AVP Solutions Architecture
Listed on 2026-10-05
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
At Scion Health
, we empower our caregivers to do what they do best. We value every voice by caring deeply for every patient and each other. We show courage by running toward the challenge and we lean into new ideas by embracing curiosity and question asking. Together, we create our culture by living our values in our day-to-day interactions with our patients and teammates.
The AVP, Information Security leads the enterprise information security program and the day-to-day protection of the organization's clinical and corporate technology environments. The AVP directs security operations, threat detection, incident response, vulnerability management, identity and access management, HIPAA security compliance, and data governance. This role advises executive leadership during security events, partners with technology and clinical leaders to incorporate security requirements into operations and builds a high-performing security team that protects systems, sensitive data, and protected health information.
EssentialFunctions
- Directs enterprise security operations, including threat monitoring, detection, investigation, containment, recovery, and post-incident review across clinical and corporate environments.
- Develops and matures Security Operations Center capabilities, monitoring coverage, operating procedures, escalation paths, and supporting security technologies.
- Owns the incident response program, including playbooks, tabletop exercises, digital forensics coordination, lessons learned, and timely communication with executive and board leadership.
- Leads the enterprise vulnerability management program, including scanning, risk-based prioritization, remediation tracking, exception management, and reporting across enterprise and clinical systems.
- Maintains a healthcare-focused threat intelligence capability and coordinates preventive and responsive action for ransomware, phishing, business email compromise, and other sector-relevant threats.
- Establishes enterprise identity and access management strategy and controls for authentication, single sign-on, multifactor authentication, conditional access, privileged access, and access governance.
- Leads the HIPAA security compliance program, including security risk assessments, control documentation, policy maintenance, corrective action tracking, audit readiness, and regulatory support.
- Establishes data governance practices for the classification, protection, retention, and lifecycle management of sensitive data and protected health information in partnership with Compliance and clinical stakeholders.
- Partners with infrastructure, network, application, and clinical technology teams to incorporate security requirements into architecture, design, implementation, and ongoing operations.
- Selects and oversees security technologies and service providers; manages vendor performance, contracts, service levels, and managed or co-sourced security operations relationships.
- Builds and leads a multidisciplinary team of security professionals; establishes clear accountabilities, staffing models, on-call coverage, development plans, and performance expectations.
- Defines and reports security metrics, key performance indicators, risk trends, and program priorities to the Chief Technology Officer / Chief Information Security Officer and executive leadership.
- Directs security due diligence, risk assessment, and operational integration for acquisitions and newly affiliated facilities.
- Develops and manages department priorities, budgets, resource plans, and roadmaps aligned with organizational risk and business needs.
- Maintains current knowledge of cybersecurity threats, regulatory requirements, and industry practices and applies that knowledge to the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).