Regional Information Security Officer
Listed on 2026-02-16
-
IT/Tech
Information Security, Cybersecurity
Overview
UnityPoint Health is looking for a Regional Information Security Officer (RISO) to oversee the information security program in collaboration with the Chief Information Security Officer (CISO). The RISO will promote enterprise security initiatives, assess and manage risks, and serve as the escalation point for security issues within the region or affiliate. This role involves liaising between business units and System Services to ensure compliance with the UPH Information Security Program.
Regular risk assessments and managing mitigation plans are key responsibilities.
Location: Primarily remote with monthly requirements for physical security walk-throughs. Applicants must reside within the UPH footprint of Iowa, Illinois, or Wisconsin.
Hours: Monday-Friday, standard business hours
Why UnityPoint HealthAt UnityPoint Health, you matter. We’re proud to be recognized as a Top 150 Place to Work in Healthcare by Becker's Healthcare several years in a row for our commitment to our team members. Our competitive Total Rewards program offers benefits options that align with your needs and priorities, no matter what life stage you’re in. Here are just a few:
- Paid time off, parental leave, 401K matching, and an employee recognition program.
- Dental and health insurance, paid holidays, short and long-term disability, and more. We also offer pet insurance for your four-legged family members.
- Early access to earned wages with Daily Pay, tuition reimbursement, and adoption assistance.
With a collective goal to champion a culture of belonging where everyone feels valued and respected, we honor the ways people are unique and embrace what brings us together. We believe equipping you with support and development opportunities is a vital part of delivering an exceptional employment experience. Find a fulfilling career and make a difference with UnityPoint Health.
ResponsibilitiesAdvancement of Information Security Program in Region, Affiliate, or Service Line
- Support projects to create, implement, manage, and enforce information security directives as mandated by federal, state, and local agencies and to appropriately mitigate information risks.
- Support the development and ongoing management of the information security program for UPH, including policies, procedures, guidelines, awareness and training plans, overall security infrastructure, and monitoring.
- Ensure ongoing integration of information security with business strategies and requirements within the region, affiliate, or service line.
- Ensure access control, disaster recovery, business continuity, incident response, risk management, and other information security best practices are properly addressed in the region, affiliate, or service line.
- Support information security awareness and training initiatives to educate the workforce about information risks and how to mitigate them.
- Participate in ongoing information risk assessments and audits to ensure that information systems are adequately protected and meet all regulations.
- Work with vendors, outside consultants, and other third parties to improve information security within the organization.
- Monitor the effectiveness of the information security program throughout region, affiliate, or service line and provide regular reports to the local Compliance Committee and the CISO.
- Work closely with the Regional Privacy Officers for ongoing application of technology functionality to protect PHI.
- Stay up-to-date with current and emerging information security threats, reported incidents, and new or updated data protection laws and regulations.
- Fulfills the ISO role for the assigned region, affiliate, or service line.
- Advises, communicates, and responds to individuals regarding information security questions and concerns.
- Supports the UPH strategic direction and balances it with the specific business and information systems needs of the customers.
- Performs daily monitoring, investigation, and mitigation of security violations.
- Understands system security requirements by function and communicates with all levels of management and end users concerning policies, procedures, standards, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).