ForgeApply · Job listing
Chief Information Security Officer
St. Charles Health System
See all 182 open roles at St. Charles Health System →
Tailor your resume for this St. Charles Health System job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for St. Charles Health System's site. Free trial, no card required.
About this role
Salary range: $176,675- $265,000/year
Relocation Assistance: This role offers in-state or out-of-state relocation assistance for candidates who have not worked at St. Charles Health System in the last year.
ST. CHARLES HEALTH SYSTEM JOB DESCRIPTION
TITLE: System Director, Information Security (CISO) REPORTS TO POSITION: SVP, Chief Information & Digital Officer DEPARTMENT: Information Security DATE LAST REVIEWED: August 2026
OUR VISION: Creating America’s healthiest community, together. OUR MISSION: In the spirit of love and compassion, better health, better care, better value OUR VALUES: Accountability, Caring and Teamwork
DEPARTMENT SUMMARY: The St. Charles Health System’s Information Security department identifies, assesses, reports, and helps to mitigate technical, physical, and administrative risks to St. Charles’ regulated and confidential information.
POSITION OVERVIEW: The System Director Information Security (CISO) collaborates internally and externally to identify, assess, report, and help mitigate risks to St. Charles’ physical and digital regulated and confidential information in alignment with business goals and objectives. This role leads the information security department and partners closely with IT, Privacy, Compliance, Internal Audit, HR, Legal, and other departments. The CISO develops strategy, policy, and oversees information security operations (e.g., network monitoring, threat intelligence, vulnerability management, penetration testing, data loss prevention, incident response, advisory services), third-party risk management, e-Discovery, information security risk management, awareness and education, program management, and governance. The CISO has demonstrated experience with the technical, administrative, and regulatory requirements and best practices relating to information security, privacy, and healthcare operations.
This position directly manages caregivers in the information security department.
ESSENTIAL FUNCTIONS AND DUTIES: Develops, implements, and oversees a strategic, enterprise-wide information security program to ensure the integrity, confidentiality, and availability of St. Charles’ regulated and confidential information and systems.
Identifies, evaluates, and reports on information security risks in a manner that meets compliance and regulatory requirements and aligns with the organization’s overall risk posture.
Establishes and facilitates information security governance through leadership and active participation in organizational governance bodies, including data governance, external data governance, technology governance, and safety governance committees.
Reports on the status of identified information security risks, provides regular updates on the evolving threat landscape, and secures executive approval for strategic initiatives to reduce St. Charles’ risk exposure.
Develops, maintains, and publishes current information security policies, standards, procedures, and guidelines.
Oversees enterprise information security risk management and mitigation activities to ensure timely and effective remediation.
Collaborates with executive leadership to define acceptable levels of information security risk and ensures alignment with organizational objectives.
Partners with the System Privacy Officer to conduct risk assessments and evaluations related to HIPAA Privacy and Security Rule compliance and the Health Industry Cybersecurity Practices.
Establishes and oversees cybersecurity risk frameworks specifically governing Internet of Medical Things (IoMT) devices, clinical networks, and biomedical integration.
Drives the adoption and continuous maturity of enterprise security frameworks, aligning operations with the NIST Cybersecurity Framework (CSF), NIST AI Risk Management Framework, and HITRUST standards.
Leads and directs a dedicated technical security team responsible for executing the following core operational functions:
Security Operations & Incident Response (SOC): • 24/7/365 security monitoring, threat hunting, log aggregation, and event correlation using SIEM/SOAR platforms.
• Rapid triage, containment, escalation, and post-incident root-cause analysis for security events across network, endpoint, and cloud environments.
Engineering & Architecture Implementation: • Design, deployment, and ongoing administration of Endpoint Detection & Response (EDR/XDR).
• Identity & Access Management (IAM) technical oversight, including privileged access management (PAM), multi-factor authentication (MFA), and directory service security controls.
Vulnerability Management & Offensive Security: • Continuous vulnerability scanning, patch verification, and risk-prioritized remediation tracking across clinical, enterprise, and infrastructure assets.
• Coordination and execution of internal/external penetration testing, red teaming exercises, and social engineering scenarios.
Data Loss Prevention (DLP) & Technical Privacy Controls: • Configuration and management of DLP agents, email security gateways, encryption tools, and data classification mechanisms to safeguard Protected Health Information (PHI) and corporate data.
• Medical Device & Endpoint Security:
• Technical discovery, isolation, and security patching for biomedical equipment, Internet of Medical Things (IoMT) hardware, and clinical workstation configurations.
Designs, implements, and manages organization-wide information security awareness and training programs for employees, contractors, and authorized system users.
Works closely with business units to facilitate information security risk assessment and management processes, engaging stakeholders across the organization to identify and manage residual risk.
Coordinates with the architecture team members to ensure security controls and strategies are aligned with enterpri
Tailor your resume for this St. Charles Health System role before you apply.
Tailor my resume for this jobSimilar jobs
- Chief Information Security Officer — Morganmorganjobsapplynow · Orlando, Florida, United States
- Chief Information Security Officer — Uline · Pleasant Prairie, WI | Milwaukee, WI | Waukegan, IL
- Chief Information Security Officer — Ext · Durham, North Carolina
- Chief Information Officer — University Of New Orleans · New Orleans, La
- Chief Information Security Officer (CISO) — Cape · New York, NY
- Chief Information Security Officer (CISO) — Hippo70 · Austin, TX / Morristown, NJ (hybrid)
- Chief Information Security Officer (CISO) — Cais · New York City
- Chief Information Security Officer (CISO) — Mastercontrol · Salt Lake City (Hybrid)
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)