- Lead the design, deployment, and maintenance of secure implementation of technologies— including firewalls connections for clients, EDR, CASB, DLP, IAM, and cloud-native security solutions.
- Architect and implement a defense-in-depth security architecture covering network, cloud, and endpoint layers.
- Define and enforce secure configuration baselines aligned with CIS Benchmarks, NIST 800-53, and Zero Trust principles.
- Document client architecture and secure connectivity along with applications aligned with organizational practices
- Collaborate with operations and architecture teams to ensure security is embedded across infrastructure and cloud.
- Lead regional data security program that safeguards sensitive, regulated, and proprietary data across its entire lifecycle — creation, storage, use, sharing, and deletion.
- Implement and manage Data Loss Prevention (DLP) solutions across endpoints, networks, and cloud platforms to prevent unauthorized data exposure.
- Oversee deployment of encryption solutions for data at rest, in motion, and in use, ensuring cryptographic controls meet enterprise and regulatory requirements.
- Ensure hardening of devices, IT & security technologies as per CIS and industry best practices.
- Develop and maintain a data classification and handling framework integrated into business processes and applications.
- Partner with Privacy and Legal teams to ensure compliance with HIPAA, GDPR, and other privacy regulations through Security and privacy-by-design principles.
- Ensure secure data transfer, storage, and deletion practices are followed during client and vendor engagements and system decommissioning.
- Lead and manage a portfolio of security and data protection projects, ensuring timely delivery and measurable outcomes.
- Partner with PMO, IT, and business leaders to integrate security requirements into enterprise projects from the outset.
- Collaborate with GRC, Privacy, Legal, and Compliance to ensure data and system security controls meet audit and certification standards (ISO 27001, HIPAA, HITRUST, SOC 2, PCI DSS).
- Support security audits, risk assessments, and remediation closure across business units and vendors.
- Contribute to the Security Governance Council by reporting key data and system risk indicators.
- Partner with Security Operations and Incident Response teams to enhance detection and response related to data breaches or exfiltration attempts
- Bachelor’s or Master’s degree in Technology, Cybersecurity, Health Information Technology, Risk Management, or a related discipline.
- 10–12 years of progressive experience in security engineering, data protection, and infrastructure security, with at least 5 years in leadership roles.
- Proven experience managing large-scale cybersecurity and data protection programs in regulated industries (healthcare, BFSI, SaaS, or manufacturing).
- Hands-on expertise in DLP, encryption, key management, tokenization, data masking, and cloud security.
- Experience integrating data protection controls into cloud platforms (AWS, Azure) and SaaS environments (O365, Salesforce, Workday, etc.).
- Strong knowledge of compliance standards (HIPAA, HITRUST, NIST 800-171, PCI DSS, ISO 27001).
- Project Management Professional (PMP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
Working in an evolving healthcare setting, we use our shared expertise to deliver innovative solutions. Our fast-growing team has opportunities to learn and grow through rewarding interactions, collaboration and the freedom to explore professional interests.
Our associates are given valuable opportunities to contribute, to innovate and create meaningful work that makes an impact in the communities we serve around the world. We also offer a culture of excellence that drives customer success and improves patient care. We believe in giving back to the community and offer a competitive benefits package. To learn more, visit: r1rcm.com
Visit us on Facebook
Top Skills
What We Do
R1 is a leading provider of technology-driven solutions that transform the patient experience and financial performance of healthcare providers
R1’s proven and scalable operating models seamlessly complement a healthcare organization’s infrastructure, quickly driving sustainable improvements to net patient revenue and cash flows while reducing operating costs and enhancing the patient experience.







