
Business Information Security Lead
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States.
• Consult on critical business initiatives, ensuring comprehensive identification and management of risks.
• Implement the security program with Value Stream partners by identifying and mitigating risks in accordance with security policies and standards.
• Comprehend business requirements and offer security expertise to inform decision-making and strategic roadmaps.
• Clarify the necessity of security measures and the potential impacts of regulatory changes or cyber-attacks.
• Serve as the primary security contact for the Value Stream, facilitating escalation for significant issues.
• Conduct audits, evaluate risks, and manage or enforce remediation of findings from security assessments, penetration tests, and internal evaluations.
• Deliver visibility into security compliance through metrics, benchmarking, and vulnerability guidance.
• Present monthly prioritized analyses of gaps, remediation strategies, and achievements to the Value Stream Lead.
• Mentor Product Teams on the maturity and effective usage of security tools and information.
• Communicate impacts to Value Stream partners during discussions on strategy and roadmap with the Information and Cyber Security Team.
• Collaborate with internal teams, auditors, vendors, managed security services, and professional service providers.
• Travel as required for business purposes.
• Minimum of 5+ years of experience in information security.
• Extensive foundational knowledge across information and cybersecurity domains, particularly in security risk management and application security.
• Familiarity with frameworks such as PCI, HIPAA, SOX, NIST CSF, ISO 27001, CIS, and others.
• Proven ability to build positive relationships across various business areas.
• Capability to work independently and make decisions aligned with policy.
• Experience in measuring and tracking cybersecurity risks, issues, and exceptions.
• Proficient in presenting complex security topics to diverse audiences, including senior technical leaders.
• Ability to advise, collaborate, and function effectively in a team setting.
• Skill in influencing without formal authority.
• Experience in executing security compliance plans, vulnerability management programs, risk management lifecycles, and/or security assessment/governance processes.
• Bachelor’s degree from an accredited institution or equivalent professional experience is required.
• Experience in developing, measuring, and tracking key performance metrics, ideally in the field of cybersecurity.
• Highly organized, efficient, and detail-oriented.
• Proven track record in developing resources, mentoring, and providing career development guidance.
• Strong written and verbal communication abilities.
• Proactive in self-development and knowledgeable about evolving threats, security trends, best practices, and regulatory requirements.
• Preferred but not mandatory: SANS GSEC, GCIA or similar certification, CISSP.
• Eligibility for an annual incentive plan bonus.
• Health insurance coverage.
• Pre-tax spending accounts.
• Retirement benefits.
• Paid time off.
• Short-term disability coverage.
• Long-term disability coverage.
• Employee stock purchase plan.
• Life insurance benefits.
• Flexible remote work arrangement.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.