| Location | Knoxville, TN |
| Industry | Healthcare Services |
| Company Size | 5,000 to 9,999 employees |
| Website | https://www.utmedicalcenter.org/ |
Position Summary:
The Director of Cybersecurity is a senior leadership team member responsible for leading, managing, and continuously improving the organization's cybersecurity program across a complex enterprise environment. Reporting directly to the Chief Information Security Officer (CISO), this role serves as the operational leader of cybersecurity and is responsible for executing the organization's security strategy, reducing cyber risk, protecting critical assets, and ensuring the resilience of business and clinical operations.
The Director of Cybersecurity provides leadership across cybersecurity Operations, Incident Response, Vulnerability Management, Security Engineering, Identity and Access Management (IAM), Governance, Risk and Compliance, Third-Party Risk Management, and Security Training and Awareness.
Cybersecurity Program Leadership
Lead the day-to-day management and execution of the enterprise cybersecurity program.
Develop, implement, and maintain cybersecurity strategies, roadmaps, policies, standards, and procedures.
Serve as a strategic advisor to the CISO.
Security Operations & Threat Management
Provide leadership and oversight of Security Operations Center (SOC) functions.
Lead threat detection, incident response, and crisis management activities.
Security Engineering & Infrastructure Protection
Vulnerability & Exposure Management
Identity & Access Management
Risk Management & Governance
Regulatory Compliance & Audit Support
Cloud Security & Emerging Technology
Third-Party Risk Management
Leadership & Team Development
Position Qualification:
Education
Required
Minimum 12 years of progressive cybersecurity experience.
Minimum 7 years of progressive leadership experience managing cybersecurity teams, with at least 3 years in a senior leadership (Manager or above) position.
Experience in regulated or mission-critical environments.
Experience developing cybersecurity strategy, policy, and governance programs.
Experience developing and managing operating and capital budgets.
Experience presenting cybersecurity risks and controls to leadership, partners, and other stakeholders.
Experience working with industry recognized cybersecurity frameworks including NIST, HITRUST, and CIS.
CISSP or CISM certification.
Preferred
Master's Degree in Cybersecurity, Information Assurance, Business or other related field.
Experience in Academic Health System or other complex healthcare environment
CCSP, CRISC, CISA, CGRC, GIAC certifications, cloud security certifications, TOGAF, SABSA.
Located in Knoxville, Tennessee, The University of Tennessee Medical Center, has a rich history in the East Tennessee community of providing patient-centered care and remaining at the forefront of research, technology and treatments. UT Medical Center attributes its well-respected standing within the community to the exceptional people that dedicate themselves to patient care excellence. The hospital serves as a referral center for Eastern Tennessee, Southeastern Kentucky and Western North Carolina. It is the region’s academic medical center, Magnet® recognized hospital and Level I Trauma Center.