Job Description:
The Intermountain Cybersecurity Program is broken into four distinct functions: Governance Risk and Compliance, Cyber Solutions, Cyber Advisory and the Cyber Fusion Center. Cyber Caregivers within Intermountain will specialize in their specific area and function.The Cybersecurity Manager is responsible for assisting and advising their Cybersecurity Director in the organization, management and delivery of their functional responsibility within the Intermountain Cybersecurity program. The Manager will lead a team of cybersecurity caregivers and deliver the cybersecurity services they are accountable to within their specific security function. They will ensure their caregivers are appropriately trained and mentored. They will assist the Cybersecurity Director in evaluating, planning and implementing tools, processes and functionality to mature Intermountain’s Cybersecurity Program. They will additionally ensure that cybersecurity best practices and standards are developed and adopted for their area of responsibility. They will coordinate with other Information Technology teams, service providers and key stakeholder groups to support enterprise initiatives and delivery of new technology and capabilities. They will adopt the Intermountain Operating Model and deliver continuous improvement for processes and technologies under their responsibility. Lastly, they will be responsible to improve and manage cybersecurity services, manage service levels, support the cybersecurity roadmap, and develop and manage meaningful metrics and key performance indicators for their function.
This specific manager position will be the manager of Incident Detection & Response and is responsible for leading the organization's 24x7 Fusion Center and Incident Response functions. This leader oversees a team of analysts, responders, and incident coordinators responsible for continuous monitoring, threat detection, investigation, containment, eradication, recovery, and post-incident improvement activities.
The role provides operational leadership for cybersecurity event monitoring, incident response, escalation management, and security operations processes. The Manager ensures effective protection of organizational assets by maintaining a highly skilled workforce, driving operational excellence, and coordinating response activities across technology, privacy, legal, risk, compliance, and business stakeholders.
This position serves as a key leader during cybersecurity incidents and is accountable for security operation center performance, service levels, operational readiness, and continuous improvement.
The position will oversee:
Established MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond) targets.
Maintain 24x7 operational coverage and service availability.
Improve alert fidelity and reduce false positives.
Meet incident handling and escalation SLAs.
Increase response automation and operational efficiency.
Advance SOC maturity through continuous improvement initiatives.
Maintain a highly engaged, trained, and retained cybersecurity workforce.
Essential Functions
- Develop and deliver consistent cybersecurity services within their functional area of responsibility.
- Ensure the maintenance, upgrades and operations of cybersecurity technologies and processes within their functional area of responsibility.
- Mentor and coach team members to ensure there is an adequate management succession plan in place and foster individual career growth for individual team members.
- Build a winning culture through the Intermountain Operating Model with a repeatable, process-based approach that recognizes the interdependence of all key stakeholders in the solutions delivery process.
- Be accountable to deliver results for area of responsibility.
- Regular and effective communication with staff on projects and operations to ensure timely delivery within budget and according to requirements, including goal setting, implementation and problem/issue resolution.
- Facilitates and is accountable for the implementation and compliance of cybersecurity standards and best practices (e.g., processes, tools, monitoring, repeatability, etc.).
- Provides consistent recommendations for improvement in cybersecurity processes, technologies, and staffing.
- Defines and measures quality and productivity associated with the services provided within the cybersecurity function.
- Coordinates project initiation, prioritization, and information technology resource allocation for staff within this function.
- Maintains current technical and business knowledge for areas of responsibility.
- Attracts, develops and maintains top diverse talent to continually raise the bar on the capabilities and deliverables of the organization.
- Lead and manage 24x7 Security Operations Center functions, including incident detection, monitoring, investigation, escalation, and response activities.
- Ensure continuous monitoring of enterprise security events, alerts, and indicators of compromise across cloud, endpoint, network, identity, email, and application environments.
- Direct day-to-day SOC operations, workload management, staffing, and resource allocation.
- Establish and maintain operational processes that support timely and effective incident response.
- Ensure operational readiness for emerging cyber threats and evolving business requirements.
- Recruit, develop, coach, and retain a high-performing cybersecurity operations team.
