Demo

VP Information Security

Lensa
Dallas, TX Full Time
POSTED ON 11/23/2025 CLOSED ON 12/21/2025

What are the responsibilities and job description for the VP Information Security position at Lensa?

Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of its direct clients, recruitment ad agencies, and marketing partners. Lensa partners with DirectEmployers to promote this job for Baylor Scott & White Health. Clicking "Apply Now" or "Read more" on Lensa redirects you to the job board/employer site. Any information collected there is subject to their terms and privacy notice.

Job Summary

Reporting to the SVP, Chief Information Officer, the VP Information Security is Baylor Scott & White Health's (BSWH) senior executive responsible for cybersecurity strategy, risk reduction, and enterprise resilience across hospitals, clinics, ambulatory sites, enterprise systems (including EHR), clinical environments, and cloud platforms. Within IS's Agile delivery model, the VP embeds "security by design" into backlogs, sprints, and release trains to translate strategy into day to day execution for product and platform teams.

The VP owns the NIST Cybersecurity Framework (CSF) adoption roadmap (Identify-Protect-Detect-Respond-Recover), ensures HIPAA/HITECH and healthcare specific compliance (e.g., 405(d) HICP; HITRUST mappings), and delivers measurable risk reduction via prioritized, evidence based investments. The CISO partners with Internal Audit, Risk, Compliance/Privacy, Legal, HR, Supply Chain/VMO, Clinical leadership, and IS Governance to align cyber risk decisions with patient safety, business goals, and financial stewardship.

The role operates with multiple Managed Service Providers (MSPs), governing cross provider standards, SLAs, joint playbooks, and unified metrics so BSWH presents one security posture.

Essential Functions

Cybersecurity Roadmap

  • Developing a Cybersecurity Road Map that could be used at both an Executive/Board Level and is also "translatable" to operational level teams.
  • Cascade the road map deliverables throughout the team, trackable as weekly, monthly, and yearly activities for the teams.

Cyber Program & Governance

  • Set the enterprise cybersecurity strategy and multi year roadmap aligned to NIST CSF 2.0; convert into budgets, OKRs, and measurable KRIs/KPIs.
  • Run executive security governance (e.g., Security Steering, Board/ISLC updates) with concise risk narratives and decision options.
  • Lead integration across MSPs (cyber, apps, infra, PMO): shared standards, SLAs, joint runbooks, cross tower escalations, and performance scorecards.
  • Embed Agile processes in daily operations
  • Own security policy/standards/baselines; drive "design time security" via enterprise architecture and Zero Trust.

Governance, Risk & Controls (GRC) / Cyber Program

  • Maintain enterprise risk register; quantify risk and prioritize remediation by business impact exploitability asset criticality.
  • Ensure regulatory, legal, and framework alignment (HIPAA/HITECH, 405(d) HICP, HITRUST mappings); coordinate internal/external audits and control testing.
  • Lead third party risk with Supply Chain/VMO (security schedules, right to audit, breach notification, continuous monitoring); track remediation to closure.
  • Operate a Cyber Risk & Performance dashboard mapped to NIST CSF and governance exhibits; present trends, heat maps, and decision asks.

Cyber Operations (SOC / Incident Response / Resilience)

  • Oversee 24×7 SOC, SIEM, EDR/XDR, threat hunting, phishing defense, use case engineering; drive MTTD/MTTR improvements and alert quality.
  • Own Incident Response and Crisis Management: tested playbooks, ransomware readiness, forensics, breach notification with Privacy/Legal, executive and Board communications.
  • Lead cyber requirements for BC/DR (backup/restore integrity, cyber recovery, segmentation) including clinical technology; run joint tabletop exercises with MSPs.

Cyber Defense (Vulnerability/Exposure/Patch; Email/Network/Endpoint defense)

  • Run an exposure management program that continuously measures risk and sequences remediation to eliminate the riskiest 20% that drive ~80% of exposure.
  • Align vulnerability SLAs by asset tier; orchestrate patching across internal teams and MSPs with defined maintenance windows and change governance.
  • Oversee platform defenses with domain leaders (e.g., Proofpoint for email, Firewall policy/governance, Endpoint protection standards).

Identity & Access Management (IAM)

  • Own IAM/IGA, SSO/MFA, PAM, privileged session monitoring; enforce least privilege, JIT access, and high assurance controls for high risk workflows (e.g., EHR admin, OT).
  • Conduct periodic access reviews and certs; integrate identity guardrails into Agile CI/CD and change processes.

Data Protection

  • Lead data classification, DLP, encryption (at rest/in transit/in use), key management, tokenization, and de identification for research/analytics; partner with Privacy.
  • Establish guardrails for data use in cloud/SaaS and with third parties; monitor and remediate data handling risks.

