This position is incentive eligible.
Introduction
Do you want to join an organization that invests in you as a Director of Information Protection Security and Risk? At HCA, you come first. HCA Healthcare has committed up to $300 million in programs to support our incredible team members over the course of three years.
Benefits
At HCA, we want to ensure your needs are met. We offer eligible colleagues an attractive benefit package that includes medical, wellbeing, dental and vision benefits along with some unique benefits including:
Learn more about Employee Benefits
You contribute to our success. Every role has an impact on our patients’ lives and you have the opportunity to make a difference. We are looking for a dedicated Director of Information Protection Security and Risk like you to be a part of our team.
Job Summary and Qualifications
The Director of Information Protection & Security (IPS) Risk Management leads the risk management function for IPS. In this critical leadership position, you will be responsible for developing and overseeing our organization's comprehensive cybersecurity risk management program. This role will be responsible for developing and implementing a robust cybersecurity risk management strategy aligned with industry best practices and evolving threats. To be successful in this role, the Director of Risk Management must be able to clearly communicate cyber risks to all levels of the organization.
This leader will be key in implementing a risk management program that results in the identification, prioritization, and reduction of cybersecurity and ensures compliance for all in-scope facilities. This trusted advisor will help raise the protection bar by building strong relationships with technical and non-technical stakeholders to make risk visible, facilitate well-informed decision, and drive accountability. The ability to clearly communicate and report cybersecurity risk, and manage organizational relationships, will be key to the success of this role. In addition, this role must be able to establish a outcome-driven metrics approach to risk management and utilize protection level agreements as a mechanism to establish risk thresholds.
This position is expected to promote a culture that supports operating with an acceptable level of risk, developing standardized risk management criteria including but not limited to threats, vulnerabilities, likelihood, impact, and maturity, establishing risk tolerance, planning risk analysis (e.g. Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining the risk register to prioritize risk reduction actions and activities is implemented. This position is also responsible for evolving the organization’s current risk treatment framework. This position is also responsible for collaborating with Information Security on the development, configuration, and implementation of the Risk Management Archer GRC application.
This position requires a candidate who can, with minimal guidance, analyze business requirements and processes, understand colleague behaviors, facilitate and lead meetings with key stakeholders within the organization, provide industry expertise and knowledge in the identification and mitigation of organizational risk, and enable decision making to support the adherence to industry standards and federal regulations.
The Director of IPS Risk Management provides guidance, direction, and mentorship to staff members to support the overall team goals and deliverables. A qualified candidate must be a highly motivated self-starter and be committed to delivering quality outcomes that meet team and organizational goals.
What you will do in this role:
Quality
Service
People
Growth
Finance
What qualifications you will need:
HCA Healthcare has been recognized as one of the World’s Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"Good people beget good people."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
At its founding in 1968, Nashville-based HCA was one of the nation's first hospital companies. Today, we are the nation's leading provider of healthcare services, a company comprised of locally managed facilities that includes about 165 hospitals and 115 freestanding surgery centers in 20 states and England and employing approximately 204,000 people. Approximately four to five percent of all inpatient care delivered in the country today is provided by HCA facilities. Richard M. Bracken serves as Chairman of HCA and R. Milton Johnson is the company's President and Chief Executive Officer.
HCA is committed to the care and improvement of human life and strives to deliver high quality, cost effective healthcare in the communities we serve. Building on the foundation provided by our Mission & Values, HCA puts patients first and works to constantly improve the care we give them by implementing measures that support our caregivers, help ensure patient safety and provide the highest possible quality. Investing in our communities is important to us. HCA typically invests about $1.5 billion annually to keep our facilities modern and up-to-date technologically and to expand and add services where needed. Focusing primarily on communities where the company is a leading healthcare provider, HCA selectively adds new facilities in order to better serve our communities.
And because two HCA founders were physicians, we value highly the strong relationships we've created with local physicians. We endeavor to provide them with a wide array of services and modern facilities in order to help them deliver the best possible care.