Chief Information Security Officer
Jobleads-US
Job Title
System Director, Information Security (CISO)
Reports to
SVP, Chief Information & Digital Officer
Department
Information Security
Last Reviewed
August 2026
Vision
Creating America’s healthiest community, together.
Mission
In the spirit of love and compassion, better health, better care, better value
Values
Accountability, Caring and Teamwork
Department Summary
The St. Charles Health System’s Information Security department identifies, assesses, reports, and helps to mitigate technical, physical, and administrative risks to St. Charles’ regulated and confidential information.
Position Overview
The System Director Information Security (CISO) collaborates internally and externally to identify, assess, report, and help mitigate risks to St. Charles’ physical and digital regulated and confidential information in alignment with business goals and objectives. This role leads the information security department and partners closely with IT, Privacy, Compliance, Internal Audit, HR, Legal, and other departments. The CISO develops strategy, policy, and oversees information security operations (e.g., network monitoring, threat intelligence, vulnerability management, penetration testing, data loss prevention, incident response, advisory services), third‑party risk managing, e‑Discovery, information security risk management, awareness and education, program management, and governance. The CISO has demonstrated experience with the technical, administrative, and regulatory requirements and best practices relating to information security, privacy, and healthcare operations. This position directly manages caregivers in the information security department.
ESSENTIAL FUNCTIONS AND DUTIES
- Develops, implements, and oversees a strategic, enterprise‑wide information security program to ensure the integrity, confidentiality, and availability of St. Charles’ regulated and confidential information and systems.
- Identifies, evaluates, and reports on information security risks in a manner that meets compliance and regulatory requirements and aligns with the organization’s overall risk posture.
- Establishes and facilitates information security governance through leadership and active participation in organizational governance bodies, including data governance, external data governance, technology governance, and safety governance committees.
- Reports on the status of identified information security risks, provides regular updates on the evolving threat landscape, and secures executive approval for strategic initiatives to reduce St. Charles’ risk exposure.
- Develops, maintains, and publishes current information security policies, standards, procedures, and guidelines.
- Oversees enterprise information security risk management and mitigation activities to ensure timely and effective remediation.
- Collaborates with executive leadership to define acceptable levels of information security risk and ensures alignment with organizational objectives.
- Partners with the System Privacy Officer to conduct risk assessments and evaluations related to HIPAA Privacy and Security Rule compliance and the Health Industry Cybersecurity Practices.
- Establishes and oversees cybersecurity risk frameworks specifically governing Internet of Medical Things (IoMT) devices, clinical networks, and biomedical integration.
- Drives the adoption and continuous maturity of enterprise security frameworks, aligning operations with the NIST Cybersecurity Framework (CSF), NIST AI Risk Management Framework, and HITRUST standards.
- Leads and directs a dedicated technical security team responsible for executing the following core operational functions: Security Operations & Incident Response (SOC): 24/7/365 security monitoring, threat hunting, log aggregation, and event correlation using SIEM/SOAR platforms. Rapid triage, containment, escalation, and post‑incident root‑cause analysis for security events across network, endpoint, and cloud environments.
- Engineering & Architecture Implementation: Design, deployment, and ongoing administration of Endpoint Detection & Response (EDR/XDR). Identity & Access Management (IAM) technical oversight, including privileged access management (PAM), multi‑factor authentication (MFA), and directory service security controls.
- Vulnerability Management & Offensive Security: Continuous vulnerability scanning, patch verification, and risk‑prioritized remediation tracking across clinical, enterprise, and infrastructure assets. Coordination and execution of internal/external penetration testing, red teaming exercises, and social engineering scenarios.
- Data Loss Prevention (DLP) & Technical Privacy Controls: Configuration and management of DLP agents, email security gateways, encryption tools, and data classification mechanisms to safeguard Protected Health Information (PHI) and corporate data.
- Medical Device & Endpoint Security: Technical discovery, isolation, and security patching for biomedical equipment, Internet of Medical Things (IoMT) hardware, and clinical workstation configurations.
- Designs, implements, and manages organization‑wide information security awareness and training programs for employees, contractors, and authorized system users.
