Chief Information Security Officer
Harding Hospital
Overview The Ohio State University Wexner Medical Center The Ohio State University Wexner Medical Center (WMC) is a proud part of one of the nation’s largest major comprehensive public research universities, serving more than 65,000 undergraduate, graduate and professional students. With nearly 41,000 full-time equivalent employees, Ohio State is Ohio’s fifth-largest employer. Scope of Position Reporting to the CIDO of the Ohio State University Wexner Medical Center with a dual report to the CISO of The Ohio State University, the WMC Chief Information Security Officer (WMC CISO) leads a department focused on security, risk management, compliance and security architecture for the clinical mission of Ohio State. Working closely with our university partners, the WMC CISO will engage and collaborate with various leaders in clinical operations, research, education, audit, legal and compliance and information systems on security initiatives. The WMC CISO oversees ongoing activities, programs, and projects that serve to protect WMC data confidentiality, integrity and availability while providing clinicians, students, patients, faculty, researchers, staff and vendors with secure and reliable access to systems and information. The WMC CISO ensures strategic alignment to the university on information security standards, controls, training, practices, and reporting. Responsibilities II. Duties and Responsibilities Strategy, Governance, and Risk Management (50%) Health System Security Strategy: Develop, champion, and execute a visionary, comprehensive, multi-year information security strategy and roadmap across all mission areas of WMC, leveraging the University Security Framework. Security Framework: Work in collaboration with University CISO to align on common standards, controls and practices, ensuring a cohesive security posture where systems, services and missions overlap. Oversee the development, enforcement and auditing of security policies, procedures, and standards for the health system. Enterprise Ownership and Tolerance: Oversee Security Risk Assessments (SRAs) and vulnerability management across clinical, research, administrative, and third-party environments for the Health System. Develop and prioritize risk mitigation and remediation strategies. Coordinate with the University CISO on a streamlined risk assessment process for technologies that impact both the Medical Center and the University. Report on the WMC’s cybersecurity risk appetite in partnership with executive leadership and proactively manage and report on the overall cyber risk posture, translating technical exposure into clear business impact to the C-suite and the board through established reporting under the university CISO. Regulatory Compliance: Ensure stringent adherence to all applicable laws and regulations, including but not limited to HIPAA/HITECH, 21 CFR Part 11, PCI DSS, state data privacy laws, and security mandates for research data and grant funding (e.g., CUI). Serves as the Security Officer to oversee implementation of HIPAA security regulations and to provide ongoing compliance monitoring and education on security. Emerging Technology Governance: Establish and lead emerging technology governance frameworks for AI, cloud, automation, and other next-generation technologies, ensuring alignment with risk management, cybersecurity strategy, regulatory requirements, and business objectives. Third-Party Risk Management (TPRM): Provide executive oversight of the Third-Party Risk Management program, ensuring vendor risks are assessed, governed, and aligned with enterprise security and compliance requirements. Oversee assessing and mitigating the security risks posed by vendors, business associates, and supply chain partners in alignment with University standards and frameworks where possible. Business Continuity / Disaster Recovery: Provide executive oversight and strategic direction for enterprise Business Continuity and Disaster Recovery (BC/DR) programs, ensuring governance, resilience, regulatory compliance, and alignment with organizational risk management objectives to maintain and restore mission-critical operations during disruptions in alignment with University standards and frameworks where possible. Security Operations and Leadership III. Security Operations and Leadership (30%) Security Operations Center (SOC) Oversight: Oversee the day-to-day operations of the information security function, including threat intelligence, security monitoring, Security Information and Event Management (SIEM), and vulnerability management across on-premise, cloud, and hybrid environments in alignment with University standards and tools where possible. Incident Response: Own the Computer Security Incident Response and Reporting (CSIRR) function, leading the coordination, containment, investigation, and recovery efforts for all security incidents and breaches, and fulfilling regulatory breach notification requirements. Security Architecture and Consulting: Provide authoritative security consultation for the design and implementation of new systems (including EHR systems, clinical IoT, and cloud services) and review of existing systems, promoting security-by-design principles. Access Management and Controls: Oversee the IT Access Management function, including the alignment to advanced Identity and Access Management (IAM) and Privileged Access Management (PAM) strategies consistent with a Zero Trust model established by the University