Vice President, Chief Information Security Officer

Sorry, this job was removed at 02:04 p.m. (CST) on Tuesday, Feb 17, 2026
Be an Early Applicant
2 Locations
In-Office
Healthtech
The Role

We are so glad you are interested in joining Sutter Health!

Organization:

SHSO-Administrative Payroll

Position Overview:

Sutter Health is one of California’s most comprehensive healthcare systems and one of the nation’s largest, generating $18+ billion in revenues. Headquartered in Sacramento, Sutter Health is a not-for-profit, integrated healthcare system committed to health equity, community partnerships and innovative, high-quality patient care. Sutter’s 60,500+ employees, 14,000+ physicians and advanced practice clinicians, serve more than 3.5 million patients through its network of hospitals, medical foundations, ambulatory surgery centers, urgent and walk-in care centers, telehealth, home health and hospice services.
The Chief Information Security Officer (CISO) is the senior executive responsible for safeguarding the confidentiality, integrity, and availability of the health system’s information assets, technologies, and patient data. CISO develops and leads an enterprise cybersecurity program that balances patient safety, regulatory compliance, and business enablement. This role requires a visionary leader who can navigate the evolving healthcare threat landscape, foster a culture of security and resilience, and partner with clinical, operational, and digital leaders to support safe, effective, and trusted care delivery.
Essential Responsibilities:
Strategic Leadership
-Develop and implement a multi-year information security strategy that aligns with organizational priorities, digital transformation goals, and regulatory requirements.
-Advise the CEO, CDO, COO, and Board of Directors on emerging cyber threats, risks to patient care, and mitigation strategies.
-Lead enterprise participation in healthcare security coalitions, information sharing groups (e.g., H-ISAC), and public–private partnerships.
Governance, Risk & Compliance
-Establish and maintain a security governance program based on healthcare-aligned frameworks (NIST CSF 2.0, HITRUST CSF, HICP, HIPAA/HITECH).
-Drive enterprise risk assessments and develop mitigation plans for cybersecurity, privacy, and clinical safety risks.
-Ensure compliance with HIPAA, HITECH, CMS, FDA (for medical device security), and state privacy regulations.
-Oversee security audits, penetration tests, and third-party/vendor risk assessments, ensuring remediation of findings.
Clinical & Operational Security
-Protect the Electronic Health Record (EHR), patient-facing portals, and digital health platforms against compromise, downtime, or data loss.
-Partner with Clinical Engineering and Biomedical teams to secure medical devices and Internet of Medical Things (IoMT).
-Lead preparedness for ransomware, phishing, insider threats, and advanced persistent threats with an emphasis on minimizing patient safety impact.
-Oversee disaster recovery and business continuity planning in alignment with emergency preparedness and patient safety frameworks.
Collaboration & Culture
-Partner with Digital, Compliance, Privacy, Clinical, and Operational leaders to embed security into new initiatives, system design, and patient engagement platforms.
-Build and lead organization-wide security awareness and phishing-resistance training tailored to caregivers, clinicians, and administrative staff.
-Serve as the public face of information security during regulatory reviews, patient safety investigations, and stakeholder engagements.
Team Leadership
-Recruit, develop, and lead a high-performing healthcare cybersecurity team across areas such as threat intelligence, incident response, IAM, and risk management.
-Promote a culture of accountability, clinical safety, and innovation in cybersecurity practices.
-Provide coaching and mentoring for next-generation security leaders.

Job Description:

Minimum Qualifications:

Education & Experience

  • Bachelor’s degree in Information Technology, Cybersecurity, Healthcare Administration, or related field required; Master’s degree preferred.
  • 10+ years of progressive leadership in information security and risk management, with 5+ years in healthcare or another highly regulated industry.
  • Demonstrated success implementing enterprise cybersecurity programs in a multi-hospital health system, payer, or large healthcare delivery network.