- Works closely with business units to facilitate information security risk assessment and management processes, engaging stakeholders across the organization to identify and manage residual risk.
- Coordinates with the architecture team members to ensure security controls and strategies are aligned with enterprise architecture and technology roadmaps.
- Defines and oversees the information security risk assessment process, including internal reporting and governance of remediation efforts for identified findings.
- Leads the organizational response to information security incidents and events to protect St. Charles’ assets, intellectual property, regulated data, and organizational reputation.
- Supports Human Resources, Legal, Compliance, and Privacy functions with internal investigations, regulatory inquiries, audits, and other investigative activities as required.
- Monitors the external threat environment for emerging risks and vulnerabilities and advises executive leadership and stakeholders on appropriate response strategies.
- Responsible for budget development, regular monitoring, accountability and meeting all operational targets for all areas within span of control.
- Hires, directs, coaches, and monitors the performance of all direct reports, to develop and maintain a high‑performance team that meets organizational and department goals.
- Monitors and ensures all direct reports are current with compliance and safety requirements.
- Implements and manages all organizational safety directives and goals.
- Provides and oversees team’s delivery of customer service in a manner that promotes goodwill, is timely, efficient, and accurate.
- Collaborates with teams to review processes and identify/implement opportunities for improvements, applying Lean principles, concepts, and tools.
- Supports the vision, mission, and values of the organization in all respects.
- Supports the Lean principles of continuous improvement with energy and enthusiasm, functioning as a champion of change.
- Provides and maintains a safe environment for caregivers, patients, and guests.
- Conducts all activities with the highest standards of professionalism and confidentiality.
- Complies with all applicable laws, regulations, policies, and procedures, supporting the organization’s corporate integrity efforts by acting in an ethical and appropriate manner, reporting known or suspected violation of applicable rules, and cooperating fully with all organizational investigations and proceedings.
- May perform additional duties of similar complexity within the organization, as required or assigned.
Education
- Required: Bachelor’s degree in information technology, information security, or related field.
- Preferred: Master’s degree in a related field.
Licensure / Certification / Registration
- Required: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or other similar credential(s).
- Preferred: Multiple relevant industry certifications.
Experience
- Required: Minimum of seven (7) years of information security experience.
- Minimum of two (2) years leading and managing information security programs and leadership experience in a regulated environment (preferably healthcare).
- Preferred Experience: Comprehensive cybersecurity leadership spanning technical operations, risk and compliance, governance and frameworks, privacy and regulation, cloud and emerging technologies.
Personal Protective Equipment
Must be able to wear appropriate Personal Protective Equipment (PPE) required to perform the job safely.
Additional Position Information
Travel
Must be able to travel to business functions/trainings/meetings and all SCHS worksites.
Physical Requirements
- Continually (75% or more): Use of clear and audible speaking voice and the ability to hear normal speech level.
- Frequently (50%): Sitting, standing, walking, lifting 1-10 pounds, keyboard operation.
- Occasionally (25%): Bending, climbing stairs, reaching overhead, carrying/pushing, or pulling 1-10 pounds, grasping/squeezing.
- Rarely (10%): Stooping/kneeling/crouching, lifting, carrying, pushing, or pulling 25-50 pounds, ability to hear whispered speech level.
Exposure to Elemental Factors
Never (0%): Heat, cold, wet/slippery area, noise, dust, vibration, chemical solution, uneven surface.
Blood‑Borne Pathogen (BBP) Exposure Category
No Risk for Exposure to BBP.
Schedule Weekly Hours
40
Caregiver Type
Regular Shift: First Shift (United States of America)
Is Exempt Position?
Yes
Job Family
DIRECTOR
Scheduled Days of the Week
Monday-Friday
Shift Start & End Time
8:00am - 5:00pm
About the Organization
St. Charles Health System is a private, nonprofit organization, dedicated to providing high‑quality care and the latest in health care technology to the communities it serves. Headquartered in Bend, Ore., St. Charles is an integrated delivery system, with a strong focus on population health, that provides a full range of evidence‑based health care services within a 32,000‑square‑mile area in Central and Eastern Oregon. The health system owns and operates a trauma level II, tertiary referral center in Bend, a trauma level III, type B rural hospital in Redmond, and trauma level IV critical access hospitals in both Prineville and Madras. As the largest employer in Central Oregon, St. Charles Health System and St. Charles Medical Group care for our communities in more than two dozen outpatient clinics and in more than 20 specialty areas of medicine.