CISO. Culture, Talent, and Collaboration IV. Culture, Talent, and Collaboration (20%) Executive Collaboration: Collaborate directly and continuously with the University CISO, CIDO, and other executive and departmental leaders to align security initiatives with broad institutional and clinical goals. Team Leadership: Lead, manage, mentor, and coach a diverse, high-performing team of information security professionals, fostering a culture of continuous learning, accountability, and excellence. Security Awareness and Education: Advise Health Systems senior leadership on security risks and strategy. Drive a mandatory, ongoing security education and awareness program for all Health Systems faculty, staff, researchers, and students to effectively reduce the "human element" risk in a decentralized academic environment. Communication: Serve as the visible, articulate internal and external champion for information security, possessing the ability to engage diverse stakeholders—from technical staff and researchers to clinicians. Other duties as assigned. Organizational Expectations Practices within the medical center’s policies and procedures. Adheres to the mission and values statements as demonstrated through positive patient/guest relations, positive and effective interactions with staff and by formulating and meeting developmental goals. Given the joint reporting relationship of the position, the following have been outlined to ensure understanding and clarity of the following: Performance evaluations of the position will be resolved through joint meeting and discussion of the WMC CIDO and the University CISO, The authority of the WMC CIDO takes precedence on budget and staffing; authority of University CISO takes precedence on risk and strategic decisions, and Conflicts between the two reporting lines will be resolved through agreement by the WMC CFO [the administrative reporting line] and the OSU CCC [the functional reporting line]. Qualifications Experience: Minimum of 12 years of experience in information security, with at least five years in a significant leadership role. Baccalaureate degree or higher in information systems or related degree. Demonstrated experience in a large, complex organization, preferably within an academic medical center, or healthcare system. Proven track record of developing and implementing a successful, enterprise-level information security program. Certifications: Professional security management certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or an equivalent, is highly desirable. Deep expertise in information security principles, practices, and technologies. Strong knowledge of relevant legal and regulatory requirements (e.g., HIPAA). Excellent communication, negotiation, and interpersonal skills with the ability to articulate complex security concepts to technical and non-technical audiences. Demonstrated ability to build relationships, collaborate, and lead through influence across a decentralized enterprise. Strong business acumen to enable technology’s impact to support secure business objectives. Adaptability to Innovation: Proven ability to manage security implications of rapid innovation in clinical care, biomedical research, and education, including cloud computing, telehealth, and AI/ML. Organization and Contact The university is an equal opportunity employer, including veterans and disability. #J-18808-Ljbffr
- ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information Security...Suggested
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...Suggested
- ...Field Chief Information Security Officer (CISO) About the Company Prominent provider of cloud-based email management services Industry Information Technology and Services Type Public Company Founded 2003 Employees 1001-5000 Categories Accounting...SuggestedWork at office
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...Suggested
- ...Deputy Chief Information Security Officer (CISO) About the Company Industry-leading cybersecurity platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2019 Employees 201-500 Funding $200+ million Categories...Suggested
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...providers; ensure contract provisions address security, privacy, SLAs, and right-to-audit.... ...a timely manner.Proficient in Microsoft Office products including Outlook, Word,... ...meetings. Job RequirementsBachelor’s degree in Information Systems, Computer Science, Business, or...Contract workWork at office
$196k - $294k
...cybersecurity leader redefining how organisations secure human risk. Our AI-powered, API-enabled... ...North America, Mimecast has established offices in Lexington (Massachusetts),... ...backgroundDepth of experience in enterprise information security, with 10+ years in a leadership...Full timeWork at officeLocal areaImmediate startWorldwide2 days per week- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
$116.26k - $151.13k
...and supports digital investigations utilizing endpoint images, security analytics, and user activity monitoring across a broad range... ...evidence handling proceduresExperience with data classification, information protection, data loss prevention (DLP), and sensitive data...Full timeWork experience placement- ...Cybersecurity Assessments And Exercises Vice President Drive the security of critical banking applications and platforms through hands-on offensive testing. As an Assessments & Exercises Vice President in the Cybersecurity and Technology Controls organization, you...
