Back to jobs
New

Senior Director, Security, CCS

Remote - United States

Overview:  The Senior Director, Security is responsible for strategic direction, leadership and execution of the company’s security strategy. This leader will be the Information Security Officer for the company and will have an overarching objective of safeguarding our organization’s assets and reputation. The Sr. Director, Security will oversee the security of our digital infrastructure, data and physical security operations, security governance, risk, and compliance for the company. The ideal candidate will be a seasoned leader with experience in cybersecurity, data privacy, risk management, and regulatory compliance in the healthcare sector. This role will work closely with the CEO, VP, Technology, and other executives to integrate security practices across all business functions. This role will serve as the subject matter expert and support client interactions related to our security program.

Key Responsibilities:

  • Leadership and Strategy:
    • Design and implement a comprehensive security strategy across the organization, including IT security, physical security, and risk management for health data. Ensure alignment between security objectives and the organization’s overall business goals.
    • Establish and maintain a security governance framework to ensure policies, procedures, and standards align with industry best practices, regulations and compliance requirements (ie. HIPAA, SOC-2, etc.).
    • Provide exceptional leadership to the security team, including hiring, mentoring and developing security (and IT professionals) across the organization.
    • Develop and maintain strong relationships with executive leadership, IT, Operations, Legal and Compliance teams to integrate security principles into business practices.
    • Communicate security-related issues, risks, and success to executive leadership and the board of directors.
  • Cyber Security and Risk Management:
  • Identify, assess and mitigate potential threats to the organization’s technology infrastructure and patient/customer data.
  • Oversee the design and implementation of robust security measures to protect against data breaches, cyberattacks, and other security risks, inclusive of security architecture.
  • Ensure a proactive approach to risk management by conducting regular vulnerability assessments, penetration testing, and incident response exercises.
  • Develop and implement disaster recovery and business continuity plans to safeguard the organization’s critical systems and data.
  • Ensure software changes align with security policies by overseeing code reviews, vulnerability scanning, risk assessments, and compliance validation before approval.
  • Compliance and Regulatory Oversight:
  • Ensure the organization adheres to all applicable healthcare privacy regulations, including HIPAA and other security regulations.
  • Lead efforts to maintain third-party security certifications (ie. SOC-2) and manage regular audits to demonstrate compliance.
  • Oversee the implementation of security policies, training programs, and awareness initiatives to ensure staff at all levels understand their role in protecting sensitive data.
  • Lead the audit program and ensure continued compliance with SOC-2 Controls
  • Establishes and oversees a security vendor risk tiering framework by evaluating vendors based on risk factors such as data sensitivity, regulatory impact, security posture, and business criticality.
  • Incident Response and Crisis Management:
  • Lead the development and execution of incident response strategies and protocols to quickly identify and mitigate security breaches and cyber incidents.
  • Oversee investigations and reporting of security incidents, ensuring all appropriate actions are taken and stakeholders internally and externally are notified promptly.

 

Qualifications:

  • 10+ years of progressive leadership in information security, with a proven track record in healthcare or a highly regulated industry.
  • In-depth knowledge of healthcare compliance and regulatory requirements.
  • Expertise in cybersecurity best practices, threat detection and incident response.
  • Strong leadership, communication, and interpersonal skills, with experience managing cross-functional teams. Ability to interact with clients.
  • Security certifications (e.g. CISSP, CISM, CISA, or equivalent) are strongly preferred.
  • Experience with security tools and technologies including firewalls, intrusion detection prevention systems, endpoint security, SIEM solutions, and cloud security.
  • Strong business acumen with the ability to balance security needs with organizational goals.

Education:

  • Bachelor’s degree in computer science, Information Technology or a related field.
  • Master’s Degree in technology or related field preferred.

Location:

  • This position is remote, but candidates must be based in the U.S.

ComplexCare Solutions Offers a Competitive Salary and Benefits Package

In addition to the base compensation, this position may be eligible for performance-based incentives.

The actual base pay offered may vary depending on multiple factors including, but not limited to, job-related knowledge/skills, experience, business needs, geographical location, and internal equity.  At ComplexCare Solutions, it is not typical for an individual to be hired at or near the top end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate.

Base Compensation Range

$149,100 - $195,000 USD

Studies have shown that women and people of color are less likely to apply for jobs unless they believe they meet every one of the qualifications listed in a job description. If you don’t meet every qualification listed but are excited about our mission and the work described, we encourage you to apply regardless.  ComplexCare Solutions is most interested in finding the best candidate for the job and you may be just the right person for this or other roles.

By embracing diversity, equity and inclusion we enhance our work environment and drive business success. ComplexCare Solutions strives to reflect the diversity of the communities where we operate and of our clients and everyone whom we serve. We endeavor to create a culture of inclusion in which our associates feel empowered to bring their full, authentic selves to work and pursue their professional goals in an equitable setting. We understand that by fostering this type of culture, and welcoming different perspectives, we generate innovation and growth.

ComplexCare Solutions is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirement.

The Company maintains a drug free work environment for all of its associates, which includes employees, contractors and vendors. It is unlawful for associates to manufacture, sell, distribute, dispense, possess or use any controlled substance or marijuana in the workplace and doing so will result in disciplinary action, up to and including termination of employment or the contracted relationship.

To review the legal requirements, including all labor law posters, please visit this link

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

You must be able to select "yes" in order to proceed.

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in CCS, Corporate’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.