Skip to content

Open nowPosted 2 days ago

Chief Information Security Off

AtlantiCare254 open roles

Where
Egg Harbor Township, NJ, United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowChief Information Security OffAtlantiCare · Egg Harbor Township, NJ, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on AtlantiCare's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. AtlantiCare postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 2 days ago

AtlantiCare median: 3 days open

The posting

Job Description

POSITION SUMMARY

The Chief Information Security Officer (CISO) is the enterprise executive accountable for protecting AtlantiCare’s patients, workforce, data, clinical operations, and reputation from cyber risk. Reporting to the EVP, Chief Information and Digital Officer, the CISO sets the vision, strategy, governance, and operating model for information security and cyber resilience across the health system. This leader translates complex threats, vulnerabilities, and regulatory obligations into clear business and patient-safety risk decisions for executive leadership and the Board.

The CISO leads the enterprise Information Security Program and team; establishes policy, architecture, controls, metrics, and accountability; and ensures readiness to prevent, detect, respond to, and recover from cyber incidents. Working across clinical, operational, technology, biomedical, legal, privacy, compliance, audit, emergency management, and vendor partners, the CISO embeds security by design while enabling AtlantiCare’s strategic, digital, cloud, data, and AI priorities. The role is both strategic and operational and requires sound judgment, calm leadership, executive presence, and the ability to influence outcomes across a complex, highly regulated environment.

Responsibilities

KEY RESPONSIBILITIES

  • Enterprise strategy and governance: Develop and execute a multi-year information security and cyber resilience strategy, roadmap, operating model, and budget aligned with AtlantiCare’s strategic plan, enterprise risk appetite, and technology priorities.
  • Executive and Board advisory: Serve as the principal cyber risk advisor to executive leadership and the Board, presenting the organization’s risk posture, material threats, control maturity, investment priorities, risk-acceptance decisions, and program performance in clear business and patient-safety terms.
  • Risk ownership and accountability: Establish governance that enables business and technology leaders to identify, understand, mitigate, accept, and document cyber risk at the appropriate level.
  • Security program leadership: Lead the enterprise Information Security Program and ensure consistent, high-quality execution across governance, risk, compliance, architecture, engineering, operations, incident response, awareness, and third-party risk.
  • Team and partner leadership: Recruit, develop, motivate, and retain a high-performing security team; set clear accountabilities and performance expectations; and oversee managed security service providers, consultants, and dotted-line resources.
  • Policy and control framework: Maintain a practical, risk-based framework of policies, standards, procedures, and controls aligned with applicable laws, regulations, contractual obligations, and recognized practices including NIST CSF 2.0, HHS 405(d) HICP, and the HHS Healthcare and Public Health Cybersecurity Performance Goals.
  • Regulatory assurance: Partner with Legal, Compliance, Privacy, Audit, and operational leaders to maintain compliance with HIPAA, HITECH, the HIPAA Security Rule, and applicable federal and state requirements; oversee assessments, remediation plans, evidence, and regulatory readiness.
  • Security architecture and engineering: Establish security-by-design requirements across identity, network, endpoint, cloud, applications, data, integration, and emerging technologies, advancing zero trust, multifactor authentication, least privilege, privileged access management, segmentation, encryption, and secure configuration.
  • Clinical and medical-device security: Partner with clinical, Biomedical Engineering, Facilities, and operational leaders to protect connected medical devices and clinical technology through accurate inventories, risk-based segmentation, vulnerability management, lifecycle planning, downtime safeguards, and security requirements in procurement.
  • Threat and vulnerability management: Maintain awareness of the external threat environment and direct threat intelligence, exposure management, penetration testing, vulnerability prioritization, and remediation across technology and business owners.
  • Incident response and crisis leadership: Lead the response to significant cyber incidents, including ransomware, data compromise, and extended technology downtime; coordinate executive, clinical, operational, legal, privacy, communications, insurance, and law-enforcement activities; and ensure timely breach assessment, notification, and lessons learned.
  • Cyber resilience and recovery: Partner with Technology, Emergency Management, and clinical operations to align disaster recovery, business continuity, backup protection, recovery testing, downtime procedures, and tabletop exercises with critical business and patient-care priorities.
  • Third-party and supply-chain risk: Establish a lifecycle process to assess and manage cyber risk associated with vendors, business associates, cloud providers, software, services, and other ecosystem partners; ensure appropriate security requirements, contractual protections, monitoring, and concentration-risk decisions.
  • Digital, cloud, data, and AI enablement: Embed proportionate security review into technology intake, procurement, architecture, development, and project delivery. Partner with Data and Analytics, Privacy, Legal, and operational leaders to govern AI tools and models, including data protection, access, acceptable use, monitoring, and third-party risk.
  • Human risk and security culture: Build an enterprise security culture through role-based awareness, phishing simulations, executive and clinical education, targeted interventions for high-risk users, and a network of security champions.
  • Metrics and continuous improvement: Define meaningful key risk and performance indicators, including risk reduction, control coverage, resilience, vulnerability remediation, third-party exposure, and workforce behavior; use results to prioritize resources and improve program maturity.
  • External engagement: Maintain effective relationships with peers, Health-ISAC, cyber insurance partners, law enforcement, CISA, HHS, and other relevant agencies to strengthen preparedness, information sharing, and response.
  • Financial stewardship: Develop and manage the information security budget, investment portfolio, contracts, and vendor performance, ensuring resources are directed to the organization’s highest risks and most critical capabilities.
  • Professional leadership: Demonstrate sound judgment, integrity, urgency, discretion, customer focus, and composure under pressure. Communicate effectively with technical and nontechnical audiences and influence outcomes where formal authority may not exist.
  • Adhere to AtlantiCare policies and procedures and perform other duties as assigned.

