Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Chief Information Security Officer

The Ohio State University

Overview The Ohio State University Wexner Medical Center The Ohio State University Wexner Medical Center (WMC) is a proud part of one of the nation’s largest major comprehensive public research universities, serving more than 65,000 undergraduate, graduate and professional students. With nearly 41,000 full-time equivalent employees, Ohio State is Ohio’s fifth-largest employer. Scope of Position Reporting to the CIDO of the Ohio State University Wexner Medical Center with a dual report to the CISO of The Ohio State University, the WMC Chief Information Security Officer (WMC CISO) leads a department focused on security, risk management, compliance and security architecture for the clinical mission of Ohio State. Working closely with our university partners, the WMC CISO will engage and collaborate with various leaders in clinical operations, research, education, audit, legal and compliance and information systems on security initiatives. The WMC CISO oversees ongoing activities, programs, and projects that serve to protect WMC data confidentiality, integrity and availability while providing clinicians, students, patients, faculty, researchers, staff and vendors with secure and reliable access to systems and information. The WMC CISO ensures strategic alignment to the university on information security standards, controls, training, practices, and reporting. Responsibilities II. Duties and Responsibilities Strategy, Governance, and Risk Management (50%) Health System Security Strategy: Develop, champion, and execute a visionary, comprehensive, multi-year information security strategy and roadmap across all mission areas of WMC, leveraging the University Security Framework. Security Framework: Work in collaboration with University CISO to align on common standards, controls and practices, ensuring a cohesive security posture where systems, services and missions overlap. Oversee the development, enforcement and auditing of security policies, procedures, and standards for the health system. Enterprise Ownership and Tolerance: Oversee Security Risk Assessments (SRAs) and vulnerability management across clinical, research, administrative, and third-party environments for the Health System. Develop and prioritize risk mitigation and remediation strategies. Coordinate with the University CISO on a streamlined risk assessment process for technologies that impact both the Medical Center and the University. Report on the WMC’s cybersecurity risk appetite in partnership with executive leadership and proactively manage and report on the overall cyber risk posture, translating technical exposure into clear business impact to the C-suite and the board through established reporting under the university CISO. Regulatory Compliance: Ensure stringent adherence to all applicable laws and regulations, including but not limited to HIPAA/HITECH, 21 CFR Part 11, PCI DSS, state data privacy laws, and security mandates for research data and grant funding (e.g., CUI). Serves as the Security Officer to oversee implementation of HIPAA security regulations and to provide ongoing compliance monitoring and education on security. Emerging Technology Governance: Establish and lead emerging technology governance frameworks for AI, cloud, automation, and other next-generation technologies, ensuring alignment with risk management, cybersecurity strategy, regulatory requirements, and business objectives. Third-Party Risk Management (TPRM): Provide executive oversight of the Third-Party Risk Management program, ensuring vendor risks are assessed, governed, and aligned with enterprise security and compliance requirements. Oversee assessing and mitigating the security risks posed by vendors, business associates, and supply chain partners in alignment with University standards and frameworks where possible. Business Continuity / Disaster Recovery: Provide executive oversight and strategic direction for enterprise Business Continuity and Disaster Recovery (BC/DR) programs, ensuring governance, resilience, regulatory compliance, and alignment with organizational risk management objectives to maintain and restore mission-critical operations during disruptions in alignment with University standards and frameworks where possible. Security Operations and Leadership III. Security Operations and Leadership (30%) Security Operations Center (SOC) Oversight: Oversee the day-to-day operations of the information security function, including threat intelligence, security monitoring, Security Information and Event Management (SIEM), and vulnerability management across on-premise, cloud, and hybrid environments in alignment with University standards and tools where possible. Incident Response: Own the Computer Security Incident Response and Reporting (CSIRR) function, leading the coordination, containment, investigation, and recovery efforts for all security incidents and breaches, and fulfilling regulatory breach notification requirements. Security Architecture and Consulting: Provide authoritative security consultation for the design and implementation of new systems (including EHR systems, clinical IoT, and cloud services) and review of existing systems, promoting security-by-design principles. Access Management and Controls: Oversee the IT Access Management function, including the alignment to advanced Identity and Access Management (IAM) and Privileged Access Management (PAM) strategies consistent with a Zero Trust model established by the University CISO. Culture, Talent, and Collaboration IV. Culture, Talent, and Collaboration (20%) Executive Collaboration: Collaborate directly and continuously with the University CISO, CIDO, and other executive and departmental leaders to align security initiatives with broad institutional and clinical goals. Team Leadership: Lead, manage, mentor, and coach a diverse, high-performing team of information security professionals, fostering a culture of continuous learning, accountability, and excellence. Security Awareness and Education: Advise Health Systems senior leadership on security risks and strategy. Drive a mandatory, ongoing security education and awareness program for all Health Systems faculty, staff, researchers, and students to effectively reduce the "human element" risk in a decentralized academic environment. Communication: Serve as the visible, articulate internal and external champion for information security, possessing the ability to engage diverse stakeholders—from technical staff and researchers to clinicians. Other duties as assigned. Organizational Expectations Practices within the medical center’s policies and procedures. Adheres to the mission and values statements as demonstrated through positive patient/guest relations, positive and effective interactions with staff and by formulating and meeting developmental goals. Given the joint reporting relationship of the position, the following have been outlined to ensure understanding and clarity of the following: Performance evaluations of the position will be resolved through joint meeting and discussion of the WMC CIDO and the University CISO, The authority of the WMC CIDO takes precedence on budget and staffing; authority of University CISO takes precedence on risk and strategic decisions, and Conflicts between the two reporting lines will be resolved through agreement by the WMC CFO [the administrative reporting line] and the OSU CCC [the functional reporting line]. Qualifications Experience: Minimum of 12 years of experience in information security, with at least five years in a significant leadership role. Baccalaureate degree or higher in information systems or related degree. Demonstrated experience in a large, complex organization, preferably within an academic medical center, or healthcare system. Proven track record of developing and implementing a successful, enterprise-level information security program. Certifications: Professional security management certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or an equivalent, is highly desirable. Deep expertise in information security principles, practices, and technologies. Strong knowledge of relevant legal and regulatory requirements (e.g., HIPAA). Excellent communication, negotiation, and interpersonal skills with the ability to articulate complex security concepts to technical and non-technical audiences. Demonstrated ability to build relationships, collaborate, and lead through influence across a decentralized enterprise. Strong business acumen to enable technology’s impact to support secure business objectives. Adaptability to Innovation: Proven ability to manage security implications of rapid innovation in clinical care, biomedical research, and education, including cloud computing, telehealth, and AI/ML. Organization and Contact The university is an equal opportunity employer, including veterans and disability. #J-18808-Ljbffr

Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer in Columbus, OH vacancy
  •  ...Chief Information Security Officer (CISO) About the Company Popular provider of enterprise resource planning & business management software Industry Computer Software Type Public Company Founded 1972 Employees 10,001+ Categories... 
    Suggested

    Confidential

    Worthington, OH
    22 hours ago
  •  ...the Ohio State University Wexner Medical Center with a dual report to the CISO of The Ohio State University, the WMC Chief Information Security Officer (WMC CISO) leads a department focused on security, risk management, compliance and security architecture for the clinical... 
    Suggested

    Wexner Medical Center

    Columbus, OH
    22 hours ago
  •  ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information Security... 
    Suggested

    Confidential

    Columbus, OH
    1 day ago
  •  ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup... 
    Suggested

    Confidential

    Columbus, OH
    1 day ago
  •  ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014... 
    Suggested

    Confidential

    Columbus, OH
    1 day ago
  •  ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories... 
    Remote work

    Confidential

    Columbus, OH
    4 days ago
  •  ...providers; ensure contract provisions address security, privacy, SLAs, and right-to-audit....  ...a timely manner.Proficient in Microsoft Office products including Outlook, Word,...  ...meetings. Job RequirementsBachelor’s degree in Information Systems, Computer Science, Business, or... 
    Contract work
    Work at office

    WesBanco

    Columbus, OH
    2 days ago
  •  ...Requirements:Physical Demand Level: S - Sedentary WorkWhat We’re Looking for:Education requirements are listed below:Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Business, Risk Management, Emergency Management, Engineering, or related field, or... 
    Full time
    Work experience placement

    American Electric Power

    Columbus, OH
    18 hours ago
  •  ...Chief Information & Technology Officer About the Company Leading business process outsourcing & work flow optimization company Industry...  ...Services Business Development Information Technology Security Information Technology & Services Specialties... 

    Confidential

    Columbus, OH
    10 hours ago
  •  ...infrastructure Manage telecom projects, upgrades, migrations, and vendor relationships Ensure high availability, performance, and security of voice and communication systems Oversee troubleshooting, incident resolution, and service delivery Develop and maintain telecom... 

    ComResource

    Columbus, OH
    22 hours ago
  •  ...Chief Impact Officer (CIO) About the Company International non-profit governing organization...  ...commercial fishing industry Industry Information Services Type Non Profit...  ...Specialties ocean conservation maritime security transparency data science... 
    Remote work
    Visa sponsorship

    Confidential

    Columbus, OH
    4 days ago
  • The Ohio State University Wexner Medical Center in Columbus, OH seeks a senior information security leader to serve as Chief Information Security Officer for the health system. You will drive risk management, policy, and security architecture across clinical, research,... 

    The Ohio State University

    Columbus, OH
    1 day ago
  • The Ohio State University Wexner Medical Center is seeking a Chief Information Security Officer to lead a comprehensive security program spanning strategy, governance, risk, compliance, and architecture across clinical, research, and academic operations. The CISO will... 

