University of Tennessee Medical Center logo

Director - Cyber Security

    Highlights

    Reporting directly to the Chief Information Security Officer (CISO), this role serves as the operational leader of cybersecurity and is responsible for executing the organization's security strategy, reducing cyber risk, protecting critical assets, and ensuring the resilience of business and clinical operations. The Director of Cybersecurity provides leadership across cybersecurity Operations, Incident Response, Vulnerability Management, Security Engineering, Identity and Access Management (IAM), Governance, Risk and Compliance, Third-Party Risk Management, and Security Training and Awareness.

    Numbers & Facts

    LocationKnoxville, TN
    IndustryHealthcare Services
    Company Size5,000 to 9,999 employees
    Websitehttps://www.utmedicalcenter.org/

    Description

    Position Summary:

    The Director of Cybersecurity is a senior leadership team member responsible for leading, managing, and continuously improving the organization's cybersecurity program across a complex enterprise environment. Reporting directly to the Chief Information Security Officer (CISO), this role serves as the operational leader of cybersecurity and is responsible for executing the organization's security strategy, reducing cyber risk, protecting critical assets, and ensuring the resilience of business and clinical operations.

    The Director of Cybersecurity provides leadership across cybersecurity Operations, Incident Response, Vulnerability Management, Security Engineering, Identity and Access Management (IAM), Governance, Risk and Compliance, Third-Party Risk Management, and Security Training and Awareness.

    Cybersecurity Program Leadership

    • Lead the day-to-day management and execution of the enterprise cybersecurity program.

    • Develop, implement, and maintain cybersecurity strategies, roadmaps, policies, standards, and procedures.

    • Serve as a strategic advisor to the CISO.

    Security Operations & Threat Management

    • Provide leadership and oversight of Security Operations Center (SOC) functions.

    • Lead threat detection, incident response, and crisis management activities.

    Security Engineering & Infrastructure Protection

    • Direct security engineering activities supporting enterprise infrastructure, cloud services, applications, and data platforms.

    Vulnerability & Exposure Management

    • Lead enterprise vulnerability management and attack surface reduction initiatives.

    Identity & Access Management

    • Provide executive oversight of IAM capabilities including Multi-factor Authentication (MFA), Privileged Access Management (PAM), Single Sign On (SSO), and Identity Governance and Administration (IGA).

    Risk Management & Governance

    • Lead cybersecurity risk assessment, treatment, and reporting activities.

    Regulatory Compliance & Audit Support

    • Support audits, regulatory reviews, and compliance requirements.

    Cloud Security & Emerging Technology

    • Oversee security governance for cloud platforms and emerging technologies.

    Third-Party Risk Management

    • Lead vendor management and third-party cybersecurity risk assessments.

    Leadership & Team Development

    • Lead, mentor, and develop cybersecurity team members.

    Position Qualification:

    Education

    • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, Engineering, or related field.

    Required

    • Minimum 12 years of progressive cybersecurity experience.

    • Minimum 7 years of progressive leadership experience managing cybersecurity teams, with at least 3 years in a senior leadership (Manager or above) position.

    • Experience in regulated or mission-critical environments.

    • Experience developing cybersecurity strategy, policy, and governance programs.

    • Experience developing and managing operating and capital budgets.

    • Experience presenting cybersecurity risks and controls to leadership, partners, and other stakeholders.

    • Experience working with industry recognized cybersecurity frameworks including NIST, HITRUST, and CIS.

    • CISSP or CISM certification.

    Preferred

    • Master's Degree in Cybersecurity, Information Assurance, Business or other related field.

    • Experience in Academic Health System or other complex healthcare environment

    • CCSP, CRISC, CISA, CGRC, GIAC certifications, cloud security certifications, TOGAF, SABSA.

    About Company

    Located in Knoxville, Tennessee, The University of Tennessee Medical Center, has a rich history in the East Tennessee community of providing patient-centered care and remaining at the forefront of research, technology and treatments. UT Medical Center attributes its well-respected standing within the community to the exceptional people that dedicate themselves to patient care excellence. The hospital serves as a referral center for Eastern Tennessee, Southeastern Kentucky and Western North Carolina. It is the region’s academic medical center, Magnet® recognized hospital and Level I Trauma Center.

    Similar Jobs

    See more jobs