Director Information Security & Governance

Posted 2 Days Ago
Be an Early Applicant
Downers Grove, IL, USA
In-Office
136K-180K Annually
Expert/Leader
Healthtech
The Role
Leads the enterprise cybersecurity strategy, security architecture, security operations, incident response, vulnerability management, and governance, risk, and compliance program. Manages a team of five, oversees HIPAA/HITECH and other regulatory requirements, leads risk assessments and audits, establishes security policies, strengthens identity and access controls, guides security technology investments, and communicates security posture and risk to executives and the Board.
Summary Generated by Built In

At Duly Health and Care, you are supported to do your best work and make a meaningful impact every day. You will be part of a collaborative, physician-led team that works as one and puts patients at the center of everything we do.
With a connected network of providers, care teams, and services across primary and specialty care, surgery centers, imaging, lab, and therapy, you are part of a system designed to deliver high-quality, coordinated care. Together, we create an environment where you can grow, contribute, and help improve the experience and outcomes for every patient we serve.
Benefits:
• Comprehensive medical, dental, and vision benefits that include healthcare navigation assistance.
• Access to a mental health benefit at no cost.
• Employer provided life and disability insurance.
• $5,250 Tuition Reimbursement per year.
• Immediate 401(k) match.
• 40 hours paid volunteer time off.
• A culture committed to community engagement and social impact.
• Up to 12 weeks parental leave at 100% pay and a financial benefit for adoption and surrogacy for non-physician team members once eligibility requirements are met.
 

Title: Director, Information Security & Governance 

Full-Time  |  Hybrid

Position Summary - We are seeking a dynamic and experienced Director of Cybersecurity to lead our enterprise security program and governance, risk, and compliance (GRC) function. Reporting to the CTO, this leader will be responsible for protecting the confidentiality, integrity, and availability of patient data, clinical systems, and enterprise assets across our large healthcare organization. The Director will serve as a strategic partner to clinical, operational, and IT leadership and ensuring patient/employee data and enterprise assets are effectively protected.

Key Responsibilities:

  • Lead, mentor, and develop a team of 5 security architects and specialists, fostering a culture of excellence, accountability, and continuous learning.
  • Define and execute the enterprise cybersecurity strategy in alignment with organizational goals and the CISO's vision.
  • Oversee security architecture design and review for enterprise systems, clinical applications, cloud environments, and third-party integrations.
  • Drive the maturation of security operations including threat detection, incident response, and vulnerability management programs.
  • Serve as a primary escalation point and decision-maker during significant security incidents or breaches.
  • Own and evolve organizations Governance, Risk & Compliance (GRC) program, ensuring alignment with HIPAA, HITECH, NIST CSF, SOC 2, and other applicable frameworks.
  • Lead risk assessment processes including third-party vendor risk assessments, enterprise risk registers, and ongoing risk treatment planning.
  • Oversee preparation for and response to regulatory audits, assessments, and examinations.
  • Develop, maintain, and enforce enterprise security policies, standards, and procedures.
  • Coordinate privacy and security initiatives in partnership with Legal, Compliance, and Privacy Office stakeholders.
  • Partner with clinical informatics, revenue cycle, HR, and other business units to embed security practices into workflows and new initiatives.
  • Present security risk posture, program metrics, and GRC status updates to executive leadership and the Board of Directors as needed.
  • Lead security awareness and training programs across the organization.
  • Evaluate and guide investment in security tooling including SIEM, EDR, CASB, DLP, identity governance, and zero trust capabilities.
  • Ensure robust identity and access management controls across EHR systems, cloud platforms, and enterprise applications.
  • Stay current on emerging threats specific to the healthcare sector (ransomware, medical device vulnerabilities, supply chain risks) and adapt program accordingly.

Qualifications:

Required

  • 10+ years of progressive experience in information security, with at least 3 years in a leadership role managing a team.
  • Demonstrated expertise in GRC — including policy development, risk management, and regulatory compliance.
  • Deep knowledge of healthcare-specific security and privacy regulations, particularly HIPAA/HITECH.
  • Experience in large, complex enterprise environments; healthcare industry experience strongly preferred.
  • Proven ability to build trusted relationships with executive stakeholders and communicate risk in business terms.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent experience).

Preferred:

  • Master's degree in a relevant discipline.
  • Active certifications such as CISSP, CISM, CRISC, HCISPP, or equivalent.
  • Hands-on experience with EHR platforms (Epic, Cerner) and their security architecture.

If you are committed to putting our patients first and helping shape the future of care, you belong at Duly.
The compensation for this role includes a base pay range of $135,861 - $180,000, with the actual pay determined by factors such as skills, experience, education, certifications, geographic location, and internal equity. Additional compensation may be available through shift differentials, bonuses, and other incentives. Base pay is only a portion of the total rewards package.

Artificial Intelligence Disclosure


Artificial Intelligence (AI) tools may be used in some portions of the candidate review process for this position, however, all employment decisions will be made by a person.

Skills Required

  • 10+ years of progressive experience in information security
  • At least 3 years in a leadership role managing a team
  • Expertise in governance, risk, and compliance, including policy development, risk management, and regulatory compliance
  • Deep knowledge of healthcare security and privacy regulations, particularly HIPAA and HITECH
  • Experience in large, complex enterprise environments
  • Ability to build trusted relationships with executive stakeholders and communicate risk in business terms
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field, or equivalent experience
  • Healthcare industry experience
  • Master's degree in a relevant discipline
  • Active certification such as CISSP, CISM, CRISC, HCISPP, or equivalent
  • Hands-on experience with EHR platforms such as Epic or Cerner and their security architecture
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
6,000 Employees
Year Founded: 1999

What We Do

Duly Health and Care is an independent, physician-directed, multispecialty medical group serving patients throughout the Midwest. Its network provides primary and specialty care, including dermatology, orthopedics, surgery, oncology, pediatrics, urology, gastroenterology, ophthalmology, and more. Duly combines traditional and value-based care with connected providers, ambulatory services, imaging, laboratories, telehealth, and a focus on quality, efficiency, access, and patient experience.

Similar Jobs

Mondelēz International Logo Mondelēz International

Manufacturing- Process Engineering Co-Op(For Naperville, IL Local Candidates Only)

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
Naperville, IL, USA
90000 Employees
66K-66K Annually

Mondelēz International Logo Mondelēz International

Sr. Associate Manager - Category Management Drug & Natural Channel

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
4 Locations
90000 Employees
97K-134K Annually

Mondelēz International Logo Mondelēz International

Multi-Media Content Creator

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
Chicago, IL, USA
90000 Employees
97K-134K Annually

Mondelēz International Logo Mondelēz International

Assistant Manager - Category Management Amazon & Away From Home (AFH)

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
6 Locations
90000 Employees
109K-150K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account