    The Ohio State University Wexner Medical Center

    Columbus, OH
    1 day ago
  •  ...Development, Director of Network Services, Enterprise Data Architect, Administratively the Director of Information Security Status: Exempt Objective The Chief Technology Officer (CTO) is responsible for ensuring a secure, stable, scalable, and future-ready technology... 

    KEMBA Financial Credit Union Inc.

    Columbus, OH
    3 days ago
  •  ...below additional details about this job.Job DescriptionCyber Incident Response, computer forensics, electronic discovery and information security. The primary purpose of this position is to conduct computer forensic investigations, data recovery and electronic discovery... 
    Contract work
    Immediate start

    idealforce

    Columbus, OH
    3 days ago
  • $128k - $216k

     ...Fintech and payments, and we move money and information in a way that moves the world. We...  ...of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay...  ...essential part of this role as in-person office experiences help you with your overall onboarding... 
    Full time
    Temporary work
    H1b
    Work at office
    Monday to Friday

    Fiserv

    Columbus, OH
    4 days ago
  •  ...DescriptionIDEALFORCE has a CONTRACT position available immediately for a IT Security Specialist(ITSS2) to join our customer in Columbus, OH. This...  ...specific responsibilities that include:-Monitor network and information system activity.-Respond to alerts (analyze, interpret,... 
    Contract work
    Immediate start

    idealforce

    Columbus, OH
    3 days ago
  • $105.4k - $207.8k

     ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this...  ...:Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent demonstrated experience... 
    Local area
    Visa sponsorship

    Deloitte

    Columbus, OH
    1 day ago
  • $105.4k - $207.8k

     ...Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to...  ...Qualifications Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related... 
    Local area
    Worldwide
    Visa sponsorship

    Deloitte

    Columbus, OH
    1 day ago
  • $105.4k - $207.8k

     ...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support...  ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation... 
    Local area
    Visa sponsorship

    Deloitte

    Columbus, OH
    1 day ago
  • $97.61k - $188.38k

     ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll...  ...configure, and deploy Saviynt.Understand complex business and information technology management processes. Execute advanced services and... 
    Local area
    Visa sponsorship

    Deloitte

    Columbus, OH
    1 day ago
  • OH0713 NW Bancshares HQJob DescriptionThe Divisional Chief Information Officer (Divisional CIO) serves as part of the Executive Leadership team...  ...strategy, delivery, modernization, support, resilience, security, and continuous improvement of technology capabilities supporting... 
    Full time
    Work at office

    Northwest Bank

    Columbus, OH
    2 days ago
  • $95.86k - $208.27k

     ...Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE),...  ..., state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment... 
    H1b
    Local area

    KPMG

    Columbus, OH
    4 days ago
  •  ...The Ohio State University Wexner Medical Center is seeking a Chief Information Security Officer (CISO) to lead information security, risk management, compliance, and security architecture for the clinical mission. The role reports to the CIDO and collaborates with the... 

    Jobleads-US

    Columbus, OH
    4 days ago
  •  ...Chief Technology Officer (CTO) About the Company Venture-backed fintech startup. Industry Accounting...  ...for ensuring the reliability, security, and scalability of the products, as...  ...problems with cutting-edge technology. Functions Engineering Information Technology... 

    Confidential

    Worthington, OH
    3 days ago
  •  ...Overview The Chief Customer Officer (CCO) reports to the President, Retail and is responsible for driving sustainable, profitable growth across all retail food channels by leading the company’s end-to-end customer strategy. As a member of the Retail Leadership Team... 
    Work at office
    Remote work

    The Marzetti Company

    Columbus, OH
    4 days ago
  •  ...donation across Central and Southeast Ohio. We are seeking a Chief Experience and Partnership Officer to help shape our organization’s future during a period...  ...to navigate conflict and influence change A data-informed, systems-oriented approach to stakeholder experience... 
    Work at office
    Local area
    Immediate start
    Afternoon shift

    Socket.dev

    Columbus, OH
    22 hours ago
  •  ...Deputy Chief Technology Officer (CTO) About the Company Prominent political organization Industry...  ...the Chief Technology Officer, Chief Security Officer, and Heads of Data &...  ...Technology Officer Functions Engineering Information Technology Confidential
    Remote work

    Confidential

    Columbus, OH
    2 days ago
  •  ...Deputy Chief Technology Officer (CTO) About the Company Top-tier investment bank Industry Investment Banking Type Public Company...  ...scenarios. Hiring Manager Title CIO/CTO Functions Engineering Information Technology Confidential

    Confidential

    Columbus, OH
    22 hours ago
  •  ...Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing in...  ...responsibilities. The position is pivotal in helping clients make informed leadership decisions and is suited to individuals who... 

    Confidential

    Columbus, OH
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Chief Information Security Officer. Be the first to apply!