of Sarbanes-Oxley (SOX), HIPAA, ISO 27001, HITRUST, SSAE 18 SOC 2 Type I & II reporting, CSA STAR, NIST CSF, client audit response (For IT, Security, and related items), PCI, and other compliance requirements.
- Develops, tracks, and reports on KPIs and OKRs.
- Determines appropriate resourcing of staff in order to achieve goals and objectives.
- Builds an effective senior leadership team through mentoring and formal education that focuses on management and project management principles.
- Defines annual Key Performance Indicators aligned with corporate goals.
- Directs and mentors senior leaders on performance gaps, career development opportunities, and strategies. Directs and coaches senior leaders on all human resource related processes including onboarding, performance management, succession planning, employee relations, selection, terminations, compensation and rewards.
- Accountable for strategic design, execution, and collective results along with others' successful contributions.
- Owns attainment of high employee satisfaction and retention; lead development of program and initiatives within group to attain high employee satisfaction.
- Directs and influences change management initiatives to drive improvements and efficiencies cross-functionally.
- Ability to direct and interact collaboratively and communicate effectively with external, internal customers, and stakeholders to address issues and ensure alignment across the organization to drive customer success.
- Prepares and manages budget as assigned; analyzes variances and initiates corrective actions to maximize operational performance.
We are interested in speaking with individuals with the following...
Bachelor's degree in Computer Science, Information Technology or related field preferred.Master's degree desired.Fifteen (15) plus years experience in Information Technology.Ten (10) plus years of experience as an executive leader.Experience developing and presenting meeting materials for executivesExperience using Information Technology Infrastructure Library (ITIL) practices for change, incident and problem managementOr equivalent combination of education and / or experience.Positive Attitude and foster a team environment of curiosity and continuous improvementEffective, versatile and action-orientedExcellent oral and written communications skillsA bias for action and a curious nature that is comfortable questioning the status quo sense of urgencyThe ability to instill trust and confidence in business partners and team membersStrong understanding of IT functions, processes and technologiesStrong understanding of Program and Project Management, Capacity Planning, Project Governance, prioritization of work loadsStrong understanding and experience working with various development principles including SDLC, Waterfall, Agile, Scrum and Kanban Experience working in an agile environment using either SCRUM or KanbanISC(2) CISSP security certification requiredCRISC, CISA, CISM preferredITIL Certification preferredBroad hands-on technical experience with :Cloud and on-prem infrastructure and user endpointsCloud-based back-office environmentsInformation Assurance systems (internal and 3rd party risk management platforms, vulnerability management platforms and consolidation tools, auditor PBC systems, GRC tools, SoD assurance systems, etc.)Salary : $202,300 - 283,000
This role is eligible for a bonus.
Modivcare's positions are posted and open for applications for a minimum of 5 days. Positions may be posted for a maximum of 45 days dependent on the type of role, the number of roles, and the number of applications received. We encourage our prospective candidates to submit their application(s) expediently so as not to miss out on our opportunities. We frequently post new opportunities and encourage prospective candidates to check back often for new postings.
We value our team members and realize the importance of benefits for you and your family.
Modivcare offers a comprehensive benefits package to include the following :
Medical, Dental, and Vision insuranceEmployer Paid Basic Life Insurance and AD&DVoluntary Life Insurance (Employee / Spouse / Child)Health Care and Dependent Care Flexible Spending AccountsPre-Tax and Post-Tax Commuter and Parking Benefits401(k) Retirement Savings Plan with Company MatchPaid Time OffPaid Parental LeaveShort-Term and Long-Term DisabilityTuition ReimbursementEmployee Discounts (retail, hotel, food, restaurants, car rental and much more!)Modivcare is an Equal Opportunity Employer.