IT Security, Director I (Hybrid)
$146.38k - $197.73kAmerican Medical Association
IT Security, Director I (Hybrid) Chicago, IL The American Medical Association (AMA) is the nation's largest professional Association of physicians and a non-profit organization. We are a unifying voice and powerful ally for America's physicians, the patients they care for, and the promise of a healthier nation. To be part of the AMA is to be part of our Mission to promote the art and science of medicine and the betterment of public health. At AMA, our mission to improve the health of the nation starts with our people. We foster an inclusive, people-first culture where every employee is empowered to perform at their best. Together, we advance meaningful change in health care and the communities we serve. We encourage and support professional development for our employees, and we are dedicated to social responsibility. We invite you to learn more about us and we look forward to getting to know you. We have an opportunity at our corporate offices in Chicago for an IT Security, Director I (Hybrid) on our Information Technology team. This is a hybrid position reporting into our Chicago, IL office, requiring 3 days a week in the office. This role is responsiblefor providing subject matter expertise on the strategy, research, design,implementation, and operation of technical and process security controls. Develops strong relationships across the AMA’s IT department and with business unit teams; serves as a trusted advisor to assess security risk in technologyselection with appropriate balance that supports business outcomes. Responsibilitiesinclude data security, collaboration with the security operations team, andmaintaining the broad suite of information security infrastructure, and allassociated contracting, policy, and regulatory compliance implications. Maintain cybersecurity and related regulatory expertise to research,prepare, and maintain strategic roadmaps incorporated into the InformationSecurity Program. Lead or assist withsecurity incidents and compliance investigations and produce timely and clearreporting to both technical and senior business leader audiences. Serves asprimary backup for the Director IT Security. RESPONSIBILITIES: System/Network/Application Security Strategy Research, design,evaluate, and test the security and regulatory compliance of AMA applications,systems, and networks to ensure the operational effectiveness of technical controls implemented by theorganization; purpose-built security tools such as data loss prevention,logging and event management, enterprise encryption systems and also securitycontrols embedded in enterprise systems and applications such as authenticationand access controls Responsible for the effective use of AMA cybersecurity systems including enhancements, upgrades, and lifecycle management throughrelationships with product and service vendors Responsible forthe technical integration of security components within the AMA’s environmentto optimize the value and control benefits including ease of use, effectiveness, and breadth of coverage Technology and Regulatory Risk Management Assess technical risks in the AMA’s environment both pre and post-production through the AMA’s Software DevelopmentLifecycle (SDLC) and Change & Release Management Boards; proposeinformation security strategy and program improvements, communicate identifiedrisks and recommend solutions Management Boards; proposeinformation security strategy and program improvements, communicate identifiedrisks and recommend solutions Manage the research, appropriate response, and remediation of malicious and inappropriate activity; ensure consistency of the riskassessment approach across the organization Prepare policy updates;research and recommend short and long-term improvements to maintain strong security posture relative to enterprise architecture standards, data integration/data access, cloudstrategy, and AI implementations Collaborate indeveloping, recommending and implementing the AMA’s information securitypolicies, and governance frameworks; this includes aligning security initiatives with business goals and ensuring compliance withindustry standards and regulations Ensures compliance with relevant laws, regulations, and frameworks, such as PCI, GDPR, NIST, or ISO standards, and manages security audits and assessments Co-manage new software, data, and service provider products and contract reviews Responsible for staying current on threats and best practices in the field of cybersecurity Service Delivery Manage continuous process improvement to identify technical or process enhancements in the delivery of ITSecurity services to increase service quality Prioritize improvements on a cost/benefit basis, communicating opportunities to management. Serve as an escalation point in the fulfillment of IT Security service requests Project Management Manage ITSecurity-led projects following the AMA’s applicable project governanceprocesses, including Software Development