{"id":1973151,"url":"https://alion.io/job/atlanticare-chief-information-security-off","title":"Chief Information Security Off","company":{"id":2227813,"name":"AtlantiCare","domain":"atlanticare.org","url":"https://alion.io/company/atlanticare","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":77,"open_postings":50,"ghost_share":0,"stale_share":0.94,"repost_share":0,"time_to_fill_p50_days":35,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"head","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Egg Harbor Township, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":134000,"max_usd":293000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":141},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"HIPAA","optional":false},{"name":"Least Privilege","optional":false},{"name":"NIST CSF","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-10-06T20:09:38Z","employer_posted_date":"2026-10-06","last_verified_at":"2026-10-11T17:56:43Z","board_verified":true,"closed_at":null,"days_open":5,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":5},"description":"POSITION SUMMARY\nThe Chief Information Security Officer (CISO) is the enterprise executive accountable for protecting AtlantiCare’s patients, workforce, data, clinical operations, and reputation from cyber risk. Reporting to the EVP, Chief Information and Digital Officer, the CISO sets the vision, strategy, governance, and operating model for information security and cyber resilience across the health system. This leader translates complex threats, vulnerabilities, and regulatory obligations into clear business and patient-safety risk decisions for executive leadership and the Board.\nThe CISO leads the enterprise Information Security Program and team; establishes policy, architecture, controls, metrics, and accountability; and ensures readiness to prevent, detect, respond to, and recover from cyber incidents. Working across clinical, operational, technology, biomedical, legal, privacy, compliance, audit, emergency management, and vendor partners, the CISO embeds security by design while enabling AtlantiCare’s strategic, digital, cloud, data, and AI priorities. The role is both strategic and operational and requires sound judgment, calm leadership, executive presence, and the ability to influence outcomes across a complex, highly regulated environment.\n KEY RESPONSIBILITIES\nEnterprise strategy and governance: Develop and execute a multi-year information security and cyber resilience strategy, roadmap, operating model, and budget aligned with AtlantiCare’s strategic plan, enterprise risk appetite, and technology priorities.\n\nExecutive and Board advisory: Serve as the principal cyber risk advisor to executive leadership and the Board, presenting the organization’s risk posture, material threats, control maturity, investment priorities, risk-acceptance decisions, and program performance in clear business and patient-safety terms.\n\nRisk ownership and accountability: Establish governance that enables business and technology leaders to identify, understand, mitigate, accept, and document cyber risk at the appropriate level.\n\nSecurity program leadership: Lead the enterprise Information Security Program and ensure consistent, high-quality execution across governance, risk, compliance, architecture, engineering, operations, incident response, awareness, and third-party risk.\n\nTeam and partner leadership: Recruit, develop, motivate, and retain a high-performing security team; set clear accountabilities and performance expectations; and oversee managed security service providers, consultants, and dotted-line resources.\n\nPolicy and control framework: Maintain a practical, risk-based framework of policies, standards, procedures, and controls aligned with applicable laws, regulations, contractual obligations, and recognized practices including NIST CSF 2.0, HHS 405(d) HICP, and the HHS Healthcare and Public Health Cybersecurity Performance Goals.\n\nRegulatory assurance: Partner with Legal, Compliance, Privacy, Audit, and operational leaders to maintain compliance with HIPAA, HITECH, the HIPAA Security Rule, and applicable federal and state requirements; oversee assessments, remediation plans, evidence, and regulatory readiness.\n\nSecurity architecture and engineering: Establish security-by-design requirements across identity, network, endpoint, cloud, applications, data, integration, and emerging technologies, advancing zero trust, multifactor authentication, least privilege, privileged access management, segmentation, encryption, and secure configuration.\n\nClinical and medical-device security: Partner with clinical, Biomedical Engineering, Facilities, and operational leaders to protect connected medical devices and clinical technology through accurate inventories, risk-based segmentation, vulnerability management, lifecycle planning, downtime safeguards, and security requirements in procurement.\n\nThreat and vulnerability management: Maintain awareness of the external threat environment and direct threat intelligence, exposure management, penetration testing, vulnerability prioritization, and remediation across technology and business owners.\n\nIncident response and crisis leadership: Lead the response to significant cyber incidents, including ransomware, data compromise, and extended technology downtime; coordinate executive, clinical, operational, legal, privacy, communications, insurance, and law-enforcement activities; and ensure timely breach assessment, notification, and lessons learned.