Cyber Architecture & Engineering

  • Define Zero Trust architecture; secure reference architectures for cloud (IaaS/PaaS/SaaS) and on prem; operate CSPM/CWPP posture management.
  • Embed secure SDLC / DevSecOps (threat modeling, SAST/DAST/IAST, SBOM, software supply chain security); provide reusable patterns and hardened baselines.
  • Partner with platform teams on secure build pipelines; codify controls as policy as code.

Platform Security Domains

  • Endpoint Management: OS/app hardening baselines, EDR policy, device compliance; integrate with patch/change windows.
  • Firewall: Network segmentation strategy, rule lifecycle governance, change control; coordinate with MSP network teams.
  • Cloud Security: Guardrails, identity boundaries, key/cert management, workload posture; integrate with product teams' Agile delivery.
  • Email Security (Proofpoint): Advanced threat protection, impersonation/BEC defenses, policy tuning; measure catch/allow rates and false positives.
  • SOC Integration: Use case roadmap, tuning, detection engineering, purple teaming; multi MSP handoffs tested and measured.

Key Success Factors

  • Education/Credentials: Bachelor's in Cybersecurity/CS/IS or related field; Master's preferred. Executive level security certification(s) (e.g., CISSP, CISM, CISA, CCISO or comparable).
  • Experience: 15-20 years relevant experience with 10 years progressive IT/security leadership in large, complex, regulated settings; 5 years leading enterprise security portfolios. Health system experience preferred.
  • Strategy ? Execution: Demonstrated ability to prioritize highest impact risks and convert strategy into an executable, Agile aligned cascade (daily?annual) with measurable outcomes.
  • MSP Leadership: Multi provider integration expertise; establishing common standards, OLAs/XLAs, joint playbooks, action oriented governance and commercial levers with VMO/Supply Chain.
  • NIST & Regulatory Mastery: NIST CSF/800 53, HIPAA/HITECH, 405(d) HICP, HITRUST mappings, PCI (as applicable), FDA/medical device guidance, privacy/security interplay.
  • Architecture & Ops: Zero Trust, IAM/IGA/PAM/MFA, cloud security, secure SDLC & software supply chain, EDR/XDR/SIEM, exposure mgmt, IR/crisis comms.
  • Executive Communication: Storytelling for Board/executives; operational translation for engineers and clinicians; calm leadership under pressure. Ability to handle sensitive information and collaborate across clinical, administrative, and technical teams.
  • People & Culture: Team builder and coach; cultivates a learning, high trust, high accountability culture; scales capability via MSPs and internal talent.

Minimum Requirements

  • Bachelor's Degree (Information Security, IT, Computer Science, or related preferred).
  • 10 years of experience

As a health care system committed to improving the health of those we serve, we are asking our employees to model the same behaviours that we promote to our patients. As of January 1, 2012, Baylor Scott & White Health no longer hires individuals who use nicotine products. We are an equal opportunity employer committed to ensuring a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.

If you have questions about this posting, please contact support@lensa.com
Cyber Security Engineer
Paradigm Information Services, Inc. -
Plano, TX
Director of Corporate Security and Physical Risk - Remote
Experian Information Solutions -
Allen, TX
Information Security Officer (ISO)
InfoDefense, Inc. -
Dallas, TX

Salary.com Estimation for VP Information Security in Dallas, TX
$172,534 to $207,076
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a VP Information Security?

Sign up to receive alerts about other jobs on the VP Information Security career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$270,069 - $359,305
Income Estimation: 
$328,229 - $449,590
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$270,069 - $359,305
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Lensa

  • Lensa Cheyenne, WY
  • Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs,... more
  • 13 Days Ago

  • Lensa Pierre, SD
  • Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs,... more
  • 13 Days Ago

  • Lensa Pierre, SD
  • Lensa is a U.S. career site that helps job seekers discover job opportunities. We are not a staffing firm or agency. We promote jobs on behalf of our clien... more
  • 13 Days Ago

  • Lensa Anchorage, AK
  • Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs,... more
  • 13 Days Ago


Not the job you're looking for? Here are some other VP Information Security jobs in the Dallas, TX area that may be a better fit.

  • Career-Mover Irving, TX
  • The Info Sec Prof Lead Analyst position at Citi is an intermediate-level role responsible for preventing, monitoring, and responding to information/data br... more
  • 4 Days Ago

  • Hispanic Technology Executive Council Irving, TX
  • About Citi: Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. ... more
  • 28 Days Ago

AI Assistant is available now!

Feel free to start your new journey!