- Establish performance expectations, training plans, career development pathways, and succession planning.
- Conduct performance evaluations and provide ongoing mentoring and professional development.
- Foster a culture of accountability, collaboration, innovation, and continuous learning.
- Ensure adequate staffing coverage across all operational shifts and rotations.
Qualifications
Minimum Qualifications
- Bachelor’s degree through an accredited institution, or an advanced cybersecurity certification such as the CISSP or SANS 700+ Series
- 3+ years of leading technology teams
- 5+ years of relevant experience in information systems/security technologies and systems.
- Demonstrated understanding and knowledge of the eight Information System Security domains in the Common Body of Knowledge for CISSP and the four core Information Security Practice areas and tasks for CISM.
- Demonstrated understanding and knowledge of information security related regulations (e.g., HIPAA / HITECH).
- Demonstrated effective leadership and communication skills.
- Demonstrated strong analysis, problem resolution, judgment, and decision-making skills.
- Demonstrated ability to effectively prioritize and execute tasks in a high-pressure environment.
- Demonstrated experience working in a team-oriented, collaborative environment.
- Experience using word processing, spreadsheet, database, internet and e-mail and scheduling applications.
- Experience in a role requiring effective verbal, written and interpersonal communication skills.
- Results and customer service orientation
- Risk-based approach to implementing cybersecurity best practices and safeguards that support the mission of Intermountain Health
Preferred Qualifications
- Bachelor’s degree through an accredited institution. A degree must be obtained through an accredited institution. Education is verified.
- ITIL certified.
- 7+ years of related experience in information systems, security technologies and systems.
- Working experience with Security and Privacy regulations and the cybersecurity aspects of other regulations including HIPAA/HITECH, PCI DSS, SOX (MAR FRC), FRCP, JCAHO and JCAHO Alert 42, GLBA, State Breach, FERPA, and FCRA, etc.
- Experience working in a healthcare or healthcare insurance environment.
- Self-motivated and directed.
- Keen attention to detail.
- Ability to manage geographically dispersed teams, including off-shore and on-shore.
- Strong knowledge of:
- Security Operations Centers (SOC)
- Incident Response methodologies
- Threat Detection and Threat Hunting
- SIEM and SOAR platforms
- Endpoint Detection and Response (EDR)
- Network security technologies
- MITRE ATT&CK
- NIST 800-61 Incident Response Framework
- Experience building and managing high-performing cybersecurity teams
Physical Requirements
- Interact with others requiring the employee to communicate information.
- Operate computers and other IT equipment requiring the ability to move fingers and hands.
- See and read computer monitors and documents.
- Remain sitting or standing for long periods of time to perform work on a computer, telephone, or other equipment.
Location:
Lake Park BuildingWork City:
West Valley CityWork State:
UtahScheduled Weekly Hours:
40The hourly range for this position is listed below. Actual hourly rate dependent upon experience.
$59.50 - $91.84We care about your well-being - mind, body, and spirit - which is why we provide our caregivers a generous benefits package that covers a wide range of programs to foster a sustainable culture of wellness that encompasses living healthy, happy, secure, connected, and engaged.
Learn more about our comprehensive benefits package here.
By applying for a position with Intermountain, I acknowledge that I will comply with all applicable Intermountain policies and expectations. If applying for a remote or hybrid role, this includes remote work expectations related to confidentiality, information security, work schedules, conflicts of interest, and use of company equipment. I further acknowledge that outside employment or activities may not interfere with job responsibilities or create a conflict of interest with Intermountain. Actual or reasonably perceived conflicts may be grounds for disqualification from consideration or, if hired, corrective action up to and including termination of employment.
Intermountain Health is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
At Intermountain Health, we use the artificial intelligence ("AI") platform, HiredScore to improve your job application experience. HiredScore helps match your skills and experiences to the best jobs for you. While HiredScore assists in reviewing applications, all final decisions are made by Intermountain personnel to ensure fairness. We protect your privacy and follow strict data protection rules. Your information is safe and used only for recruitment. Thank you for considering a career with us and experiencing our AI-enhanced recruitment process.
All positions subject to close without notice.

