×
Register Here to Apply for Jobs or Post Jobs. X

Vice President, Chief Information Security Officer

Job in Northern, Floyd County, Kentucky, USA
Listing for: Sutter Health
Full Time position
Listed on 2026-02-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Job Description & How to Apply Below
Location: Northern

Sutter Health is one of California’s most comprehensive healthcare systems and one of the nation’s largest, generating $18+ billion in revenues. Headquartered in Sacramento, Sutter Health is a not-for-profit, integrated healthcare system committed to health equity, community partnerships and innovative, high-quality patient care. Sutter’s 60,500+ employees, 14,000+ physicians and advanced practice clinicians, serve more than 3.5 million patients through its network of hospitals, medical foundations, ambulatory surgery centers, urgent and walk-in care centers, telehealth, home health and hospice services.

Essential

Responsibilities Strategic Leadership
  • Develop and implement a multi-year information security strategy that aligns with organizational priorities, digital transformation goals, and regulatory requirements.
  • Advise the CEO, CDO, COO, and Board of Directors on emerging cyber threats, risks to patient care, and mitigation strategies.
  • Lead enterprise participation in healthcare security coalitions, information sharing groups (e.g., H-ISAC), and public–private partnerships.
Governance, Risk & Compliance
  • Establish and maintain a security governance program based on healthcare-aligned frameworks (NIST CSF 2.0, HITRUST CSF, HICP, HIPAA/HITECH).
  • Drive enterprise risk assessments and develop mitigation plans for cybersecurity, privacy, and clinical safety risks.
  • Ensure compliance with HIPAA, HITECH, CMS, FDA (for medical device security), and state privacy regulations.
  • Oversee security audits, penetration tests, and third-party/vendor risk assessments, ensuring remediation of findings.
Clinical & Operational Security
  • Protect the Electronic Health Record (EHR), patient-facing portals, and digital health platforms against compromise, downtime, or data loss.
  • Partner with Clinical Engineering and Biomedical teams to secure medical devices and Internet of Medical Things (IoMT).
  • Lead preparedness for ransomware, phishing, insider threats, and advanced persistent threats with an emphasis on minimizing patient safety impact.
  • Oversee disaster recovery and business continuity planning in alignment with emergency preparedness and patient safety frameworks.
Collaboration & Culture
  • Partner with Digital, Compliance, Privacy, Clinical, and Operational leaders to embed security into new initiatives, system design, and patient engagement platforms.
  • Build and lead organization-wide security awareness and phishing-resistance training tailored to caregivers, clinicians, and administrative staff.
  • Serve as the public face of information security during regulatory reviews, patient safety investigations, and stakeholder engagements.
Team Leadership
  • Recruit, develop, and lead a high-performing healthcare cybersecurity team across areas such as threat intelligence, incident response, IAM, and risk management.
  • Promote a culture of accountability, clinical safety, and innovation in cybersecurity practices.
  • Provide coaching and mentoring for next-generation security leaders.
Education & Experience
  • Bachelor’s degree in Information Technology, Cybersecurity, Healthcare Administration, or related field required;
    Master’s degree preferred.
  • 10+ years of progressive leadership in information security and risk management, with 5+ years in healthcare or another highly regulated industry.
  • Demonstrated success implementing enterprise cybersecurity programs in a multi-hospital health system, payer, or large healthcare delivery network.
Knowledge & Skills
  • Deep knowledge of HIPAA, HITECH, CMS, OCR enforcement, FDA guidance for medical devices, and healthcare-specific risk management frameworks.
  • Expertise in EHR security (Epic preferred), identity and access management, cloud security, and medical device security.
  • Strong business and clinical acumen; ability to align security with patient care priorities.
  • Exceptional communication skills with the ability to present to clinical leaders, executives, and boards.
  • Relevant certifications strongly preferred: CISSP, HCISPP, CISM, CISA, or CHPS.

The primary office location of this position will be in Sacramento or Emeryville, CA.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary