Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

University of Tennessee Medical Center.

Director - Cyber Security

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
78
out of 100
Average of individual scores

Were these scores useful?

Job Description

Job Detail

Job Title:

Director - Cyber Security

Department:

Info Services Security

Full/Part Time:

Full

Req Number:
UHS-36467
Position Summary:

The Director of Cybersecurity is a senior leadership team member responsible for leading, managing, and continuously improving the organization's cybersecurity program across a complex enterprise environment. Reporting directly to the Chief Information Security Officer (CISO), this role serves as the operational leader of cybersecurity and is responsible for executing the organization's security strategy, reducing cyber risk, protecting critical assets, and ensuring the resilience of business and clinical operations.

The Director of Cybersecurity provides leadership across cybersecurity Operations, Incident Response, Vulnerability Management, Security Engineering, Identity and Access Management (IAM), Governance, Risk and Compliance, Third-Party Risk Management, and Security Training and Awareness.

Cybersecurity Program Leadership

Lead the day-to-day management and execution of the enterprise cybersecurity program.

Develop, implement, and maintain cybersecurity strategies, roadmaps, policies, standards, and procedures.

Serve as a strategic advisor to the CISO.

Security Operations & Threat Management

Provide leadership and oversight of Security Operations Center (SOC) functions.

Lead threat detection, incident response, and crisis management activities.

Security Engineering & Infrastructure Protection

Direct security engineering activities supporting enterprise infrastructure, cloud services, applications, and data platforms.

Vulnerability & Exposure Management

Lead enterprise vulnerability management and attack surface reduction initiatives.

Identity & Access Management

Provide executive oversight of IAM capabilities including Multi-factor Authentication (MFA), Privileged Access Management (PAM), Single Sign On (SSO), and Identity Governance and Administration (IGA).

Risk Management & Governance

Lead cybersecurity risk assessment, treatment, and reporting activities.

Regulatory Compliance & Audit Support

Support audits, regulatory reviews, and compliance requirements.

Cloud Security & Emerging Technology

Oversee security governance for cloud platforms and emerging technologies.

Third-Party Risk Management

Lead vendor management and third-party cybersecurity risk assessments.

Leadership & Team Development

Lead, mentor, and develop cybersecurity team members.

Position Qualification:
Education

Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, Engineering, or related field.

Required

Minimum 12 years of progressive cybersecurity experience.

Minimum 7 years of progressive leadership experience managing cybersecurity teams, with at least 3 years in a senior leadership (Manager or above) position.

Experience in regulated or mission-critical environments.

Experience developing cybersecurity strategy, policy, and governance programs.

Experience developing and managing operating and capital budgets.

Experience presenting cybersecurity risks and controls to leadership, partners, and other stakeholders.

Experience working with industry recognized cybersecurity frameworks including NIST, HITRUST, and CIS.

CISSP or CISM certification.

Preferred

Master's Degree in Cybersecurity, Information Assurance, Business or other related field.

Experience in Academic Health System or other complex healthcare environment

CCSP, CRISC, CISA, CGRC, GIAC

certifications, cloud security certifications, TOGAF, SABSA.