What are the responsibilities and job description for the Chief Information Security Officer position at KamisPro?
Must be local to DC metro area and able to work on-site 3 days per week. This is a consulting role that will convert to full time employee. Thank you.
Job Title: Chief Information Security Officer (CISO)
Job Description:
Seeking a highly experienced Chief Information Security Officer (CISO) to lead and manage our cybersecurity program. The ideal candidate will have a robust background in IT security within federal law enforcement, along with specialized knowledge of the regulatory landscape affecting healthcare organizations.
Key Responsibilities:
- Develop, implement, and maintain a comprehensive information security strategy aligned with hospital operations and mission.
- Oversee risk management initiatives related to cybersecurity, including vulnerability assessments, threat modeling, and compliance audits.
- Lead incident response efforts and manage investigations into security events, data breaches, or other cyber threats.
- Ensure compliance with all relevant healthcare security and privacy regulations, including HIPAA, HITECH, and HITRUST certification requirements.
- Collaborate with IT, compliance, clinical, and legal teams to integrate security into technology deployments and clinical workflows.
- Develop and maintain policies, procedures, and training programs to support a strong security and privacy culture throughout the organization.
- Stay current with evolving threats and regulatory requirements, leveraging insights from federal law enforcement experience to strengthen institutional readiness.
- Manage third-party vendor risk and ensure security standards are upheld across external partnerships.
Qualifications:
- Proven leadership in IT security, preferably with direct experience in or with federal law enforcement agencies.
- In-depth understanding of HIPAA, HITECH, and HITRUST frameworks, and their application in a healthcare setting.
- Strong knowledge of healthcare IT systems, data protection strategies, and clinical technology integration.
- Relevant certifications such as CISSP, CISM, CISA, or HITRUST Certified CSF Practitioner are highly desirable.
- Excellent communication skills with the ability to present complex issues to executive leadership and cross-functional teams.
- Bachelor’s degree in cybersecurity, information systems, or related field (Master’s preferred).