Director, Cybersecurity - Cyber Defense Operations

Posted 2 Days Ago
Be an Early Applicant
Sacramento, CA, USA
In-Office
260K-417K Annually
Expert/Leader
Healthtech
The Role
Lead Sutter Healths enterprise cyber defense operations (SOC, IR, Threat Intel, Detection Engineering, automation, adversary simulation). Deliver 24/7 detection, rapid containment, coordinated response, and measurable risk reduction. Own program maturity, roadmaps, metrics, and executive reporting while partnering with Security Engineering, Data Protection, GRC, IT, legal, and business stakeholders to protect clinical and digital assets.
Summary Generated by Built In

We are so glad you are interested in joining Sutter Health!

Organization:

SHSO-Sutter Health System Office-Valley

Position Overview:

The Director of Cyber Defense Operations leads Sutter Health’s enterprise cybersecurity defense capabilities, responsible for protecting critical clinical, operational, and digital assets against evolving cyber threats. This role provides strategic and operational leadership across core defensive functions including Security Operations Center (SOC), Incident Response (IR), Threat Intelligence, Detection Engineering, Security Automation, and Adversary Simulation.
The Director is accountable for delivering 24/7 threat detection, rapid incident containment, and coordinated response across the organization, while continuously improving defensive capabilities through automation, intelligence-driven operations, and measurable risk reduction. This leader drives alignment across cybersecurity, IT, clinical engineering, legal, and business teams to ensure resilience against cyber events that could impact patient care and operations.
This role also owns the maturity and performance of the cyber defense program, establishing roadmaps, operational metrics, and executive reporting that demonstrate control effectiveness, detection coverage, and overall security posture improvement. The Director partners closely with Security Engineering, Data Protection, and GRC leaders to ensure a fully integrated, threat-informed defense strategy aligned to enterprise risk priorities.

Job Description:

EDUCATION:
Equivalent experience will be accepted in lieu of the required degree or diploma.

  • Bachelor's: Business, Cybersecurity, Computer Science, Information Technology/Security, Risk Management, or related field or equivalent education/experience

CERTIFICATION & LICENSURE

  • CISSP-Certified Information Systems Security Professional within 1 Year of hire

TYPICAL EXPERIENCE:

  • 12 years recent relevant experience.

PREFERRED EXPERIENCE:

  • Leadership experience overseeing Cyber Defense Operations functions including SOC, Incident Response, Threat Intelligence, Detection Engineering, and Incident Response in a large enterprise environment.

  • Hands-on experience with SIEM, SOAR, EDR/XDR, threat hunting, automation, and security monitoring technologies.

  • Proven ability to build and inspire high-performing cybersecurity teams through mentorship, Capture the Flag (CTF) events, attack demonstrations, tabletop exercises, and continuous technical development.

  • Strong communication and executive presence with experience delivering cybersecurity metrics, threat intelligence reporting, operational dashboards, and risk updates to technical and business stakeholders.

  • Experience defending healthcare environments and protecting critical systems, PHI, and clinical operations against modern cybersecurity threats including ransomware and advanced adversary activity.

SKILLS AND KNOWLEDGE:

  • Solid expertise in formal/structured information security risk assessment methodology, including understanding the implementation challenges and advantages across all levels of hardware platforms and software applications.

  • In-depth knowledge of information security technologies, infrastructures, methodologies, frameworks, techniques, security incident and event monitoring (SIEM) solutions (e.g., Splunk Enterprise Security, IBM QRadar, HP ArcSight, etc.), compliance reporting, and the development and implementation of these concepts to manage risk within a clinical environment.

  • Extensive knowledge and understanding of current and emerging digital security trends, risks, threats, countermeasures, vulnerabilities, and mitigations ranging across the technologies required for securing applications, data centers, networks, and third-party access to data, applications, and resources.

  • Broad working knowledge of health care operations and their related data/software/hardware requirements including, but not limited to, hospitals, clinics, medical offices, and their information technology needs.

  • Detailed knowledge of state and federal information security, cyber security, compliance and privacy-related regulatory requirements, including a comprehensive understanding of National Institute of Standards and Technology (NIST), Federal Information Processing Standards (FIPS), and other recognized industry security standards and best practices.

  • Comprehensive understanding of information confidentiality and integrity requirements especially as it relates to patient information in a healthcare environment (electronic health/medical records (EHR/EMR), Health Insurance Portability and Accountability Act (HIPAA), Health Information Technology for Economic and Clinical Health Act (HITECH), etc.).

  • Superior business acumen and exceptional leadership skills to provide innovative solutions to complex problems and leveraging appropriate internal/external resources to meet corporate objectives.

  • Expertise in building cross-functional team, fostering consensus, resolving conflicts, and managing risk, in addition to being an effective decision maker and expert delegator.

  • Organizational skills with an understanding of team building and organizational dynamics, including creative problem identification and resolution, conceptualization, and contingency thinking skills.

  • Advanced project management skills, including the ability to manage multidisciplinary teams that successfully define, develop, and deliver various information security solutions.

  • Attention to detail with exceptional analytical skills in problem identification, analysis, and innovative resolution.