WORK ENVIRONMENT

This position requires sitting at a desk or computer a majority of the day, with frequent speaking, reaching, and reading. This position requires occasional lifting up to 20 lbs. This position requires availability outside normal business hours, including evenings, weekends, and holidays, to lead the response to significant security incidents.

REPORTING RELATIONSHIP

This position reports to the EVP, Chief Information and Digital Officer, provides regular cyber risk reporting to executive leadership and the Board, and supervises Information Security staff as assigned.

Qualifications

QUALIFICATIONS

EDUCATION: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Business, Health Informatics, or a related field, or equivalent relevant experience, required. Master’s degree preferred.

LICENSE/CERTIFICATION: CISSP or CISM strongly preferred; CRISC, CISA, CCSP, HCISPP, or comparable security, risk, cloud, or healthcare credentials are desirable.

EXPERIENCE: Ten or more years of progressive cybersecurity, information security, technology risk, or related experience, including at least five years leading teams, enterprise programs, or significant security functions. Health care experience and demonstrated knowledge of HIPAA, HITECH, the HIPAA Security Rule, health information privacy, and the operational and patient-safety implications of cyber events are required.

The successful candidate will have experience advising executives or boards; leading incident response and recovery; managing regulatory, audit, and third-party risk; establishing security architecture and controls across network, identity, endpoint, cloud, application, data, and medical-device environments; and developing multi-year strategy, budgets, metrics, and talent. Experience evaluating AI-enabled platforms and securing major digital or clinical transformation programs is strongly preferred.

About Us

Total Rewards at AtlantiCare

At AtlantiCare, we believe in supporting the whole person. Our market-competitive Total Rewards package is designed to promote the physical, emotional, social, and financial well-being of our team members. We offer a comprehensive suite of benefits and resources, including:

Generous Paid Time Off (PTO)

Medical, Prescription Drug, Dental & Vision Insurance

Retirement Plans with employer contributions

Short-Term & Long-Term Disability Coverage

Life & Accidental Death & Dismemberment Insurance

Tuition Reimbursement to support your educational goals

Flexible Spending Accounts (FSAs) for healthcare and dependent care

Wellness Programs to help you thrive

Voluntary Benefits, including Pet Insurance and more

Benefits offerings may vary based on position and are subject to eligibility requirements.

Join a team that values your well-being and invests in your future.

Pay Transparency

In order to support the Fair Compensation Strategy by the US Govt., HR Dept., clients are required to adhere to "Pay Transparency Law" in impacted states, which mandate employers to list salary ranges in job advertisements and promotions.

AtlantiCare is an Equal Opportunity Employer

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against AtlantiCare's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on AtlantiCare's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    AtlantiCare's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.