Join Martin's Point Health Care - an innovative, not-for-profit health care organization offering care and coverage to the people of Maine and beyond. As a joined force of "people caring for people," Martin's Point employees are on a mission to transform our health care system while creating a healthier community. Martin's Point employees enjoy an organizational culture of trust and respect, where our values - taking care of ourselves and others, continuous learning, helping each other, and having fun - are brought to life every day. Join us and find out for yourself why Martin's Point has been certified as a "Great Place to Work" since 2015.
Position Summary
The Manager Information Security is responsible for the effective and dynamic management of the Information Security infrastructure, risk, compliance team and ongoing operations. This role works collaboratively within IT and across the organization to ensure security and compliance while adapting to business and industry changes. The Manager Information Security also leads efforts to support the Martin’s Point business resiliency program including business continuity, incident response and disaster recovery plans and assists in the Security teams strategic planning, management, and execution to achieve its goals.
Job Description
Key Outcomes:
- Leads, mentors, and coaches the Information Security team in achieving goals and ensuring the department has the technical skills, tools, and resources to meet current and future business needs.
- Maintains knowledge of latest security and privacy legislation, regulations, advisories, alerts, and vulnerabilities pertaining to Martin’s Point vision, mission, and operations.
- Collaborates with Martin’s Point leadership and Compliance team, internal IT business partners, data custodians and government groups to develop company-wide information security polices and guidelines that align with external regulations and industry best practices.
- Initiates and supports continuous improvement efforts within the team to maximize and enhance individual and team performance.
- Responsible for MPHC Business Resiliency Management strategy development and recovery planning with guidance from the Senior Director Chief Information Security Officer, and the IT Leadership Team.
- Ensures efficient implementations of Incident Reporting and Response Systems to address MPHC security incidents and/or breaches, respond to alleged policy violations, and/or complaints from external parties.
- Coordinates the development and delivery of an education and training program on information security and privacy matters for employees and other authorized users.
- Partners with the Senior Director Chief Information Security Officer on reports to external agencies to meet or exceed all compliance requirements
- Active participation on the Information Technology Leadership Team to achieve department and organizational goals in alignment with Martin’s Point values and strategy.
- Manage information security vendors, consultants and outside contacts to ensure strong partnership, service, and performance.
- Provides input to the budget process to support Martin’s Point strategic goals within industry benchmarks.
- Serves as back up to the Senior Director Chief Information Security Officer as the official corporate contact point for information security.
Education/Experience:
- Bachelor’s degree in CIS, CS, Business Administration, or similar program, or combination of relevant education and experience. Master’s degree is preferred.
- 7+ years applicable practice, management and/or leadership in information security and/or information technology with at least 3 years in a leadership role.
- Budgeting and contract negotiation experience required.
- Healthcare experience and familiarity with HIPAA, PCI-DSS, or NIST is highly desirable.
Required License(s) and/or Certification(s):
- Global Information Assurance Certification (GIAC), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), and/or Certified Information Security Manager (CISM) is highly desired.
Skills/Knowledge/Competencies:
- Demonstrates an understanding of and alignment with Martin’s Point Values.
- Successful track record in leading, collaborating coaching and mentoring technical teams.
- Expertise in the highly regulated security industry best practices.
- Strong working knowledge of PCI, HIPAA Privacy & Security, DoD, CMS and other applicable industry and organizational local, state, and federal information security guidelines.
- Ability to translate organizational objectives into information technology needs, initiatives, and deliverables.
- Must be an effective leader and a strong collaborative team player both internally and externally.
- Excellent written and oral communications skills to present clear, accurate and timely information to technical and non-technical audiences at all levels of the organization.
- Ability to rapidly assess situations, develop alternatives and make decision in a fast-paced work environment.
- Ability to design, manage and deliver effective technology solutions to meet business needs.
- Proven track record of managing projects, initiatives, and accountabilities within a team.
- Approach all organizational and departmental situations with a growth mindset.
- A demonstrated ability to work with diverse groups of people.
Key Outcomes:
- Leads, mentors, and coaches the Information Security team in achieving goals and ensuring the department has the technical skills, tools, and resources to meet current and future business needs.
- Maintains knowledge of latest security and privacy legislation, regulations, advisories, alerts, and vulnerabilities pertaining to Martin’s Point vision, mission, and operations.
- Collaborates with Martin’s Point leadership and Compliance team, internal IT business partners, data custodians and government groups to develop company-wide information security polices and guidelines that align with external regulations and industry best practices.
- Initiates and supports continuous improvement efforts within the team to maximize and enhance individual and team performance.
- Responsible for MPHC Business Resiliency Management strategy development and recovery planning with guidance from the Senior Director Chief Information Security Officer, and the IT Leadership Team.
- Ensures efficient implementations of Incident Reporting and Response Systems to address MPHC security incidents and/or breaches, respond to alleged policy violations, and/or complaints from external parties.
- Coordinates the development and delivery of an education and training program on information security and privacy matters for employees and other authorized users.
- Partners with the Senior Director Chief Information Security Officer on reports to external agencies to meet or exceed all compliance requirements
- Active participation on the Information Technology Leadership Team to achieve department and organizational goals in alignment with Martin’s Point values and strategy.
- Manage information security vendors, consultants and outside contacts to ensure strong partnership, service, and performance.
- Provides input to the budget process to support Martin’s Point strategic goals within industry benchmarks.
- Serves as back up to the Senior Director Chief Information Security Officer as the official corporate contact point for information security.
Education/Experience:
- Bachelor’s degree in CIS, CS, Business Administration, or similar program, or combination of relevant education and experience. Master’s degree is preferred.
- 7+ years applicable practice, management and/or leadership in information security and/or information technology with at least 3 years in a leadership role.
- Budgeting and contract negotiation experience required.
- Healthcare experience and familiarity with HIPAA, PCI-DSS, or NIST is highly desirable.
Required License(s) and/or Certification(s):
- Global Information Assurance Certification (GIAC), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), and/or Certified Information Security Manager (CISM) is highly desired.
Skills/Knowledge/Competencies:
- Demonstrates an understanding of and alignment with Martin’s Point Values.
- Successful track record in leading, collaborating coaching and mentoring technical teams.
- Expertise in the highly regulated security industry best practices.
- Strong working knowledge of PCI, HIPAA Privacy & Security, DoD, CMS and other applicable industry and organizational local, state, and federal information security guidelines.
- Ability to translate organizational objectives into information technology needs, initiatives, and deliverables.
- Must be an effective leader and a strong collaborative team player both internally and externally.
- Excellent written and oral communications skills to present clear, accurate and timely information to technical and non-technical audiences at all levels of the organization.
- Ability to rapidly assess situations, develop alternatives and make decision in a fast-paced work environment.
- Ability to design, manage and deliver effective technology solutions to meet business needs.
- Proven track record of managing projects, initiatives, and accountabilities within a team.
- Approach all organizational and departmental situations with a growth mindset.
- A demonstrated ability to work with diverse groups of people.
We are an equal opportunity/affirmative action employer.
Do you have a question about careers at Martin’s Point Health Care? Contact us at: jobinquiries@martinspoint.org