  • Verbal and written communication, interpersonal, and presentation skills with the ability to present regulatory requirements, directives, ideas, and concepts effectively to a diverse audience

  • Advanced level of computer and application competency including Excel, Power Point, Word, and Project and relational database management systems.

  • Adapt to changing or challenging initiatives while developing new ideas and approaches aimed at improving results.

  • Foster an environment of collaboration at all levels of the organization, including engaging and influencing individuals or groups with various opinions and levels of knowledge, building consensus, and then enlisting cooperation without direct control/authority.

These Principal Accountabilities, Requirements and Qualifications are not exhaustive, but are merely the most descriptive of the current job. Management reserves the right to revise the job description or require that other tasks be performed when the circumstances of the job change (for example, emergencies, staff changes, workload, or technical development).
 

Job Shift:

Days

Schedule:

Full Time

Days of the Week:

Monday - Friday

Weekend Requirements:

As Needed

Benefits:

Yes

Unions:

No

Position Status:

Exempt

Weekly Hours:

40

Employee Status:

Regular

Sutter Health is an equal opportunity employer EOE/M/F/Disability/Veterans.

Pay Range is $260,312.00 to $416,520.00 / annual salary

The compensation range may vary based on the geographic location where the position is filled. Total compensation considers multiple factors, including, but not limited to a candidate’s experience, education, skills, licensure, certifications, departmental equity, training, and organizational needs. Base pay is only one component of Sutter Health’s comprehensive total rewards program. Eligible positions also include a comprehensive benefits package.

Skills Required

  • Bachelor's degree in Business, Cybersecurity, Computer Science, IT/Security, Risk Management, or related field (or equivalent experience)
  • CISSP certification within 1 year of hire
  • 12 years recent relevant experience
  • Leadership experience overseeing Cyber Defense Operations (SOC, Incident Response, Threat Intelligence, Detection Engineering, Security Automation)
  • Hands-on experience with SIEM, SOAR, EDR/XDR, threat hunting, automation, and security monitoring technologies
  • Experience building and mentoring high-performing cybersecurity teams, CTFs, tabletop exercises, and attack demonstrations
  • Experience defending healthcare environments and protecting PHI and clinical operations against ransomware and advanced adversary activity
  • In-depth knowledge of SIEM solutions (e.g., Splunk Enterprise Security, IBM QRadar, HP ArcSight)
  • Solid expertise in formal information security risk assessment methodologies
  • Detailed knowledge of state and federal cybersecurity/compliance requirements and frameworks (NIST, FIPS)
  • Comprehensive understanding of HIPAA, HITECH, and patient information confidentiality/integrity requirements
  • Advanced project management skills and ability to manage multidisciplinary teams
  • Advanced level of computer/application competency including Excel, PowerPoint, Word, Project, and relational databases
  • Strong communication and executive presence with experience delivering cybersecurity metrics, dashboards, and risk updates to stakeholders

Sutter Health Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sutter Health and has not been reviewed or approved by Sutter Health.

  • Healthcare Strength Healthcare coverage is described as comprehensive, with broad networks and strong wellness support. Family coverage is characterized as low-cost or nearly free in some plan options, reinforcing perceived value.
  • Retirement Support Retirement offerings include employer matching and, in some cases, a pension after a tenure threshold. Supplemental protections like life and disability insurance add to the overall financial security package.
  • Leave & Time Off Breadth Paid time off is framed as generous, with examples of sizable PTO allotments early in tenure. Additional supports such as flexible scheduling and leave programs contribute to a sense of time-off breadth.

Sutter Health Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sacramento, CA
68,000 Employees
Year Founded: 1921

What We Do

Sutter Health is one of the nation's leading not-for-profit healthcare networks, which includes award-winning physician organizations, acute care hospitals, surgery centers, medical research facilities and specialty services. Our team of 68,000 doctors, employees and volunteers proudly cares for Northern California. Our facilities and care centers are located in large, urban cities and small, rural communities, from the Pacific Coast to the San Joaquin Valley. You’ll find us in San Francisco, Oakland, Sacramento, the snowy mountains of the Sierra Nevada and Lake Tahoe, Napa Valley, Yosemite and the coastal redwoods. We even have an affiliate in Hawaii. Join us and be part of a dedicated group of professionals committed to putting patients’ needs first and achieving the highest levels of quality, access and affordability.

Similar Jobs

Navan Logo Navan

Senior Product Manager

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
2 Locations
3300 Employees
115K-255K Annually

Parsec Automation Logo Parsec Automation

Customer Success Manager

Artificial Intelligence • Information Technology • Internet of Things • Software • Analytics • Automation • Manufacturing
Easy Apply
In-Office
Anaheim, CA, USA
99 Employees
250K-250K Annually

Braze Logo Braze

Solutions Engineer

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
San Francisco, CA, USA
2000 Employees
86K-142K Annually
Hybrid
San Francisco, CA, USA
897 Employees
210K-240K Annually

Similar Companies Hiring

Camber Thumbnail
Fintech • Healthtech • Social Impact
New York, New York
90 Employees
Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account