What are the responsibilities and job description for the IT Security Lead position at SWITS DIGITAL Private Limited?
Greetings from Smartwork IT Services,
We are actively looking for an IT Security Lead for one of our valuable clients. This is a full-time, remote opportunity (US-based) with 50% travel required to Virginia (VA) or Massachusetts (MA). The role focuses on leading cybersecurity and data protection for a large-scale Public Health System Oracle Health EHR implementation, ensuring compliance with state and federal security standards across healthcare and correctional health environments.
Job Title: IT Security Lead
Location: US – Remote (Any location)
Travel: 50% (VA or MA)
Job Summary
The IT Security Lead will oversee the design, implementation, validation, and sustainment of cybersecurity and data protection strategies for an Oracle Health EHR ecosystem. This role ensures secure, compliant, and resilient operations across infrastructure, applications, integrations, and data flows, aligning with HIPAA, NIST 800-53, FISMA, and state-specific cybersecurity policies. The position involves close collaboration with state cybersecurity teams, executive stakeholders, and third-party vendors.
Key Responsibilities
Security Architecture & Governance
We are actively looking for an IT Security Lead for one of our valuable clients. This is a full-time, remote opportunity (US-based) with 50% travel required to Virginia (VA) or Massachusetts (MA). The role focuses on leading cybersecurity and data protection for a large-scale Public Health System Oracle Health EHR implementation, ensuring compliance with state and federal security standards across healthcare and correctional health environments.
Job Title: IT Security Lead
Location: US – Remote (Any location)
Travel: 50% (VA or MA)
Job Summary
The IT Security Lead will oversee the design, implementation, validation, and sustainment of cybersecurity and data protection strategies for an Oracle Health EHR ecosystem. This role ensures secure, compliant, and resilient operations across infrastructure, applications, integrations, and data flows, aligning with HIPAA, NIST 800-53, FISMA, and state-specific cybersecurity policies. The position involves close collaboration with state cybersecurity teams, executive stakeholders, and third-party vendors.
Key Responsibilities
Security Architecture & Governance
- Lead hybrid cloud security architecture using Oracle Cloud Infrastructure (OCI) and state-managed data centers.
- Implement Zero Trust architecture, including MFA, RBAC, and least-privilege access.
- Align security controls with NIST 800-53, CIS benchmarks, and service agreements.
- Establish governance for change control, incident response, and disaster recovery (DR).
- Act as primary liaison with Executive Steering Committee and state cybersecurity teams.
- Conduct enterprise risk assessments across technical, operational, and hosting domains.
- Maintain a risk register with mitigation strategies and governance controls.
- Lead vulnerability assessments, penetration testing, and firewall reviews.
- Ensure compliance with HIPAA, 42 CFR Part 2, FISMA, and applicable regulations.
- Oversee continuous monitoring, patching, and SOC coordination.
- Design and implement IAM across Oracle Health Millennium, RevElate, and integrated systems.
- Manage user provisioning, de-provisioning, and access audits.
- Validate SSO and MFA integrations with Oracle IAM and state identity providers.
- Define and validate SLAs, RTO/RPO, uptime, and incident response metrics.
- Coordinate DR testing with Oracle Health and state infrastructure teams.
- Develop and maintain failover, downtime, and recovery playbooks.
- Oversee secure data ingestion using Oracle Health Data Intelligence (HDI).
- Validate HL7/FHIR interface security (encryption, authentication, audit logging).
- Implement secure APIs and interoperability frameworks for state and federal systems.
- Provide 24/7 monitoring, quarterly health checks, and performance tuning.
- Lead modernization initiatives leveraging OCI security and automation services.
- Ensure alignment with ITIL service management and state governance practices.
- Bachelor’s degree required.
- 5 years of IT security leadership experience in healthcare or public sector environments.
- Proven experience securing large-scale EHR implementations (Oracle Health Millennium/RevElate preferred).
- Strong knowledge of HIPAA, NIST, FISMA, and state cybersecurity frameworks.
- Experience with IAM, SOC operations, vulnerability management, and DR planning.
- Familiarity with OCI, HL7/FHIR, and secure data integration practices.
- Excellent communication, stakeholder management, and documentation skills.