Life Cycle; ensure successful project outcomes, such as completing projects within time andbudget tolerances Mentor security and infrastructure team members, including analysts, engineers, and managers,related to information security strategies and threat prevention techniques. May include other responsibilities as assigned REQUIREMENTS: Minimum 10+ years engineering/design experience with a mix of the following security platforms is required: network and application-layer firewallsand secure network design; infrastructure and application-layer vulnerabilitymanagement, security information and event management (SIEM); Security,Orchestration, Automation and Response (SOAR), data loss prevention (DLP);enterprise encryption solutions for database, file systems and data in motion;Internet/Web Gateway; end point security controls (such as anti-virus, anti-malware XDR, host-based firewall, and full disk encryptionsolutions); and intrusion detection and prevention systems. Knowledge of Attack and Penetrationmethodologies, tools, and techniques Minimum 5 yearsconducting infrastructure and application project design reviewsEngineering/design experience with a mix of the following infrastructuretechnologies is required: Microsoft/Azure (Azure AD, ADFS, M365, Sharepoint 2019, Windows Server2019-2022, Windows 10-11); RedHat Linux, VMware, AWS EC2, S3, IAM Demonstrated industry leadership capabilities, and recognized as a subject expert in the informationsecurity field. Knowledgeofsecurity scanning and analyzing tools; Commercial Application andInfrastructure/Operating System and Opensource Vulnerability scanning/management, andfreeware/commercial Wireshark, NMAP, Burp Suite, Nikto, Qualys, Tenable, Snyk,Wiz Polished verbal and written communication, interpersonal, analytical, and organizational skills, attention to detail, and a highlevel of integrity are required Strong business acumen. Ability to understand the organization's various business functions and their objectives Experience with project management and software development lifecycle methodologies preferred. Professional IT Security and IT Audit certifications such as CISSP,CISM, CEH, CISA, and/ortechnical certifications preferred Experience with IT Infrastructure Library (ITIL) – particularly incident, change, release, and/or problem management preferred Experience with ITsecurity standards, such as CIS Top 20, ISO 27001, NIST CSF, NIST 800-53,HITRUST, MITRE, OWASP,CWE/SANS Top 25 Programming Errors, and attestation reports such as SOC 1/2/3 and technology risk management methodologies, such asNIST 800-30 preferred. Experience with compliance standards such as PaymentCard Industry (PCI),Sarbanes Oxley (SOX) and Health Insurance Portability& Accountability Act (HIPAA) preferred Bachelor’s Degree in Computer Science or related discipline strongly preferred. Master’s Degree in Computer Science or related disciplinea plus Additional Technical Background Experience with: Cloud-based security tools (CloudTrail, WAF, Security Center, etc.) Source code management tools (GitHub, BitBucket, etc.) Code scanning tools (Dynamic, Static and Opensource) Vulnerability Management solutions(Qualys, Tenable, Wiz) Knowledge of: User authentication such as Zero Trust concepts, SAML and OAuth-based SSO architectures and IDPintegrations, MFA, Virtual Private Networks (VPNs), TLS, PAM, corporate wifi,device identity, 802.1x port-based authentication, server identification,authentication of web applications, S/MIME Email Signing, is desirable Programming languages (.Net, Java, JavaScript, Angular, Drupal, Python, etc.) Web services, API, REST, RPC Infrastructure as Code (CloudFormation, Terraform) preferred Administration ofAzure suite, including; Azure Active Directory, Conditional Access, Intune,Mobile Application Management, Microsoft Cloud App Security, and/or advancedAzure security services like Azure Security Center, Advanced DDoS Protection, Azure Firewall, and Azure WAF Administration of AWS security services and related best practices: GuardDuty, Cognito, Inspector,Detective and advocate AWS Identity & Access Management (IAM) Operating systems: Windows, Mac, Linux, WVD, VDI, and Jump Boxes/Bastion Servers Network routing and communication frameworks, protocols, and technologies such as OSI, TCP/IPv4 & v6, RIP, OSPF, VPN, TLS, and SSH is required. Working knowledge of SQL, LDAP, and/or regex is a plus. The American Medical Association is located at 330 N. Wabash Avenue, Chicago, IL 60611 and is convenient to all public transportation in Chicago. This role is an exempt position, and the salary range for this position is $146,384 - $197,728. This is the lowest to highest salary we believe we would pay for this role at the time of this posting. An employee’s pay within the salary range will be determined by a variety of factors including but not limited to business consideration and geographical location, as well as candidate qualifications, such as skills, education, and experience. Employees are also eligible to participate in an incentive plan. To learn more about the American Medical Association’s benefits offerings, please click here. We are an equal opportunity employer, committed to diversity in our workforce. All qualified applicants will receive consideration for employment. As an EOE/AA employer, the American Medical Association will not discriminate in its employment practices due to an applicant’s race, color, religion, sex, age, national origin, sexual orientation, gender identity and veteran or disability status. THE AMA IS COMMITTED TO IMPROVING THE HEALTH OF THE NATION #J-18808-Ljbffr American Medical Association