- ...Development, Director of Network Services, Enterprise Data Architect, Administratively the Director of Information Security Status: Exempt Objective The Chief Technology Officer (CTO) is responsible for ensuring a secure, stable, scalable, and future-ready technology...
$105.4k - $207.8k
...Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to... ...Qualifications Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related...Local areaWorldwideVisa sponsorship- OH0713 NW Bancshares HQJob DescriptionThe Divisional Chief Information Officer (Divisional CIO) serves as part of the Executive Leadership team... ...strategy, delivery, modernization, support, resilience, security, and continuous improvement of technology capabilities supporting...Full timeWork at office
$105.4k - $207.8k
...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support... ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation...Local areaVisa sponsorship- ...DescriptionIDEALFORCE has a CONTRACT position available immediately for a IT Security Specialist(ITSS2) to join our customer in Columbus, OH. This... ...specific responsibilities that include:-Monitor network and information system activity.-Respond to alerts (analyze, interpret,...Contract workImmediate start
- ...below additional details about this job.Job DescriptionCyber Incident Response, computer forensics, electronic discovery and information security. The primary purpose of this position is to conduct computer forensic investigations, data recovery and electronic discovery...Contract workImmediate start
$95.86k - $208.27k
...Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE),... ..., state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment...H1bLocal area$122k - $240.5k
...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this... ...:Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent demonstrated experience...Local areaVisa sponsorship- ...Regional Field Chief Technology Officer (CTO) About the Company Globally recognized provider of automated solutions for securing & managing open source software Industry Computer... ...to translate complex technical information into clear narratives for both technical...
- ...Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing in... ...responsibilities. The position is pivotal in helping clients make informed leadership decisions and is suited to individuals who...
- ...Deputy Chief Technology Officer (CTO) About the Company Top-tier investment bank Industry Investment Banking Type Public Company... ...scenarios. Hiring Manager Title CIO/CTO Functions Engineering Information Technology Confidential
- ...Deputy Chief Technology Officer (CTO) About the Company Prominent political organization Industry... ...the Chief Technology Officer, Chief Security Officer, and Heads of Data &... ...Technology Officer Functions Engineering Information Technology ConfidentialRemote work
- ...Chief Technology Officer (CTO) Reports to: President/CEO Supervises: Director of Application Development, Director of Network Services... ...Enterprise Data Architect, Administratively the Director of Information Security Status: Exempt Objective The Chief Technology...Work at officeRemote work
- ...Information Security ManagerWe are seeking an Information Security Manager — a hands-on player-coach who will both run the security program and do the operational security work. This is the senior owner of CAG's information-security function: you set the roadmap, governance...Permanent employmentInterim roleInternshipSummer internship
$127.5k - $204k
...Fintech and payments, and we move money and information in a way that moves the world. We... ...of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay... ...essential part of this role as in-person office experiences help you with your overall onboarding...Full timeTemporary workH1bWork at officeMonday to Friday$134.5k - $265.1k
...automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to... ...:Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience...Local areaVisa sponsorship- ...imagine.ABOUT ACCENTURE SECURITYAccenture Security helps organizations prepare, protect,... ...include but are not limited to the specific office location, role, skill set, and level of... ...holidays, and paid time off. See more information on our benefits here:U.S. Employee Benefits...Full timeWork experience placementLive inWork at officeLocal area
- ...Chief Technology Officer (CTO) About the Company Emerging defense technology company Industry... ...inference frameworks and edge acceleration technologies. Security clearance or eligibility is also a plus. Functions Engineering Information Technology Confidential
- ...Chief Technology Officer (CTO) About the Company Pioneering media company focused on news & educational information about financial technology & cryptocurrency Industry Newspapers... ...team, and ensuring the platform is secure, compliant, and ready for enterprise...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer. Be the first to apply!
- sr information security engineer Columbus, OH
- information technology security engineer Columbus, OH
- data center security officer Columbus, OH
- director information security Columbus, OH
- entry level information security analyst Columbus, OH
- information security Columbus, OH
- senior information security analyst Columbus, OH
- information security compliance analyst Columbus, OH
- information security lead Columbus, OH
- information systems security officer


