IT Security, Director ; Hybrid
Listed on 2026-09-13
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
IT Security, Director I (Hybrid) Chicago, IL
The American Medical Association (AMA) is the nation's largest professional Association of physicians and a non-profit organization. We are a unifying voice and powerful ally for America's physicians, the patients they care for, and the promise of a healthier nation. To be part of the AMA is to be part of our Mission to promote the art and science of medicine and the betterment of public health.
At AMA, our mission to improve the health of the nation starts with our people. We foster an inclusive, people-first culture where every employee is empowered to perform at their best. Together, we advance meaningful change in health care and the communities we serve.
We encourage and support professional development for our employees, and we are dedicated to social responsibility. We invite you to learn more about us and we look forward to getting to know you.
We have an opportunity at our corporate offices in Chicago for an IT Security, Director I (Hybrid) on our Information Technology team. This is a hybrid position reporting into our Chicago, IL office, requiring 3 days a week in the office.
This role is responsible
for providing subject matter expertise on the strategy, research, design,
implementation, and operation of technical and process security controls. Develops strong relationships across the AMA's IT department and with business unit teams; serves as a trusted advisor to assess security risk in technology
selection with appropriate balance that supports business outcomes. Responsibilities
include data security, collaboration with the security operations team, and
maintaining the broad suite of information security infrastructure, and all
associated contracting, policy, and regulatory compliance implications. Maintain cybersecurity and related regulatory expertise to research,
prepare, and maintain strategic roadmaps incorporated into the Information
Security Program. Lead or assist with
security incidents and compliance investigations and produce timely and clear
reporting to both technical and senior business leader audiences. Serves as
primary backup for the Director IT Security.
System/Network/Application Security Strategy
- Research, design,
evaluate, and test the security and regulatory compliance of AMA applications,
systems, and networks to ensure the operational effectiveness of technical controls implemented by the
organization; purpose-built security tools such as data loss prevention,
logging and event management, enterprise encryption systems and also security
controls embedded in enterprise systems and applications such as authentication
and access controls - Responsible for the effective use of AMA cybersecurity systems including enhancements, upgrades, and lifecycle management through
relationships with product and service vendors - Responsible for
the technical integration of security components within the AMA's environment
to optimize the value and control benefits including ease of use, effectiveness, and breadth of coverage
- Assess technical risks in the AMA's environment both pre and post-production through the AMA's Software Development
Lifecycle (SDLC) and Change & Release - Management Boards; propose
information security strategy and program improvements, communicate identified
risks and recommend solutions - Manage the research, appropriate response, and remediation of malicious and inappropriate activity; ensure consistency of the risk
assessment approach across the organization - Prepare policy updates;
research and recommend short and long-term improvements to maintain strong security posture relative to enterprise architecture standards, data integration/data access, cloud
strategy, and AI…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).