SCA Health is a leader in redefining specialty care through accessible, patient-centered practice solutions. They are seeking a Director of IT Security Operations and Engineering to provide enterprise-wide leadership for security operations, including strategy, governance, and incident response coordination across various environments.
Responsibilities:
- Provide enterprise-wide leadership and accountability for Security Operations, including strategy, operating model, governance, and measurable outcomes
- Lead Security Operations Engineering, vulnerability management operations, incident response coordination, and operational security tooling across the enterprise
- Establish annual and long-range security operations goals, strategies, metrics, reporting mechanisms, service expectations, and maturity roadmaps for continual improvement
- Define and standardize security operations processes, controls, and lifecycle management for logging, monitoring, endpoint, infrastructure, and related security services
- Direct enterprise vulnerability management strategy, prioritization, and remediation governance in partnership with infrastructure, application, and operations teams
- Oversee incident readiness, escalation, coordination, and recovery activities, including leadership of cross-functional response efforts and alignment with external security service partners
- Partner with IT, business, clinical leadership, and affiliated security teams to align operational security priorities, service levels, and remediation outcomes
- Assess the effectiveness of security controls and operational practices, communicate risks and performance trends, and recommend corrective actions where needed
- Drive standardization and optimization of security operations tooling, ensuring solutions are scalable, sustainable, and aligned to business and regulatory requirements
- Develop and maintain policies, procedures, standards, and guidelines that support operational security, incident management, and vulnerability response
- Provide executive-level communication and reporting on security operations risks, service performance, remediation progress, and maturity improvements
- Support audit, regulatory, and compliance readiness as it relates to operational security controls and evidence of effective risk treatment
- Coach and lead managers and cross-functional teams to ensure clear accountability, consistent prioritization, and effective execution of security operations initiatives
- Manage day-to-day support operations
- Adhering to company values at all times
- Performing other related duties as assigned
Requirements:
- Bachelor's degree in information technology, cybersecurity, or related field; supplemented with seven (7) or more years of progressive information security experience, including leadership responsibility for security operations, incident response, vulnerability management, or related operational security functions
- Proactive, decisive, action-oriented individual
- Strong written and verbal communication skills, including with Executive audiences
- Excellent interpersonal, leadership, collaboration, facilitation, and negotiation skills
- Able to clearly explain technical issues in a way that nontechnical people can understand
- Ability to be broadly focused and manage multiple efforts concurrently
- Ability to work effectively with all levels of the organization, including staff, business stakeholders, and all levels of management
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Firewalls, SIEM, DLP, VPN, DMZ, IAM, MFA, Intrusion Detection/Prevention, Encryption, Anti-Malware, MDM, MAM, asset management, VMS and other IT Security solutions is highly preferred