×
Register Here to Apply for Jobs or Post Jobs. X

Chief Information Security Officer

Job in Columbus, Franklin County, Ohio, 43224, USA
Listing for: Wexner Medical Center
Full Time position
Listed on 2026-07-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Consultant, Data Security
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below
Position: Wexner Medical Center Chief Information Security Officer

Current Employees and Students: Please log in to Workday to use the internal job search and application process. Scope of Position

Reporting to the CIDO of the Ohio State University Wexner Medical Center with a dual report to the CISO of The Ohio State University, the WMC Chief Information Security Officer (WMC CISO) leads a department focused on security, risk management, compliance and security architecture for the clinical mission of Ohio State. Working closely with our university partners, the WMC CISO will engage and collaborate with various leaders in clinical operations, research, education, audit, legal and compliance and information systems on security initiatives.

The WMC CISO oversees ongoing activities, programs, and projects that serve to protect WMC data confidentiality, integrity and availability while providing clinicians, students, patients, faculty, researchers, staff and vendors with secure and reliable access to systems and information. The WMC CISO ensures strategic alignment to the university on information security standards, controls, training, practices, and reporting.

Duties and Responsibilities Strategy, Governance, and Risk Management (50%)
  • Health System Security Strategy: Develop, champion, and execute a visionary, comprehensive, multi-year information security strategy and roadmap across all mission areas of WMC, leveraging the University Security Framework.
  • Security Framework: Work in collaboration with University CISO to align on common standards, controls and practices, ensuring a cohesive security posture where systems, services and missions overlap. Oversee the development, enforcement and auditing of security policies, procedures, and standards for the health system.
  • Enterprise Ownership and Tolerance: Oversee Security Risk Assessments (SRAs) and vulnerability management across clinical, research, administrative, and third-party environments for the Health System. Develop and prioritize risk mitigation and remediation strategies. Coordinate with the University CISO on a streamlined risk assessment process for technologies that impact both the Medical Center and the University. Report on the WMC’s cybersecurity risk appetite in partnership with executive leadership and proactively manage and report on the overall cyber risk posture, translating technical exposure into clear business impact to the C-suite and the board through established reporting under the university CISO.
  • Regulatory Compliance: Ensure stringent adherence to all applicable laws and regulations, including but not limited to HIPAA/HITECH, 21 CFR Part 11, PCI DSS, state data privacy laws, and security mandates for research data and grant funding (e.g., CUI). Serves as the Security Officer to oversee implementation of HIPAA security regulations and to provide ongoing compliance monitoring and education on security.
  • Emerging Technology Governance: Establish and lead emerging technology governance frameworks for AI, cloud, automation, and other next-generation technologies, ensuring alignment with risk management, cybersecurity strategy, regulatory requirements, and business objectives.
  • Third-Party Risk Management (TPRM): Provide executive oversight of the Third-Party Risk Management program, ensuring vendor risks are assessed, governed, and aligned with enterprise security and compliance requirements. Oversee assessing and mitigating the security risks posed by vendors, business associates, and supply chain partners in alignment with university standards and frameworks where possible.
  • Business Continuity / Disaster Recovery: Provide executive oversight and strategic direction for enterprise Business Continuity and Disaster Recovery programs, ensuring governance, resilience, regulatory compliance, and alignment with organizational risk management objectives to maintain and restore mission-critical operations during disruptions.
Security Operations and Leadership (30%)
  • Security Operations Center (SOC) Oversight: Oversee the day-to-day operations of the information security function, including threat intelligence, security monitoring, Security Information and Event Management (SIEM), and vulnerability…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary