| Location | Irvine, California |
| Job Type | Full-time |
| Salary | $169,000–$227,000 Per Year |
Now is the time to join PDS Health. You will have opportunities to learn new skills from our team of experienced professionals. If you're ready to take your career to the next level and gain valuable experience, apply today!
Overview:Reporting to the VP, IT & Chief Information Security Officer (CISO), the Director, Information Security (Operations) is responsible for the strategy, execution, and continuous improvement of cybersecurity operations across the PDS Health enterprise – spanning networks, endpoints, cloud and SaaS environments, applications, AI systems, all web and digital assets, and people. This leader directs the capabilities that prevent, detect, investigate, contain, and recover from cyber threats across a large, distributed healthcare ecosystem that includes supported dental and medical practices, national support centers, clinical and business applications, connected devices, and third-party partners. This is a critical, future-focused leadership role. Beyond defending the organization against existing threats and vulnerabilities, the Director must anticipate and prepare PDS Health for the next generation of risk including threats introduced by artificial intelligence, automation, expanding cloud adoption, citizen development and low-code platforms, and a rapidly growing digital footprint. The incumbent will build a resilient, intelligence-led security operations function that evolves ahead of the threat landscape while enabling innovation, growth, and the continuity of patient care. Healthcare experience is essential. The Director will lead risk assessments and control validation against HIPAA/HITECH, ISO/IEC 27001, NIST CSF, and PCI DSS; ensure the protection of electronic protected health information (ePHI) and sensitive personal information; and work hands-on with Legal, Compliance, Privacy, and Risk Management stakeholders to protect the confidentiality, integrity, and availability of critical PDS Health information and information assets in a commercially sensible, risk-based manner.
Responsibilities
Develop, implement, enforce, and monitor a comprehensive, intelligence-led security program covering networks, endpoints, cloud and SaaS services, applications, AI systems, web and digital assets, and the human layer.
Maintain effective 24x7 security monitoring, triage, escalation, and response coverage through the right combination of internal teams, automation, and managed security services; establish service-level objectives, playbooks, quality controls, and clear handoffs across security and IT operations.
Direct enterprise incident response and cyber crisis management for ransomware, identity compromise, data exposure, business email compromise, cloud and supply-chain events, and threats affecting clinical operations; lead tabletop and technical simulation exercises with executive, legal, privacy, clinical, and business continuity stakeholders; ensure root-cause analysis results in assigned and verified corrective actions.
Advance risk-based detection engineering, threat intelligence, and proactive threat hunting mapped to adversary behaviors, critical business services, identity pathways, and known control gaps.
Lead a risk-based vulnerability, exposure, and attack-surface management program that prioritizes exploitability, asset criticality, and clinical impact – not severity scores alone, with transparent ownership, remediation targets, and governance across infrastructure, applications, cloud, endpoints, medical and dental technology, and third parties.
Establish and operate the security program for AI systems: ensure every AI system has named, accountable ownership; require documented risk and impact assessments before deployment; enforce human oversight for high-impact decisions; and implement post-deployment monitoring for drift, misuse, and abuse. Defend the organization against AI-enabled threats, including AI-driven phishing and social engineering, deepfakes, data poisoning, and model manipulation.
Establish security guardrails and governance for automation, robotic process automation, and citizen development, enabling low-code/no-code innovation while managing the risks of unmanaged applications, data flows, and integrations.
Oversee cloud and SaaS security operations, including posture management, secure configuration, workload protection, and identity threat detection across multi-cloud and hybrid environments.
Direct application and web/digital asset security, including secure development lifecycle practices, web application protection, external attack-surface management, and penetration testing and control validation.
Own the human layer of defense: security awareness training, phishing simulation, and insider-risk programs and campaigns across all PDS Health team members and supported practices.
Lead and source risk assessments, audits, and security incident investigations; conduct and oversee assessments against HIPAA, HITRUST CSF, ISO/IEC 27001, NIST, and PCI DSS, and support related certification, attestation, and audit activities for internal and external (third-party vendor and supplier) environments.
Own the operational effectiveness and lifecycle strategy for security platforms, including SIEM, SOAR and automation, endpoint and network detection and response, email security, threat intelligence, case management, and vulnerability management; drive automation where it improves speed and consistency while retaining human review for high-impact actions and patient-care-sensitive environments.
Embed patient safety, care continuity, and recovery requirements into security decisions; partner with business continuity, disaster recovery, infrastructure, and clinical leaders to validate isolation, restoration, and recovery of critical services.
Translate operational telemetry into defensible performance, risk, and resilience measures for executive leadership, governance committees, auditors, and business owners; escalate material risk clearly and promptly with business impact, options, and a recommended course of action.
Develop and manage operating and capital budgets; lead vendor selection, performance management, and renewal decisions for security operations partners and platforms, connecting investments to measurable risk reduction.
Recruit, coach, and retain a high-performing, diverse security team; build technical and leadership depth, succession plans, accountable, learning-oriented operating culture.
Research and leverage security trends, emerging threats, new technologies to create business value consistent with the company's need to balance growth expectations with risk.
Performs other duties and/or responsibilities as assigned.
Ensures compliance with all policies and standards, as well as state, federal and other regulatory bodies.
This is not intended to be a comprehensive list of the duties and responsibilities of the position and the duties and responsibilities may change.
Qualifications
Bachelor’s Degree in Arts/Sciences (BA/BS) Cybersecurity, IT / Information Security, Computer Science, Engineering, or a related discipline, equivalent progressive experience will be considered.
10+ years of progressive experience in security operations, information security, technology risk, or security engineering in an enterprise environment.
5+ years in a security leadership position.
Healthcare industry experience, including protecting ePHI and securing clinical environments, and demonstrated ability to conduct and lead risk assessments against HIPAA/HITECH, HITRUST CSF, ISO/IEC 27001, PCI-DSS, and NIST frameworks.
Two or more information security certifications such as CISSP, CISM, CISA, HCISPP, or equivalent.
Demonstrated leadership of significant cyber incidents and cross-functional response involving executive stakeholders, technical teams, legal or external stakeholders.
Experience operating security services across cloud, SaaS, endpoint, identity, network, application, and third-party dependencies in a large, complex, multi-site enterprise.
Working knowledge of securing or governing AI systems, automation platforms, and low-code/no-code (citizen development) environments, and of the threat landscape these technologies create.
Experience across the security operations lifecycle – vulnerability, patch, and security incident management – and the
IT service lifecycle (change, release, incident, and problem management). The ability to communicate clearly with audiences, ranging from operational staff to senior executives, is required.
The ability to communicate clearly with audiences, ranging from operational staff to senior executives.
Preferred
Master’s degree in Arts/Sciences (MA/MS) Cybersecurity, IT / Information Security, Computer Science, Engineering, or a related discipline.
Experience supporting an ISO/IEC 27001-certified information security management system, HITRUST-certified or HITRUST-aligned environment, or formal control assurance program.
One or more risk, cloud, or specialized certifications such as CRISC, CCSP, HCISPP, GIAC (incident response, forensics, or security operations), or equivalent.
Experience with enterprise electronic health records, clinical applications, connected medical or dental technologies, and mixed modern and legacy environments.
Experience building or transforming a security operations center, managing detection and response relationship, incident response program, or enterprise exposure management capability.
Working knowledge of security management tooling for SIEM/SOAR, endpoint and network detection and response, patch and vulnerability management, identity threat detection, and cloud security posture management.
Knowledge/Skills/Abilities
Excellent interpersonal, oral, and written communication skills, including the ability to brief executives and explain technical risks in direct, business-relevant language.
Future-oriented and strategic: anticipates how AI, automation, cloud, and citizen development will reshape the threat landscape and positions the organization ahead of it.
Decisive under pressure makes timely, risk-informed decisions with incomplete information, communicates uncertainty honestly, and adjusts quickly as facts change.
Technically credible: sufficient depth to evaluate architecture, challenge technical conclusions, and guide teams through complex events without serving as the primary administrator of every platform.
Detail oriented, organized, process focused, proactive, and customer service focused; creates clear ownership, repeatable processes, and measurable follow-through without unnecessary bureaucracy.
Interpersonal and collaboration skills to partner effectively with internal business partners, clinical teams, vendors, and consultants, with the ability to be both directive and collaborative as the situation requires.
Ability to identify measures or indicators of performance and the actions needed to improve or correct performance relative to goals.
Ability to evaluate technology solutions using logic and reasoning to identify the strengths and weaknesses of alternative solutions, conclusions, or approaches to problems.
Ability to comprehend, organize, and synthesize complex data, identify issues and trends, and develop and implement solutions to achieve management objectives.
Self-motivated, reliable individual, capable of working independently as well as part of a team; models integrity, accountability, and sound judgment, especially during high-pressure events.
Benefits
PDS Health is an Equal Opportunity Employer. We celebrate diversity and are united in our mission to create healthier and happier team members.
Salary Information: $169,000.00-$227,000.00 / Annually