Dir, Security Operations
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Reporting to the VP, IT & Chief Information Security Officer (CISO), the Director, Information Security (Operations) is responsible for the strategy, execution, and continuous improvement of cybersecurity operations across the PDS Health enterprise – spanning networks, endpoints, cloud and SaaS environments, applications, AI systems, all web and digital assets, and people. This leader directs the capabilities that prevent, detect, investigate, contain, and recover from cyber threats across a large, distributed healthcare ecosystem that includes supported dental and medical practices, national support centers, clinical and business applications, connected devices, and third-party partners.
This is a critical, future-focused leadership role. Beyond defending the organization against existing threats and vulnerabilities, the Director must anticipate and prepare PDS Health for the next generation of risk including threats introduced by artificial intelligence, automation, expanding cloud adoption, citizen development and low-code platforms, and a rapidly growing digital footprint. The incumbent will build a resilient, intelligence-led security operations function that evolves ahead of the threat landscape while enabling innovation, growth, and the continuity of patient care.
Healthcare experience is essential. The Director will lead risk assessments and control validation against HIPAA/HITECH, ISO/IEC 27001, NIST CSF, and PCI DSS; ensure the protection of electronic protected health information (ePHI) and sensitive personal information; and work hands-on with Legal, Compliance, Privacy, and Risk Management stakeholders to protect the confidentiality, integrity, and availability of critical PDS Health information and information assets in a commercially sensible, risk-based manner.
- Develop, implement, enforce, and monitor a comprehensive, intelligence-led security program covering networks, endpoints, cloud and SaaS services, applications, AI systems, web and digital assets, and the human layer.
- Maintain effective 24x7 security monitoring, triage, escalation, and response coverage through the right combination of internal teams, automation, and managed security services; establish service-level objectives, playbooks, quality controls, and clear handoffs across security and IT operations.
- Direct enterprise incident response and cyber crisis management for ransomware, identity compromise, data exposure, business email compromise, cloud and supply-chain events, and threats affecting clinical operations; lead tabletop and technical simulation exercises with executive, legal, privacy, clinical, and business continuity stakeholders; ensure root‑cause analysis results in assigned and verified corrective actions.
- Advance risk‑based detection engineering, threat intelligence, and proactive threat hunting mapped to adversary behaviors, critical business services, identity pathways, and known control gaps.
- Lead a risk-based vulnerability, exposure, and attack‑surface management program that prioritizes exploitability, asset criticality, and clinical impact – not severity scores alone, with transparent ownership, remediation targets, and governance across infrastructure, applications, cloud, endpoints, medical and dental technology, and third parties.
- Establish and operate the security program for AI systems: ensure every AI system has named, accountable ownership; require documented risk and impact assessments before deployment; enforce human oversight for high‑impact decisions; and implement post‑deployment monitoring for drift, misuse, and abuse. Defend the organization against AI‑enabled threats, including AI‑driven phishing and social engineering, deepfakes, data poisoning, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).