#J-18808-Ljbffr Jobleads-US- ...Posted Friday, August 7, 2026 at 5:00 AM SpecPro Sustainment and Environmental (SSE) is seeking a Chief Information Security Officer (CISO) to support the National Space Intelligence Center (NSIC) Military Construction (MILCON) program at Wright-Patterson Air Force...SuggestedTemporary workFor contractorsWork at officeFlexible hours
- ...wide cybersecurity strategy and multi-year roadmap protecting information assets, global distribution services, ecommerce, cloud solutions... ...Committee, and the Board of Directors Lead a central security team and coordinate matrixed security resources across global...Suggested
- ...Job Title System Director, Information Security (CISO) Reports to SVP, Chief Information & Digital Officer Department Information Security Last Reviewed August 2026 Vision Creating America’s healthiest community, together. Mission In the...SuggestedFor contractorsMonday to FridayShift workDay shift
- ...positively impact others, and pursue your personal and professional dreams-we'd love to meet you. Job Description The Chief Information Security Officer (CISO) is a senior leadership role responsible for the development, implementation, and ongoing oversight of the Bank...SuggestedContract workWork at office
- ...that’s all in? At Imprivata, we deliver unified access and security management programs that eliminate friction, empowering... ...make an impact—you’ll find it here. We are seeking a Chief Information Security Officer to join our team. This is a hybrid opportunity based out...SuggestedWork at officeLocal area
- ...Chief Information Security Officer (CISO)ADI requires a CISO who will establish and maintain an enterprise-wide strategy, and multi-year roadmap to protect information assets, global distribution services, ecommerce, and cloud solutions, along with enterprise IT systems...
- ...a high bar for itself — keep reading. About the Role Socure is seeking an experienced, executive-level Deputy Chief Information Security Officer (Deputy CISO) to report directly to the CISO. In this role, you will lead company-wide security, data governance, compliance...
- ...Asst VP, Chief Information Security Officer Organization: Scripps Health Location: Description: About the job Scripps Health Administrative Services supports our five hospital campuses, 31 outpatient centers, clinics, emergency rooms, urgent care sites...Full time
$245k - $325k
...LinkedIn. Summary of Position: Scholar Rock is seeking a Senior Director, Cybersecurity to serve as the company’s Chief Information Security Officer, responsible for building and scaling enterprise cybersecurity capabilities that protect the organization’s people,...Contract workFor contractors- ...Job Title: Information Security Officer Summary The Information Security Officer (ISO) at German American Bank is responsible for establishing and coordinating information security efforts, privacy efforts and business resumption planning across the company...Temporary workWork experience placement
- ...St. Charles Health System in Bend, Oregon seeks a System Director of Information Security (CISO) to lead the information security program, risk management, and governance across the organization. This executive role collaborates with IT, Privacy, Compliance, Legal,...
- ...Asst VP, Chief Information Security Officer at Scripps Health will lead cybersecurity strategy for a top integrated health system, safeguarding critical systems, data, and digital assets while enabling innovation and patient care. You'll lead a high-performing information...
- ...SpecPro Sustainment and Environmental, LLC seeks a Chief Information Security Officer (CISO) to lead IT infrastructure design for a high‑profile MILCON project at Wright‑Patterson AFB, OH. The role supports NSIC and collaborates with WPAFB, NASIC, and IC partners....For contractors
$160k - $194k
...Resources at (***) ***-**** or by sending an email to ****@*****.*** Requisition ID:110602By submitting your information and application, you confirm that you have read and agree to the country or regional recruitment notice linked below applicable...Full timeRemote workWorldwide- ...Baseten is seeking a Head of IT to build, scale, and secure our internal technology function as we grow. You will lead 5+ IT engineers, own corporate IT infrastructure, identity management, device lifecycles, and vendor procurement, delivering a world-class tech experience...
