Logo
Point32Health

Director, Cyber & Information Security - Identity & Threat Management

Point32Health, Canton, MA


Who We ArePoint32Health is a leading health and wellbeing organization, delivering an ever-better personalized health care experience to everyone in our communities. At Point32Health, we are building on the quality, nonprofit heritage of our founding organizations, Tufts Health Plan and Harvard Pilgrim Health Care, where we leverage our experience and expertise to help people find their version of healthier living through a broad range of health plans and tools that make navigating health and wellbeing easier.We enjoy the important work we do every day in service to our members, partners, colleagues and communities. To learn more about who we are at Point32Health, click here.Job SummaryThe Director, Cyber & Information Security - Identity & Threat Management, will report into the Chief Information Security Officer (CISO) for Point32Health. The Director leads Cyber & Information Security managers and/or security leaders to oversee and help to ensure that core programs are effectively implemented. This role is integral in driving the organization’s Cyber & Information Security strategy and objectives. The Director, Cyber & Information Security is considered a leader within the IT Department and is expected to work collaboratively to identify, influence, and enhance areas of improvement across the organization.Key Responsibilities/Duties – what you will be doingManage a team of managers/senior leaders responsible for overseeing the core pillars of Cyber & Information SecurityDevelop and implement policies, standards, and guidelines that continuously increase the organization’s Cyber & Information Security program maturity Communicate potential security concerns/exposures with recommended improvements Lead communication and collaboration efforts with the business and IT to ensure quality solutions are delivered Evangelize the objective to embed security behaviors and principles into the Point32Health culture through active engagement, education, awareness, and partnership Develop operational excellence in anticipation and response to evolving threats and opportunities to improve cyber and information security Identify business risk and communicate risk to appropriate leadership Collaborate with stakeholders to define and implement technical and non-technical controls designed to cyber risk objectives and legal / regulatory obligations. Maintain the risk repository to continually identity, prioritize, and mitigate cyber and information security related risk issues Participate in various forums and groups across Point32Health to understand the risk environment and to provide recommends that effectively incorporate security objectives while balancing the business impact of recommendations providedFacilitate adoption of leading security practices to remain in compliance with regulations and to support our continuous monitoring and improvement goalsMaintain up-to-date knowledge of the cyber and information security industry, including awareness of new or revised security capabilities, improved security processes, threat scenarios, trends, etc.Identify/recommend tools, processes, software, and protocols to advance or replace current security practices, services, or technologies to meet strategic objectives.Other duties and projects as assigned.Qualifications – what you need to perform the jobEDUCATION, CERTIFICATION AND LICENSURE: Bachelor’s degree in Cyber Security, Computer Science, Risk Management, or related field preferred or equivalent experienceEXPERIENCE (minimum years required):10+ years combined IT, cyber/information security, risk, audit, compliance, with increasing responsibility5+ years in cybersecurity or field(s) related to the programs for which the role is responsible for5+ years in a leadership role, preferably with at least 2 of those years overseeing other managersExperience in leading or sponsoring implementation of technical security solutions within large organizationsExperience developing and implementing process-based security controls, processes, and capabilitiesExperience in engaging with and managing vendors responsible for implementing processes and/or IT solutionsExperience creating and maintaining security requirements, guidelines, and procedure documentsExtensive knowledge and experience in security and compliance frameworks such as NIST, ISO, etcSKILL REQUIREMENTS: Ability to lead a team, including managers, through mentoring, coaching, and motivating - providing an opportunity to learn and grow at Point32Health Requires the ability to identify risk within complex, interrelated programs; ability to assess dynamic situations objectively; and to make recommendations or decisions that best align with the corporate strategic objectivesAbility to communicate effectively across multiple levels of the organization including managing through cross-business area or business unit prioritization discussionsStrong relationship building skills; Must be able to work collaboratively and cooperatively as a team member, fostering an atmosphere of trust and respectAbility to influence all levels of staff and senior management in the decision-making processDeep understanding of IT infrastructure, program portfolio management, application design, and secure software development lifecycle (SDLC) methodologiesWORKING CONDITIONS AND ADDITIONAL REQUIREMENTS (include special requirements, e.g., lifting, travel):Must be able to work under normal office conditions and work from home as required.Work may require simultaneous use of a telephone/headset and PC/keyboard and sitting for extended durations. May be required to work additional hours beyond standard work schedule.DISCLAIMERThe above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Management retains the discretion to add to or change the duties of the position at any time.Compensation & Total Rewards OverviewAs part of our comprehensive total rewards program, colleagues are also eligible for variable pay. Eligibility for any bonus, commission, benefits, or any other form of compensation and benefits remains in the Company's sole discretion and may be modified at the Company’s sole discretion, consistent with the law.Point32Health offers their Colleagues a competitive and comprehensive total rewards package which currently includes:Medical, dental and vision coverageRetirement plansPaid time offEmployer-paid life and disability insurance with additional buy-up coverage optionsTuition programWell-being benefitsFull suite of benefits to support career development, individual & family health, and financial healthFor more details on our total rewards programs, visit Commitment to Diversity, Equity, Inclusion, Accessibility (DEIA) and Health Equity​Point32Health is committed to making diversity, equity, inclusion, accessibility and health equity part of everything we do—from product design to the workforce driving that innovation. Our Diversity, Equity, Inclusion, Accessibility (DEIA) and Health Equity team's strategy is deeply connected to our core values and will evolve as the changing nature of work shifts. Programming, events, and an inclusion infrastructure play a role in how we spread cultural awareness, train people leaders on engaging with their teams and provide parameters on how to recruit and retain talented and dynamic talent.  We welcome all applicants and qualified individuals, who will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.Scam Alert: Point32Health has recently become aware of job posting scams where unauthorized individuals posing as Point32Health recruiters have placed job advertisements and reached out to potential candidates. These advertisements or individuals may ask the applicant to make a payment. Point32Health would never ask an applicant to make a payment related to a job application or job offer, or to pay for workplace equipment. If you have any concerns about the legitimacy of a job posting or recruiting contact, you may contact TA_operations@point32health.orgSummaryLocation: Canton, MAType: Full time