Director of SecOps/CISO - San Francisco, United States - ConsultNet

    Default job background
    Permanent Technology / Internet
    Description
    The Director of Security & IT Operations (SecOps) is responsible for leading all Information Security and IT operations of the company, including development, implementation and review of information security & IT Operations policies, procedures, and regulations. The Director of SecOps will be charged with safeguarding all systems, PHI and intellectual property utilizing the most up to date tools and techniques and have the ability to lead and support compliance with and achievement of industry certifications (HITRUST, SOC 2, etc.).

    PRIMARY ROLE AND RESPONSIBILITIES:
    Security
    • Build and lead a team of security and infrastructure professionals, attracting and retaining high-performers and fostering a collaborative culture.
    • Provide guidance, mentorship, and professional development opportunities to team members, promoting their growth and success.
    • Establish and maintain effective communication channels to ensure seamless collaboration across teams and departments.
    • Develop security strategy and collaborate with other departments to ensure proper execution protecting information assets without detriment to profitability or productivity; directing system control development and access management, monitoring, control and evaluation
    • Implement robust data privacy and security measures to safeguard sensitive patient health information
    • Establish enterprise security standards through architecture, policy, and training
    • Select, implement, and maintain security tooling to support our security strategy
    • Lead the attainment, and renewal of existing industry certifications or client required security assessments in a timely, accurate manner including SOC2, and HITrust
    • Oversee and support responding to client security assessments
    • Lead risk management, security incident response programs and procedures; Conduct periodic security audits and investigate breaches
    • Integrate security into every stage of the Development pipeline providing teams with tools and resources at each phase to create safe and secure code
    • Monitors and recommends improvements to security, compliance, and privacy environment

    Infrastructure & IT Operations
    • Oversee the design, development, and maintenance of our cloud infrastructure, ensuring scalability, reliability, and security in accordance with AWS's Well Architected Framework
    • Continuously monitor and optimize system performance, leveraging data analytics and performance metrics to drive improvements.
    • Lead Disaster Recovery and Data Backup planning, analysis, implementation, testing and execution
    • Implement and oversee IT Service Management (ITSM) processes to ensure that incidents, service requests, problems, changes, and IT assets in addition to other aspects of IT services are managed in a streamlined way
    • Develop and improve our security and infrastructure technical practices including Infrastructure as Code (IaC), automation, DevSecOps, and CI/CD.
    Join the Tekne revolution. Specializing in direct hire placements, Tekne operates in collaboration with ConsultNet, a leading national IT staffing and solutions provider. Together, we deliver unparalleled services to a diverse range of companies, from startups to midmarket and Fortune 1000 enterprises across North America. Tekne takes a proactive approach to recruiting, ensuring the perfect match for your team. By leveraging our extensive network and industry expertise, the hiring process is streamlined, connecting clients with skilled professionals who possess the right blend of technical prowess and cultural fit.
    Over the past two years, we have successfully secured placements for more than 1,500 consultants, through contract, contract-to-hire, or direct placement. Recognizing that effective communication is key to finding the right job that aligns with skills and career aspirations, Tekne emphasizes not just the work it does, but how it approaches the work. Client more at .