Full-Time

Chief Information Security Officer

Deadline 9/8/26
Ohio State University

Ohio State University

Public research university in Columbus, OH

No salary listed

Company Does Not Provide H1B Sponsorship

Columbus, OH, USA

In Person

Bachelor's, Master's, PhD

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
HIPAA

Get referred to Ohio State University

See people who can refer or advise you

Requirements
  • Minimum of 12 years of experience in information security, with at least five years in a significant leadership role.
  • Baccalaureate degree or higher in information systems or a related degree.
  • Proven track record of developing and implementing a successful, enterprise-level information security program.
  • Strong business acumen to enable technology’s impact to support secure business objectives.
  • Demonstrated ability to build relationships, collaborate, and lead through influence across a decentralized enterprise.
  • Excellent communication, negotiation, and interpersonal skills with the ability to articulate complex security concepts to technical and non-technical audiences.
  • Strong knowledge of relevant legal and regulatory requirements, including HIPAA.
  • Deep expertise in information security principles, practices, and technologies.
  • Proven ability to manage security implications of rapid innovation in clinical care, biomedical research, and education, including cloud computing, telehealth, and artificial intelligence and machine learning.
Responsibilities
  • Develop, champion, and execute a comprehensive, multi-year information security strategy and roadmap across all mission areas of the Wexner Medical Center.
  • Collaborate with the University Chief Information Security Officer to align common standards, controls, and practices, and oversee the development, enforcement, and auditing of health-system security policies, procedures, and standards.
  • Oversee security risk assessments and vulnerability management across clinical, research, administrative, and third-party environments, and develop and prioritize risk mitigation and remediation strategies.
  • Report on the health system’s cybersecurity risk appetite and overall cyber risk posture to executive leadership and the board.
  • Ensure adherence to applicable laws and regulations, including HIPAA/HITECH, 21 CFR Part 11, PCI DSS, state data privacy laws, and security mandates for research data and grant funding.
  • Serve as the Security Officer overseeing implementation of HIPAA security regulations, compliance monitoring, and security education.
  • Establish and lead emerging-technology governance frameworks for artificial intelligence, cloud, automation, and other next-generation technologies.
  • Provide executive oversight of the Third-Party Risk Management program and vendor, business associate, and supply-chain security risks.
  • Provide executive oversight and strategic direction for enterprise business continuity and disaster recovery programs.
  • Oversee day-to-day information security operations, including threat intelligence, security monitoring, Security Information and Event Management, and vulnerability management across on-premises, cloud, and hybrid environments.
  • Own the Computer Security Incident Response and Reporting function, leading coordination, containment, investigation, recovery, and regulatory breach notification efforts for security incidents and breaches.
  • Provide authoritative security consultation for the design and implementation of new systems, including electronic health record systems, clinical Internet of Things, and cloud services, and review existing systems using security-by-design principles.
  • Oversee Information Technology Access Management, including alignment with Identity and Access Management and Privileged Access Management strategies consistent with a Zero Trust model.
  • Collaborate with the University Chief Information Security Officer, Chief Information and Digital Officer, and other executive and departmental leaders to align security initiatives with institutional and clinical goals.
  • Lead, manage, mentor, and coach a diverse information security team, fostering continuous learning, accountability, and excellence.
  • Advise senior leadership on security risks and strategy and drive a mandatory, ongoing security education and awareness program for faculty, staff, researchers, and students.
  • Serve as an internal and external champion for information security and engage stakeholders across technical, research, clinical, and other communities.
Desired Qualifications
  • Professional security management certification, such as Certified Information Systems Security Professional, Certified Information Security Manager, or an equivalent, is highly desirable.
  • Demonstrated experience in a large, complex organization, preferably within an academic medical center or healthcare system.
Ohio State University

Ohio State University

View

The Ohio State University is a comprehensive public research university that combines undergraduate, graduate, and professional education with research and public service.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Get referred to Ohio State University

See people who can refer or advise you