\n\nCyber resilience and recovery: Partner with Technology, Emergency Management, and clinical operations to align disaster recovery, business continuity, backup protection, recovery testing, downtime procedures, and tabletop exercises with critical business and patient-care priorities.\n\nThird-party and supply-chain risk: Establish a lifecycle process to assess and manage cyber risk associated with vendors, business associates, cloud providers, software, services, and other ecosystem partners; ensure appropriate security requirements, contractual protections, monitoring, and concentration-risk decisions.\n\nDigital, cloud, data, and AI enablement: Embed proportionate security review into technology intake, procurement, architecture, development, and project delivery. Partner with Data and Analytics, Privacy, Legal, and operational leaders to govern AI tools and models, including data protection, access, acceptable use, monitoring, and third-party risk.\n\nHuman risk and security culture: Build an enterprise security culture through role-based awareness, phishing simulations, executive and clinical education, targeted interventions for high-risk users, and a network of security champions.\n\nMetrics and continuous improvement: Define meaningful key risk and performance indicators, including risk reduction, control coverage, resilience, vulnerability remediation, third-party exposure, and workforce behavior; use results to prioritize resources and improve program maturity.\n\nExternal engagement: Maintain effective relationships with peers, Health-ISAC, cyber insurance partners, law enforcement, CISA, HHS, and other relevant agencies to strengthen preparedness, information sharing, and response.\n\nFinancial stewardship: Develop and manage the information security budget, investment portfolio, contracts, and vendor performance, ensuring resources are directed to the organization’s highest risks and most critical capabilities.\n\nProfessional leadership: Demonstrate sound judgment, integrity, urgency, discretion, customer focus, and composure under pressure. Communicate effectively with technical and nontechnical audiences and influence outcomes where formal authority may not exist.\n\nAdhere to AtlantiCare policies and procedures and perform other duties as assigned.\n\nWORK ENVIRONMENT\nThis position requires sitting at a desk or computer a majority of the day, with frequent speaking, reaching, and reading.This position requires occasional lifting up to 20 lbs. This position requires availability outside normal business hours, including evenings, weekends, and holidays, to lead the response to significant security incidents.\nREPORTING RELATIONSHIP\nThis position reports to the EVP, Chief Information and Digital Officer, provides regular cyber risk reporting to executive leadership and the Board, and supervises Information Security staff as assigned.\n QUALIFICATIONS\nEDUCATION: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Business, Health Informatics, or a related field, or equivalent relevant experience, required. Master’s degree preferred.\nLICENSE/CERTIFICATION: CISSP or CISM strongly preferred; CRISC, CISA, CCSP, HCISPP, or comparable security, risk, cloud, or healthcare credentials are desirable.\nEXPERIENCE: Ten or more years of progressive cybersecurity, information security, technology risk, or related experience, including at least five years leading teams, enterprise programs, or significant security functions. Health care experience and demonstrated knowledge of HIPAA, HITECH, the HIPAA Security Rule, health information privacy, and the operational and patient-safety implications of cyber events are required.\nThe successful candidate will have experience advising executives or boards; leading incident response and recovery; managing regulatory, audit, and third-party risk; establishing security architecture and controls across network, identity, endpoint, cloud, application, data, and medical-device environments; and developing multi-year strategy, budgets, metrics, and talent. Experience evaluating AI-enabled platforms and securing major digital or clinical transformation programs is strongly preferred.","description_format":"text","description_chars":8655,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":5,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Health Care","Urgent & Emergency Care","Information Security","Primary Care & Medical Centers"],"lifecycle":[{"event":"open","at":"2026-10-06T20:09:38Z"}],"visa":[],"liveness":{"score":60,"band":"ok","label":"Likely open","p_open":1,"p_active":0.602,"p_room":1,"age_days":3,"expected_fill_days":35,"reasons":["conf:2","stale_co","win:early","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/atlanticare-chief-information-security-off","json_url":"https://alion.io/job/atlanticare-chief-information-security-off.json","meta":{"generated_at":"2026-10-11T21:38:08Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":10666,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2227813},"rest":"https://alion.io/mcp/rest/get_company?id=2227813"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fatlanticare-chief-information-security-off"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fatlanticare-chief-information-security-off"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fatlanticare-chief-information-security-off"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/atlanticare-chief-information-security-off\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fatlanticare-chief-information-security-off"}]}