What are the responsibilities and job description for the Information Security Manager (ISM/HIPAA Security Officer) position at Community Health Alliance?
Community Health Alliance is looking for full-time Information Security Manager (ISM/HIPAA Security Officer). Join our talented team of IT that focus on serving the community and helping those in need by creating healthy outcomes for patients of every income.
We operate six convenient locations throughout Reno and Sparks, providing comprehensive, top-quality medical services, dental and pediatric care, behavioral health, low-cost pharmacies, nourishing food pantries, and more.
Position Summary:
The Information Security Manager (referred to as ISM hereafter) owns, develops, implements, and continuously improves the organization's Information Security Program to protect internal information systems, sensitive data, and electronic Protected Health Information (ePHI).
This position serves as the organization's designated HIPAA Security Officer, responsible for implementing and managing the technical and administrative safeguards required under the HIPAA Security Rule. The Information Security Manager is the organization's technical security authority, accountable for cybersecurity governance, risk assessments, security operations, incident response readiness, and the administration and oversight of enterprise security technologies.
This is both a strategic and hands-on role within a lean IT environment, providing leadership, governance, monitoring, and direct operational support across Microsoft 365 technologies (Entra ID, SharePoint, Teams, OneDrive, Purview) and related cybersecurity platforms such as Arctic Wolf and Netwrix.
The ISM represents the organization in collaboration with the Health Center Controlled Network (HCCN), Primary Care Association (PCA), and peer Federally Qualified Health Centers (FQHCs) to address evolving cybersecurity risks, regulatory requirements, and emerging technologies.
Collaboration
The ISM collaborates closely with the Quality Improvement & Compliance Director, HIPAA Privacy Officer, Risk Manager, Information Technology leadership, General Counsel, and Executive Leadership to ensure alignment of information security, regulatory compliance, HIPAA privacy, and enterprise risk management activities.