Knowledge & Skills

  • Deep knowledge of HIPAA, HITECH, CMS, OCR enforcement, FDA guidance for medical devices, and healthcare-specific risk management frameworks.
  • Expertise in EHR security (Epic preferred), identity and access management, cloud security, and medical device security.
  • Strong business and clinical acumen; ability to align security with patient care priorities.
  • Exceptional communication skills with the ability to present to clinical leaders, executives, and boards.
  • Relevant certifications strongly preferred: CISSP, HCISPP, CISM, CISA, or CHPS.

The primary office location of this position will be in Sacramento or Emeryville, CA.

    Job Shift:

    Days

    Schedule:

    Full Time

    Days of the Week:

    Monday - Friday

    Weekend Requirements:

    As Needed

    Benefits:

    Yes

    Unions:

    No

    Position Status:

    Exempt

    Weekly Hours:

    40

    Employee Status:

    Regular

    Sutter Health is an equal opportunity employer EOE/M/F/Disability/Veterans.

    Pay Range is $189.00 to $255.71 / hour

    The compensation range may vary based on the geographic location where the position is filled. Total compensation considers multiple factors, including, but not limited to a candidate’s experience, education, skills, licensure, certifications, departmental equity, training, and organizational needs. Base pay is only one component of Sutter Health’s comprehensive total rewards program. Eligible positions also include a comprehensive benefits package.

    Sutter Health Compensation & Benefits Highlights

    The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sutter Health and has not been reviewed or approved by Sutter Health.

    • Healthcare Strength Healthcare coverage is described as comprehensive, with broad networks and strong wellness support. Family coverage is characterized as low-cost or nearly free in some plan options, reinforcing perceived value.
    • Retirement Support Retirement offerings include employer matching and, in some cases, a pension after a tenure threshold. Supplemental protections like life and disability insurance add to the overall financial security package.
    • Leave & Time Off Breadth Paid time off is framed as generous, with examples of sizable PTO allotments early in tenure. Additional supports such as flexible scheduling and leave programs contribute to a sense of time-off breadth.

    Sutter Health Insights

    Similar Jobs

    Vercel Logo Vercel

    Counsel

    Artificial Intelligence • Cloud • Software
    Easy Apply
    Hybrid
    San Francisco, CA, USA
    250K-270K Annually

    CoreWeave Logo CoreWeave

    Director, Business Development

    Cloud • Information Technology • Machine Learning
    In-Office
    3 Locations
    1450 Employees
    182K-242K Annually

    FloQast Logo FloQast

    Technical Support

    Artificial Intelligence • Fintech • Software
    Hybrid
    Los Angeles, CA, USA
    800 Employees
    60K-90K Annually

    BlackRock Logo BlackRock

    Director, Institutional - Healthcare

    Fintech • Information Technology • Financial Services
    In-Office
    2 Locations
    25000 Employees
    200K-270K Annually
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    HQ: Sacramento, CA
    68,000 Employees
    Year Founded: 1921

    What We Do

    Sutter Health is one of the nation's leading not-for-profit healthcare networks, which includes award-winning physician organizations, acute care hospitals, surgery centers, medical research facilities and specialty services. Our team of 68,000 doctors, employees and volunteers proudly cares for Northern California. Our facilities and care centers are located in large, urban cities and small, rural communities, from the Pacific Coast to the San Joaquin Valley. You’ll find us in San Francisco, Oakland, Sacramento, the snowy mountains of the Sierra Nevada and Lake Tahoe, Napa Valley, Yosemite and the coastal redwoods. We even have an affiliate in Hawaii. Join us and be part of a dedicated group of professionals committed to putting patients’ needs first and achieving the highest levels of quality, access and affordability.

    Similar Companies Hiring

    Camber Thumbnail
    Fintech • Healthtech • Social Impact
    New York, New York
    90 Employees
    Sailor Health Thumbnail
    Healthtech • Social Impact • Telehealth
    New York City, NY
    20 Employees
    Granted Thumbnail
    Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
    New York, New York
    23 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account