- The American Medical Association in Chicago, IL seeks a Director I for IT Security (Hybrid) to lead strategy, risk management, and incident response. You will design and operate security controls across the AMA IT landscape, partner with business units, and serve as a...Suggested
- ...sensitive information. The role requires a Bachelor's degree and at least two years in data privacy or related IT/risk roles. The position is grant funded, at-will, and offers a hybrid work environment with a salary in the posted range. #J-18808-Ljbffr Cook County (Illinois)SuggestedWork at office
- ...in Golden, CO and requires in-office presence at least three days per week. The position supports OT/ICS security, with travel to Golden, CO and potential hybrid work options. A TS/SCI clearance is required or attainable, and strong communication skills are essential....SuggestedWork at office3 days per week
$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll... ...public key infrastructure strategies across cloud, on-premises, and hybrid environments.Designing, implementing, and operating technology...SuggestedLocal area- ...Manager to bridge technical depth with customer advocacy, helping security teams embed Darktrace AI into daily operations and reduce risk.... ..., and Professional Services to deliver measurable outcomes. Hybrid work model requires 3 days in office weekly and strong collaboration...SuggestedWork at office
- ...Cyber Defense to lead in-depth analysis and response to escalated security incidents. You will investigate complex events, implement... ...and leadership experience, you will coordinate with threat intel, IT staff, and Tier 1 analysts, staying current on trends and SOC best...
- ...possess strong analytical and interpersonal skills, a proactive attitude, and fundraising expertise. Join ADL to contribute to its mission against hate and bias. This hybrid role requires in-office presence three days a week. #J-18808-Ljbffr ADL (Anti-Defamation League)Work at office3 days per week
- ...a Major Gifts Officer (MGO) to enhance the agency's mission by securing philanthropic support. This role involves cultivating long-term... ...fundraising experience, ideally in social services or healthcare. This hybrid role allows for personal and professional development while...
- ...detailed file audits, subsidy management, and training for property teams, with a focus on regulatory integrity. The position supports a hybrid work model across Michigan markets and requires experience with LIHTC, Section 8, and Yardi systems to drive compliance excellence...
- ...Quality Utilization Specialist Full-time, Days, Hybrid The Quality Utilization Specialist reflects the... ...pathways (Quality Utilization Medical Director (s) or the Lead Quality Utilization Specialists) to secure further information or expertise to resolve identified...Full timeFor contractorsWork at officeRelocation package
- ...involves Code of Ethics oversight, AML/KYC reviews, and training, reporting to the Chief Compliance Officer. The position operates in a hybrid model, requiring in-office presence 3 days per week. Ideal candidates hold a Bachelor's in business or finance with 5+ years in...Work at office3 days per week
- ...role partners with Legal, Risk, and Business units to ensure robust controls and regulatory adherence. The position operates in a hybrid model, requiring in-office presence three days per week, with opportunities to lead the integration of AI tools and scalable processes...Work at office3 days per week
- ...manager on a regular basis with direction provided by manager Trains, and mentors less experienced staff. This position will work a hybrid work schedule, 3 days in office & 2 days remote, from our AbbVie North Chicago, IL headquarters. Significant Work Activities:...Temporary workWork at officeRemote work
- ...comprehensive knowledge of Financial Institution Regulatory and Compliance, particularly AML and KYC requirements. Strong communication and organizational skills are essential. The position is hybrid and offers a robust benefits package. #J-18808-Ljbffr Northern Trust Corp
- A consulting firm in the Greater Chicago Area is seeking an IT Compliance Analyst to support ongoing compliance initiatives. The candidate... ...familiarity with regulatory frameworks. This position offers a hybrid work environment with opportunities for professional growth. #J-1...
