Chief Information Security Officer – Los Angeles, CA

Chief Information Security Officer Los Angeles CA

Role Overview for Chief Information Security Officer – Los Angeles, CA

JRG Partners is proud to represent a pioneering medical device company based in Los Angeles, CA, in their search for a strategic and transformative Chief Information Security Officer (CISO). This is a premier executive leadership opportunity to shape and mature the cybersecurity posture of an organization at the forefront of healthcare innovation. Our client is dedicated to developing life-saving and life-enhancing medical technologies, and the security of these products, patient data, and corporate systems is of paramount importance.

As the CISO, you will be the senior-most executive responsible for the company’s enterprise-wide information security and risk management program. Reporting directly to the Chief Executive Officer, you will serve as a trusted advisor to the executive leadership team and the Board of Directors. You will be tasked with building a world-class, business-aligned security program that not only defends against sophisticated cyber threats but also enables business growth and innovation.

This role requires a visionary leader who understands the unique challenges of the medical device industry, including product security for connected devices (IoMT), regulatory compliance with FDA and HIPAA, and the protection of sensitive patient health information (PHI) and valuable intellectual property. You will lead a dedicated team of security professionals and champion a culture of security consciousness across the entire organization, from R&D and manufacturing to sales and operations.

Key Responsibilities of Chief Information Security Officer – Los Angeles, CA

Strategic Leadership & Vision

Develop, implement, and maintain a comprehensive, long-term information security strategy and roadmap that aligns with business objectives and the evolving threat landscape. Articulate a clear vision for the future of cybersecurity within the organization and secure executive buy-in and resources.

Governance, Risk, and Compliance (GRC)

Establish and oversee a formal security GRC framework. Lead enterprise-wide risk assessments, identify vulnerabilities, and drive remediation efforts. Ensure and demonstrate compliance with a complex web of regulations and standards, including HIPAA, HITECH, GDPR, CCPA, and crucial FDA cybersecurity mandates for medical devices.

Product & Device Security (IoMT)

Partner closely with Engineering, R&D, and Quality Assurance teams to embed security into the entire product development lifecycle (Secure SDLC). Champion security-by-design principles for connected medical devices, ensuring the confidentiality, integrity, and availability of device software, firmware, and data transmissions.

Security Operations & Incident Response

Lead the Security Operations Center (SOC) and mature its capabilities in threat detection, analysis, and response. Develop and regularly test a robust, enterprise-wide incident response plan to ensure swift and effective containment and recovery from security incidents.

Threat Intelligence & Vulnerability Management

Implement a proactive threat intelligence program to anticipate and counter emerging threats specific to the healthcare and medical device sectors. Oversee a comprehensive vulnerability management program, including regular scanning, penetration testing, and prioritized remediation.

Data Protection & Privacy

Design and enforce policies and technical controls to protect the company’s most critical data assets, including Protected Health Information (PHI), Personally Identifiable Information (PII), and proprietary intellectual property, both at rest and in transit.

Security Architecture & Engineering

Provide strategic direction for the design and implementation of a secure IT and OT (Operational Technology) architecture. Evaluate and deploy state-of-the-art security technologies for network, cloud, endpoint, and application security.

Identity and Access Management (IAM)

Oversee the strategy and operations for managing digital identities and access controls for all employees, contractors, and third-party partners, ensuring the principle of least privilege is consistently applied.

Third-Party Risk Management (TPRM)

Develop and manage a program to assess and mitigate the cybersecurity risks associated with the company’s supply chain, vendors, and business partners.

Executive & Board Communication

Effectively communicate complex cybersecurity risks, strategies, and program status to the executive leadership team and the Board of Directors in clear, business-oriented terms.

Budget and Team Management

Develop and manage the annual cybersecurity budget, ensuring optimal allocation of resources. Recruit, mentor, and lead a high-performing team of cybersecurity professionals, fostering a culture of excellence, collaboration, and continuous learning.

Requirements for the Chief Information Security Officer – Los Angeles, CA

Executive Experience

A minimum of 15 years of progressive experience in information security, with at least 7 years in a senior leadership capacity (e.g., CISO, VP of Security, Senior Director of Security) with demonstrable experience setting strategy and managing teams.

Industry-Specific Expertise

Proven experience within the medical device, pharmaceutical, or healthcare industry is mandatory. The ideal candidate will have deep familiarity with the unique security challenges of this regulated environment.

Regulatory Mastery

Expert-level knowledge of relevant legal and regulatory requirements. Demonstrated expertise in navigating and implementing controls based on the FDA’s cybersecurity guidance for medical devices is mandatory. Deep familiarity with HIPAA, HITECH, and global privacy laws (GDPR, CCPA) is also required.

Technical Acumen

Broad and deep technical knowledge across a wide range of security domains, including cloud security (AWS, Azure), network security, application security (SAST/DAST), incident response, cryptography, and secure software development (SSDLC).

Product Security Knowledge

Direct experience with embedded systems security, IoT/IoMT security, and securing hardware and software products throughout their lifecycle is highly desirable.

Educational Background

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field is required. A Master’s degree (e.g., MBA, MS in Cybersecurity) is strongly preferred.

Professional Certifications

Advanced security certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control) are highly valued.

Leadership & Communication Skills

Exceptional communication, presentation, and interpersonal skills. Proven ability to influence and build consensus with senior executives, technical teams, and non-technical stakeholders. A track record of building and leading successful cybersecurity teams is essential.

Business Acumen

Strong business acumen with the ability to translate security risks into business terms and effectively manage budgets, vendors, and strategic initiatives.

Benefits & Perks Offered

Our client is committed to attracting and retaining top-tier talent and offers a highly competitive executive compensation and benefits package, including:

  • Competitive base salary and an attractive executive-level annual bonus plan.
  • Meaningful equity package with stock options or RSUs.
  • Comprehensive health, dental, vision, and life insurance plans for you and your dependents.
  • Generous 401(k) retirement plan with a strong company match.
  • Substantial paid time off (PTO), paid holidays, and flexible work arrangements.
  • Relocation assistance package for qualified candidates.
  • Annual budget for professional development, conferences, and certifications.
  • Access to corporate wellness programs and other employee perks.
  • The opportunity to make a tangible impact on patient safety and public health.

How to Apply

If you are a visionary cybersecurity leader passionate about protecting technology that saves lives and you meet the qualifications outlined above, we strongly encourage you to apply for this exciting opportunity. JRG Partners is dedicated to connecting exceptional leaders with transformative roles.

To be considered, please submit your resume and a cover letter detailing your specific experience in the medical device or healthcare industry. For more information about our executive search capabilities in this sector, please visit the JRG Partners’ Technology Officers practice page. We look forward to reviewing your application.

Job Category: Information Technology
Job Type: Full Time
Job Location: Los Angeles, CA

Apply for this position

Allowed Type(s): .pdf, .doc, .docx, .rtf
This entry was posted in . Bookmark the permalink.