Vice President, Information Security, KPIT Job in Oakland, California US

Vice President, Information Security, KPIT

The Vice President, Information Security is accountable for overall information security, governance planning, strategy practices, and compliance standards for Kaiser Permanente (KP) and its affiliates. As health care delivery grows increasingly dependent on technology coupled with the increasing level of regulatory requirements that demand additional rigor, KP must implement highly resilient, reliable and effective solutions that meet and in some cases exceed performance standards found in financial services and other information rich industries. This VP with extensive experience in information security will lead a risk based management effort to fully integrate and optimize information security throughout Kaiser Permanente. The Information Security role includes protecting the confidentiality, integrity and availability of all sensitive KP information. It applies to all sensitive internal information, including member/patient information, business information (e.g., proprietary, privileged, financial, competitive), and employee/employer information. It includes all forms of information including electronic, paper, audio-visual, etc. Essential Functions: The VP, Information Security possess the vision, foresight and systemic view that plans for desired business growth as well as the ability to anticipate unspoken needs is essential for this role. Understands the overall impact to the security environment of any major changes to business and/or delivery modalities through risk assessments and leads the effort to manage the risk. Responsibilities include: - Lead and develop a team of security professionals providing guidance for leadership development . - Collaborate and teams with other groups within IT and KP for mutually beneficial business results. - Develop strategic and operational goals and influence functional areas to deliver an effective and appropriate information security framework. - Ensure that the appropriate KP wide governance structure is in place and highly functional. - Establish and maintain enterprise security principles, policies, standards and practices to ensure compliance with all regulatory mandates and requirements including, but not limited to HIPAA, SOX, FDA, PCI etc. - Leverage existing KP resources, departments, and infrastructure to perform Information Security activities and related work. - Ensure that operational impacts of security measures are risk based, well understood and well managed. - Develop, implement and report on progress for achieving and implementing security strategies, plans, products, and controls. - Manage escalation of issues relating to the overall security environment. - Actively participate in applicable information security and IT Risk Councils. - Effectively manage issues related to information security incidents and work with applicable KP-wide incident management programs. - Periodically report on the state of security to executive leadership. - Represent KP interests to appropriate industry and standards forums and advise senior leadership concerning topics and trends pertaining to information security. - Provide support for internal and third party audits. - Oversight of information security investigations and forensics. - Provide leadership development by providing opportunities for exposure, experience and education. The successful candidate is a visionary leader, highly effective communicator and influencer, with the ability to develop business solutions that garner stakeholder sponsorship to support organizational objectives and project deliverables. Qualifications: Basic Qualifications: - The position requires a bachelor's degree in business, management information systems or related business field. - The successful incumbent must have at minimum of 10 years of broad experience and deep knowledge in several of the following key areas with at least 5 years in a senior leadership role: - Subject matter expertise on information security governance, strategy development, standards, and controls. - Knowledge of security issues within a regulated industry. - Experience in compliance issues such as SOX, COBIT, HIPAA, etc. - Experience implementing and enhancing security in large-scale multi-location environments. - Proven track record initiating and leading performance change through line management and operations. - Demonstrated success in developing effective working relationships with business and physician leaders. - Strong business acumen with excellent strategic and business and analytical thinking. - Proven leadership, communication, partnership and collaboration and influencing skills are essential. - Develop and lead large organizations inclusive of directors, managers and individual contributors - The successful candidate possesses leadership capabilities to build and manage a highly effective organization and develop high-performance teams that may be geographically dispersed. - We expect a track record of solid leadership experience, a solution-oriented thought leader who leads by example through strong personal leadership conviction, possesses consensus building skills and a true team orientation, and displays good interpersonal skills. We seek a strong team player willing to partner and engage with other IT functional units to deliver substantive added value to business planning and operations. Preferred Qualifications: - Master's level graduate degree and/or MBA preferred.