$67.1k - $94.75k
...apply for the InfoSec Compliance Analyst #Hybrid role at Alliant Credit Union Join to... ...this role, you will support the Information security governance, risk management and compliance... ...assessments align securing ACU. Facilitate IT issue management by work with employees...Full timeTemporary workPart timeWork from home3 days per week- ...audit, and process expense claims for domestic and international directors and staff. The role enforces board policy and reimbursement... ...communication skills, along with familiarity with expense policies. A hybrid work arrangement is offered with portions in-office several...Work at office
- ...implement enterprise IAM and authorization solutions across cloud, on‑premises, and hybrid environments. You will work directly with clients and cross‑functional teams to strengthen security posture, support digital transformation, and streamline identity workflows...
$141.92k - $212.89k
...Regulatory Authority) is the largest independent regulator of securities firms doing business in the United States. Our mission is to protect... .... Ready to make a difference? Let's talk.Work Conditions:Hybrid work environment, with defined in-person presence requirementsFor...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start$118.7k - $218.6k
...with confidence, and proactively manage to secure success.Recruiting for this role ends on 1... ..., including cloud, on-premises, and hybrid infrastructures, to manage the deployment... ...silos, including multifunctional teams of IT professionals, legal/compliance teams, and...Work experience placementLocal areaVisa sponsorship- ...state, federal, and internal standards. This role blends meticulous compliance work with teamwork to maintain a trusted marketplace for schools and teachers. The position is hybrid (3 days in-office) with a 40-hour week, Monday through Friday. #J-18808-Ljbffr Zen EducateWork at officeMonday to Friday
$144.48k
...sensitive data, strengthen resilience, and securely enable digital transformation. Managers... ...understanding of key internal controls related to IT, cybersecurity, and other healthcare... ..., CISM, or similar preferred. Our Hybrid Workplace Protiviti practices a hybrid...Full timeTemporary workLive inWork at officeLocal areaRemote workFlexible hours- ...benefit administration, and analytical support. Ideal candidates have a Bachelor's degree, 3-5 years in Benefits/HR, strong analytical and communication skills, and a customer-centric approach. The position offers a hybrid work schedule. #J-18808-Ljbffr ViziRecruiter,LLC.
- ...experience. Strong analytical skills, attention to detail, and proficiency in MS Office are essential. The position offers competitive compensation and benefits, including medical insurance and paid time off, with opportunities for hybrid work. #J-18808-Ljbffr Genstone Realty
- ...accurate disclosures. This role requires deep balance sheet knowledge and experience with liquidity concepts. The position offers a hybrid work model in the United States and a comprehensive benefits program. Applicants must be authorized to work in the U.S. #J-18808-...
- ...financial services company, seeks a detail‑oriented professional to support compliance testing and third‑party risk processes. This hybrid Chicago role offers cross‑functional exposure and growth opportunities, focusing on BSA/AML/OFAC controls, vendor risk, and...
- ...user data. The role demands deep knowledge of applicable laws and the ability to communicate directly with requesting attorneys. A hybrid or fully remote setup is available for eligible candidates in approved locations. You will analyze subpoenas and civil demands, assess...Remote job
- ...problem‑solving and cross‑functional collaboration in a fast‑paced environment. The position supports onboarding, guideline analysis, and documentation accuracy, with a hybrid work schedule requiring two days in-office and three #J-18808-Ljbffr Manatt Phelps & PhillipsWork at office
- ...Chicago. The role involves designing and implementing network solutions, installing and configuring equipment, and ensuring network security and performance. The ideal candidate has a bachelor's degree in Computer Science or related field, with over 4 years of relevant...Flexible hours
$130k - $155k
...seeking an experienced Consultant, Network Security & Governance to join our dynamic... ...Integration: Collaborate with other security and IT teams to integrate cloud and network... ...activities within a remote (if non-local) or hybrid work arrangement where you’ll spend 2 days...Full timeLocal areaRemote work2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security, Director I (Hybrid). Be the first to apply!
