Chief Information Security Officer
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, IT Consultant
Council Capital is a healthcare-focused private equity firm based in Nashville, Tennessee, managing over $350 million in committed capital. We invest in lower middle market healthcare companies where we see the potential to scale purpose and performance. Our investments span control and minority positions in businesses with enterprise values between $10 million and $100 million. What sets us apart is the Council Model
—a proven framework that surrounds founders and leadership teams with a powerful combination of support: our CEO Council of seasoned operators, our Strategic Healthcare Investors who bring real-world insight and access, and our internal Value Creation Team
, focused on enabling growth through talent, systems, and strategy. At Council Capital, we’re not just backing companies—we’re helping build enduring businesses that improve lives and shape the future of healthcare.
A fast-growing, healthcare analytics technology company is seeking a hands‑on Chief Information Security Officer (CISO) to own and scale its information security program in a regulated healthcare environment.
This role is a player‑coach position
, not a policy‑only or advisory role. The CISO will be directly accountable for protecting sensitive healthcare data, enabling enterprise and government customer growth, and ensuring security is never a blocker to revenue or product velocity.
The ideal candidate combines strong judgment, pragmatic execution, modern technical fluency, and executive‑level communication
.
Security & Risk
- Zero security breaches impacting the company or its customers
- Successful completion of SOC and high‑trust audits on time with no reportable findings or corrective action plans
- Delivery and maintenance of:
- Security risk assessments (internal and external)
- System security plans
- Business continuity and disaster recovery plans
- Fully operational vulnerability management, patching, remediation, and incident response programs
- Effective oversight and closure of POA&M items and vulnerability scan findings
Sales Enablement & Customer Trust
- Security is never the reason a deal is lost
- Strong performance on customer security reviews and RFPs
- Trusted executive presence in customer and auditor conversations
Speed, Scale & Operations
- New environments stood up within defined SLAs (measured in days, not weeks)
- Security reviews for releases and deployments completed rapidly without slowing delivery
- Access provisioning and approvals completed within one business day
- Security operating costs aligned with industry benchmarks
Technology & Modern Practices
- Secure support of modern technology stacks, including:
- Public cloud environments (AWS and/or Azure)
- Infrastructure as Code
- Containers and orchestration
- Modern data platforms and emerging AI use cases
- Practical approach to endpoint security that balances usability and protection
- Openness to technology choices beyond a single vendor ecosystem when value‑justified
Leadership & Communication
- Regular executive‑level security updates on risk posture, trends, and forward roadmap
- Clear, credible communication with executives, boards, customers, and partners
- High professionalism and reliability in internal and external engagements
- Own the company’s end‑to‑end information security strategy and execution
- Serve as the accountable executive for healthcare security and compliance obligations
- Design and maintain secure cloud, data, and application architectures
- Lead vulnerability management, incident response, and remediation efforts
- Establish and track measurable security KPIs and dashboards
- Partner with Sales on customer security reviews, audits, and due diligence
- Balance security rigor with speed, usability, and business outcomes
- Advise executive leadership on security risk and readiness
- Build and lead a lean, high‑impact security function (internal and external resources)
- Significant experience securing healthcare or other regulated data environments
- Senior security leadership experience (CISO, VP Security, or equivalent)
- Experience operating in early‑stage or scaling technology companies
- Hands‑on,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).