via Oraclecloud
$150K - 250K a year
Lead enterprise cybersecurity program including governance, risk, compliance, and incident response in healthcare.
Bachelor's degree plus 7+ years progressive experience including 5 years in security leadership in healthcare, with preferred certifications.
The Chief Information Security Officer (CISO) is responsible for the strategic leadership, governance, and execution of Baptist Health Care's enterprise cybersecurity program. The CISO establishes and maintains a comprehensive information security program designed to protect the confidentiality, integrity, and availability of organizational information assets, technology systems, connected medical devices, and digital services while enabling clinical, operational, and business objectives. The CISO leads cybersecurity strategy, cyber risk management, regulatory compliance, security operations, incident response, business resilience, third-party risk, and security awareness initiatives across the enterprise. The position works under the direction of the Vice President and Chief Information Officer with support from the General Counsel and Chief Compliance Officer. RESPONSIBILITIES Essential Functions • Builds a strategic and comprehensive information security program that defines, develops, maintains and implements policies and processes that enable consistent, effective information security practices which minimize risk and ensure the integrity, confidentiality and availability of information that is owned, controlled and processed within the organization. Ensures information security policies, standards, and procedures are up to date. • Evaluates security trends, evolving threats, risks and vulnerabilities and applies tools to mitigate risk as necessary. Familiar with sourcing information from DHHS, AHCA, NIST, PCI, ISO, Joint Commission and other regulatory and standards bodies. • Leads the organization's cybersecurity incident preparedness and response program, including cyber crisis management, ransomware readiness, incident response planning, tabletop exercises, recovery validation, and post-incident lessons learned activities. • Collaborates with organization senior management, Privacy Officer, and Corporate Compliance officer to establish governance for the security program. • Is responsible for initial and periodic information security risk assessment/analysis, mitigation and remediation. Responsible for development and implementation of security risk management plan. Ensure organization has audit controls to monitor activity on electronic systems that contain or use electronic protected health information. • Ensure the organization has and maintains appropriate system use and disclosure / confidentiality statement. • Participates in the development, implementation, and ongoing compliance monitoring of all BA's and business associate agreements, to ensure -security concerns, requirements, and responsibilities are addressed. • Assists Privacy Officer as needed with breach determination and notification processes under HIPAA and applicable State breach rules and requirements. • Maintains current knowledge of applicable federal and state security laws, licensing and certification requirements and accreditation standards. • Serves as information security consultant to all departments for all data security related issues with understanding of advancing technologies including Encryption, Clinical Device Convergence, Bring-Your-Own-Device (BYOD), premise and with cloud-based computing. • Attains all agreed to goals and objectives within specified time frames, as part of the organization’s overall mission. • Oversees third-party security assessments and vendor risk management programs. Establishes cybersecurity requirements for vendors, business associates, cloud providers, and strategic partners. Evaluates independent security attestations including HITRUST, SOC 2 Type II, ISO 27001, and NIST alignment. • Present cybersecurity risk reports to executive leadership and board committees • Establish security metrics and maturity benchmarks • Effectively communicates departmental, organization, and industry information to staff. • Develops cybersecurity standards for connected medical devices and clinical technologies. Partners with Clinical Engineering, Biomedical Services, and clinical leadership to manage cybersecurity risks associated with medical equipment. QUALIFICATIONS Minimum Education * Bachelor's Degree in Information Security, Computer Science, Information Technology, Healthcare Informatics, or related field required. Master's Degree preferred. Minimum Work Experience * Minimum 7 years of progressive information security, cybersecurity, risk management, or technology leadership experience, including at least 5 years in an information security leadership role within a complex healthcare environment. Licenses and Certifications * Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Healthcare Privacy and Security (CHPS), Healthcare Information Security and Privacy Practitioner (HCISPP), and/or Certified in Risk and Information Systems Control (CRISC) are preferred. Required Skills, Knowledge and Abilities * Knowledge and experience in state and federal information security laws, including but not limited to HIPAA, including NIST, PCI and all other applicable regulation. * Demonstrated organization, facilitation, written and oral communication, and presentation skills. * Self-starter who is results oriented, with a willingness and desire to work with and through others to accomplish departmental and organizations objectives. * A team player who is able to work well with all levels of the organization. * Politically savvy with a high tolerance for ambiguity and can work successfully in a matrix management model. * Proven organizational, leadership and consensus-building skills related to developing a shared vision among diverse stakeholders, systems-thinking, innovation, and the guiding and implementation of successful strategies and enterprises within a complex system in a competitive marketplace. Baptist Health Care is a not-for-profit health care system committed to improving the quality of life for people and communities in northwest Florida and south Alabama. The organization includes three hospitals, four medical parks, Andrews Institute for Orthopaedic & Sports Medicine, and an extensive primary and specialty care provider network. With more than 4,000 team members, Baptist Health Care is one of the largest non-governmental employers in northwest Florida. Baptist Health Care, Inc. is an Equal Opportunity Employer. BHC maintains and enforces a policy that prohibits discrimination against any workforce members or applicants for employment because of sex, race, age, color, disability, marital status, national origin, religion, genetic information, or other category protected by federal, state or local law. Certain positions may require a Level 2 Background check through AHCA. Additional information about this requirement can be found here: Florida Care Provider Background Screening Clearinghouse [https://info.flclearinghouse.com/]
This job posting was last updated on 9/21/2026