CISO with a Healthcare Provider – Nashville, TN

CISO With A Healthcare Provider Nashville TN

Role Overview for CISO with a Healthcare Provider – Nashville, TN

JRG Partners is proud to partner with a premier, patient-focused healthcare provider in Nashville, Tennessee, in their search for a visionary and strategic Chief Information Security Officer (CISO). This is a critical executive leadership opportunity to shape and lead the cybersecurity posture of a complex and dynamic healthcare organization. The CISO will be the foremost authority on information security, responsible for establishing and maintaining a comprehensive, enterprise-wide security program that protects the confidentiality, integrity, and availability of patient data and critical systems.

In an era where healthcare data is a primary target for cyber threats, this role is paramount to maintaining patient trust and ensuring operational resilience. The successful candidate will be a forward-thinking leader who can balance the demands of robust security with the need for clinical and operational efficiency. You will serve as a key advisor to the executive leadership team and the Board of Directors, providing expert guidance on cyber risk and compliance with stringent healthcare regulations.

This position requires a leader who can not only manage technology and processes but also inspire a culture of security awareness and accountability across the entire organization. You will be at the helm of protecting sensitive electronic Protected Health Information (ePHI) and other confidential data, ensuring the organization not only meets but exceeds industry standards and regulatory requirements such as HIPAA and HITECH. This is a chance to make a tangible impact on patient safety and care delivery by safeguarding the digital infrastructure that underpins modern medicine.

Key Responsibilities of CISO with a Healthcare Provider – Nashville, TN

The CISO will have a broad range of responsibilities, encompassing strategic leadership, operational management, and regulatory compliance. Your primary objective will be to mature the organization’s security program to effectively mitigate current and emerging cyber threats.

Strategic Leadership & Program Development

Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program aligned with the organization’s goals and objectives.

Policy & Governance

Create, enforce, and maintain information security policies, standards, and procedures across the enterprise to ensure consistent and effective security practices.

Risk Management

Lead a formal information security risk assessment program, identifying and analyzing potential threats, vulnerabilities, and their impacts. Develop and implement risk mitigation strategies and controls.

Compliance & Auditing

Ensure full compliance with all applicable laws and regulations, including HIPAA, HITECH, and PCI-DSS. Serve as the primary point of contact for internal and external audits related to information security.

Security Operations

Oversee the Security Operations Center (SOC) and manage threat intelligence, vulnerability management, security monitoring, and incident response activities. Lead the response to any security breaches or incidents, including investigation, remediation, and reporting.

Team Leadership & Mentorship

Build, lead, and mentor a high-performing team of security professionals. Foster a collaborative and innovative environment that encourages continuous learning and professional growth.

Technology & Architecture

Direct the evaluation, selection, and implementation of security technologies and tools, including firewalls, intrusion detection/prevention systems (IDS/IPS), data loss prevention (DLP), SIEM, and endpoint protection solutions.

Identity & Access Management (IAM)

Oversee the IAM program, ensuring that access to systems and data is appropriate, authorized, and audited based on the principle of least privilege.

Vendor Risk Management

Establish and manage a third-party risk management program to ensure that business partners and vendors meet the organization’s security requirements.

Security Awareness & Training

Develop and champion a robust security awareness training program to educate all employees, contractors, and stakeholders on security best practices and their responsibilities in protecting company assets.

Budgeting & Financial Management

Develop and manage the annual information security budget, ensuring strategic allocation of resources to address the most significant risks and support key business initiatives.

Executive Reporting

Regularly report on the status of the information security program, including key metrics, risks, and incidents, to the executive leadership team, the Board of Directors, and relevant governance committees.

Requirements for the CISO with a Healthcare Provider – Nashville, TN

We are seeking an accomplished and seasoned security executive with a proven track record of success, particularly within the complex regulatory landscape of the healthcare industry.

Education & Professional Experience

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field is required. A Master’s degree is highly preferred.
  • A minimum of 12-15 years of progressive experience in information security, with at least 5-7 years in a senior leadership role (e.g., Director of Security, VP of Security, or CISO).

Mandatory experience within the healthcare industry.

A deep and practical understanding of healthcare operations, clinical workflows, and the unique security challenges of protecting ePHI is essential.

  • Proven experience developing and executing security strategies that align with business objectives in a large, complex organization.
  • One or more of the following professional certifications is strongly preferred: CISSP, CISM, CISA, HCISPP.

Technical Expertise & Knowledge

  • Expert-level knowledge of security risk management frameworks, such as the NIST Cybersecurity Framework, ISO 27001/27002, and HITRUST.
  • In-depth, hands-on knowledge of security technologies, including network security, cloud security (Azure/AWS), application security, encryption, identity and access management, and vulnerability management.
  • Comprehensive understanding of regulatory requirements, including HIPAA Security and Privacy Rules, HITECH Act, and PCI-DSS.
  • Experience with modern security operations, threat intelligence platforms, and incident response methodologies.

Leadership & Communication Skills

  • Exceptional leadership and team-building skills with the ability to inspire, motivate, and manage a diverse team of technical experts.
  • Outstanding communication and interpersonal skills, with the ability to effectively translate complex technical security concepts into business terms for executive leadership and non-technical stakeholders.
  • Strong business acumen and the ability to think strategically about risk and its impact on the organization’s mission.
  • Proven ability to influence change and build consensus across different departments and levels of the organization.
  • High level of personal integrity, ethics, and professionalism.

Benefits & Perks Offered

Our client is committed to attracting and retaining top-tier talent by offering a comprehensive and competitive executive compensation and benefits package. This includes:

Competitive Executive Salary

An attractive base salary commensurate with experience and market standards.

Performance-Based Bonus

A significant annual bonus potential based on individual and organizational performance.

Long-Term Incentives

Potential eligibility for long-term incentive plans.

Comprehensive Health & Wellness

Robust medical, dental, and vision insurance plans for you and your eligible dependents.

Retirement Savings

A 401(k) retirement plan with a generous company match to help you plan for your future.

Generous Paid Time Off

A substantial PTO policy, including vacation, sick days, and paid holidays, to promote a healthy work-life balance.

Professional Development

Strong support for continuous learning, including reimbursement for certifications, training, and attendance at industry conferences.

Relocation Assistance

A comprehensive relocation package is available for the right candidate.

Mission-Driven Culture

The opportunity to work in a collaborative and supportive environment dedicated to improving patient outcomes and community health.

How to Apply

If you are a visionary security leader with a passion for protecting critical healthcare infrastructure and a desire to make a significant impact, we encourage you to apply for this exciting opportunity. JRG Partners is a leader in executive search for security and technology roles. To learn more about our expertise, please explore our Information Technology practice area. To be considered for this confidential search, please submit your resume and a cover letter detailing your relevant experience through our secure application portal.

Job Category: Information Technology
Job Type: Full Time
Job Location: Nashville, TN

Apply for this position

Allowed Type(s): .pdf, .doc, .docx, .rtf
This entry was posted in . Bookmark the permalink.