- ...Network Security Administrator Clearance: U.S. Citizen with Secret clearance (minimum) Location: Bluegrass Station, Lexington, KY (primary); travel to Ft Walton Beach, FL and Crestview, FL may be required Position Summary: The Network Security Administrator...Full time
$275k - $350k
...Looking For: AmeriSave is seeking a Chief Technology Officer to lead our Enterprise Technology &... ...software engineering, infrastructure, and security function responsible for our... ...required to sustain that bar at scale. Information Security: Own the organization's...Local areaRemote work$255k - $295k
Chief Information OfficerSkip to main content**Applicant Privacy Policy:** As a candidate for this... ...@csiperseus.com.#Chief Information Officer page is loaded## Chief Information OfficerApplylocations... ...Blue’s growth through scalable, secure, and efficient technology capabilities...Full timeTemporary workRemote work- ...that’s all in? At Imprivata, we deliver unified access and security management programs that eliminate friction, empowering... ...can make an impact—you’ll find it here. We are seeking a Chief Information Officer to join our team. This is a hybrid opportunity based in our...Contract workWork at officeLocal area
- ...atmosphere that encourages innovation and teamwork Job Summary MBC Holdings, Inc (MBC) is seeking an accomplished Fractional Chief Information Officer to partner directly with executive leadership in modernizing the company’s technology strategy and IT organization. This...Temporary workLocal area
- ...innovative and strategic technology leader to serve as its next Chief Information Officer (CIO). Reporting to the Assistant City Manager, the CIO... ...governance while partnering with departments to deliver secure, reliable, and innovative technology solutions that enhance...Full timeContract workPart timeSeasonal workWork at officeLocal area
$105.4k - $207.8k
...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this... ...:Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent demonstrated experience...Local areaVisa sponsorship$97.61k - $188.38k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll... ...configure, and deploy Saviynt.Understand complex business and information technology management processes. Execute advanced services and...Local areaVisa sponsorship$117.6k - $161.7k
...Tooling capability inside our Offensive Security organization, and we're looking for a senior... ...: To ensure Home or Hybrid Home/Office employees’ ability to work effectively,... ...interruptions to protect member PHI / HIPAA information.Travel: While this is a remote position,...Full timeTemporary workApprenticeshipWork at officeRemote workWork from homeHome office- ...technologies that advance patient care, operational efficiency, and data security. Why join usWe believe that investing in our employees is the... ...in healthcare IT.Bachelor's degree in Computer Science, Information Systems, Business, or related field required, or 7+ years of...Full timeTemporary workPart timeLocal area
- ...location health system across application management, integration, security, reporting, release management and vendor partnerships to... ...measurable operational value.Qualifications: Bachelor’s degree in Information Systems, Computer Science, Business, or a related field (or...Full time
$80k
Ready for a Better Way to Practice Chiropractic? Sometimes, the right adjustment changes everything — including your career. At The Joint Chiropractic, we’ve reimagined how chiropractic care is delivered so doctors can focus on what matters most: treating patients...Full timeRelocation packageMonday to FridayFlexible hours- ...OH0713 NW Bancshares HQ Job Description The Divisional Chief Information Officer (Divisional CIO) serves as part of the Executive... ...the strategy, delivery, modernization, support, resilience, security, and continuous improvement of technology capabilities supporting...Work experience placementWork at office
- ...Imprivata is seeking a strategic Chief Information Security Officer to lead the global information security program. The CISO will partner with executive, product, engineering, IT, legal, and compliance teams to integrate security into all business areas. The role...
$181.6k - $220k
...an accommodation or an alternative application process. Chief People Officer Full Time Senior Leadership 18 days ago Requisition ID... ...the ability to maintain confidentiality of highly sensitive information ~ Detail-oriented and able to efficiently prioritize...Full timeLive inLocal areaRemote workDay shiftAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer. Be the first to apply!
- business information security officer Kentucky
- ciso Kentucky
- chief information security officer ciso Kentucky
- information security officer Kentucky
- chief information security officer Kentucky
- information technology security engineer Kentucky
- information security Kentucky
- director information security Kentucky
- information security lead Kentucky
- remote ciso



