Healthcare Technology Consulting - IT Security Lead
Listed on 2026-01-27
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant, Data Security
Healthcare Technology Consulting - IT Security Lead
Join to apply for the Healthcare Technology Consulting - IT Security Lead role at Guidehouse
1 day ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
What You Will Do
Guidehouse’s Health IT Solutions team works with clients to measurably improve their technology outcomes through a mix of IT strategies, improvement in IT operations, and adoption of technology initiatives. By leveraging a deep understanding of health system IT operational best practices supported by data, Guidehouse propels IT operational improvement and technology adoption across departments and service lines at client organizations.
Job Family
Technology Consulting
Travel Required
Up to 50%
Clearance Required
None
What You Will Do
Guidehouse’s Health IT Solutions team works with clients to measurably improve their technology outcomes through a mix of IT strategies, improvement in IT operations, and adoption of technology initiatives. By leveraging a deep understanding of health system IT operational best practices supported by data, Guidehouse propels IT operational improvement and technology adoption across departments and service lines at client organizations.
The IT Security Lead will oversee the design, implementation, validation, and sustainment of cybersecurity and data protection strategies for an expansive Public Health System’s Oracle Health EHR implementation. This role is responsible for ensuring that all infrastructure, applications, integrations, and data flows meet or exceed state and federal security standards, including HIPAA, NIST 800-53, and State‑specific cybersecurity policies. The IT Security Lead will work closely with technical partners, stakeholders, and third‑party vendors to ensure secure, compliant, and resilient operations across state and correctional health environments.
Key Responsibilities
Security Architecture and Governance
- Lead the development of a hybrid cloud security architecture leveraging Oracle Cloud Infrastructure (OCI) and State‑managed data centers.
- Implement zero‑trust architecture with least‑privilege access, multi‑factor authentication (MFA), and role‑based access controls (RBAC).
- Align all security controls with service agreements, NIST 800‑53, and CIS benchmarks.
- Establish governance models for change control, incident response, and disaster recovery (DR) planning.
- Serve as the primary liaison to the Executive Steering Committee and state cybersecurity teams.
Risk Management and Compliance
- Conduct structured risk assessments across technical, contractual, staffing, and hosting domains.
- Develop and maintain a risk register with mitigation strategies anchored in governance, monitoring, and contract safeguards.
- Lead vulnerability scanning, penetration testing, and firewall reviews across all environments.
- Ensure compliance with HIPAA, 42 CFR Part 2, FISMA, and other applicable regulations.
- Oversee the implementation of continuous monitoring, patching, and SOC (Security Operations Center) coordination.
Identity and Access Management (IAM)
- Design and implement IAM protocols across Oracle Health Millennium, Rev Elate, and integrated systems.
- Manage user provisioning, de‑provisioning, and access audits across all care settings.
- Validate integration with Oracle IAM and state identity providers for seamless SSO and MFA.
Disaster Recovery and Business Continuity
- Define and validate SLAs for uptime, performance, RTO/RPO, and incident response.
- Coordinate DR testing with Oracle Health and state infrastructure teams.
- Develop and maintain playbooks for failover, downtime procedures, and recovery operations.
- Ensure that DR protocols are embedded in training and operational handoffs.
Data Protection and Integration Security
- Oversee secure ingestion and normalization of multi‑source data (clinical, claims, operational) using Oracle Health Data Intelligence (HDI).
- Validate HL7/FHIR interface security, including encryption, authentication, and audit logging.
- Implement secure APIs and data exchange frameworks for interoperability with federal and state systems.
Operational Support and Sustainment
- Provide 24/7 monitoring, quarterly…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).