Manager - Information Security

Stamford Health Stamford, CT
Full Time 130 - Manager
Job Details
Full Time
Day
Stamford, CT
Job Description

As a Certified Great Place to Work organization, Stamford Health understands what it takes to attract talent to improve our workforce and support our mission, to that end we offer:

Competitive salary

Comprehensive, low-cost health insurance plans (including GLP-1 coverage options) available day one

Wellness programs

Paid Time Off accruals

Tax deferred annuity and (403b) pension plan

Tuition reimbursement

Free on-site parking and train station shuttle

Childcare partnership with Children’s Learning Center Regular, Full Time Monday-Friday, 8:00AM-5:00PM Responsibilities: The Manager, Security Operations reports into the Director IS & CISO for Stamford Health. In partnership, the manager and CISO will define and execute Stamford’s Information/Cyber security strategies and operational excellence. The Manager, Security Operations oversees the Information security team and leads the day to the day support of enforcing Stamford’s Information security program. This effort includes perimeter/edge defenses, endpoint security, threat and vulnerability management, new project implementation, enforcing policies and standards, risk management and overall transformation and maturity of the information security initiatives. The Manager will assist the CISO with the support continual/regular refinement and enforcement of our Stamford’s Information Security policies, procedures, programs, and response plans, and with the creation and implementation of those policies, procedures and programs that do not currently exist. - Oversee the delivery and ongoing support of Stamford Health’s information security services. - Oversee the development and implementation of technical cybersecurity initiatives to continuously improve and expand protective and defensive security capabilities. - Monitor and report on key performance metrics to ensure service quality and delivery - Drive security control implementation and maturity in both on-prem and cloud environments and ensure compliance with corporate security policies and regulatory requirements. - Lead a team of Information Security architects, engineers, and analysts that plan, implement and sustain the full lifecycle of various cybersecurity capabilities. - Ensure security assessments of the information technology environment are being performed and with assisting in the developing and implementing security plans to mitigate those risks. - Assist with forensics investigation, penetration testing, implementation of new security solutions, participation in the creation and or maintenance of policies, standards, and procedures. - Recommend changes/upgrades to service components, technologies, processes and metrics to keep pace with the threat landscape and align with and business strategies. - Partner with department leaders / project sponsors in the implementation of secure-by-design initiatives into their business processes. - Develops and/or oversees the development of documentation (procedures, runbooks, etc.) to ensure effective service delivery - Coach and mentor team for high performance, creating a supportive working environment where everyone has the opportunity to fulfill their potential - Maintain up-to-date knowledge of industry standards, best practices and the evolving security threat landscape - Manage information security related tasks performed by the team including, but not limited to: digital forensic investigations, vulnerability management, alert and incident response. - Manage employees including performance management, salary administration, succession planning and workforce development. - Partner & collaborate with other IT teams as necessary to ensure that overall IT objectives are met. - Performs special projects and other duties as assigned by management Qualifications: - Bachelor’s degree in Computer Science, Information Systems, Information Security - Minimum 3 years of healthcare experience - Minimum of ten years of relevant experience in Cybersecurity Operations & Engineering with at least five years’ experience leading cybersecurity teams. - Professional certifications in Information Security, Risk Management and/or Compliance (such as CISM, CISA, CRISC, CISSP etc.) - Proficient in Secure DNS, Secure email gateways, Fortinet firewall/NAC/VPN, threat and vulnerability management, endpoint security, digital certification management, Microsoft CAS/Authenticator - Expert knowledge with general security best practices, protocols, etc.

Interested in this position?

Apply directly on the hospital's official career page.

Apply Now