Recovery Centers of America Logo

Recovery Centers of America

IT Security Program Manager

Posted 6 Hours Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Manage the day-to-day cybersecurity program, including audits, risk registers, third-party risk assessments, security policies, awareness training, vulnerability remediation, MDM security, incident response exercises, and compliance with HIPAA, HITECH, NIST, and HITRUST frameworks. The role prepares security metrics for leadership, coordinates cross-functional remediation, and supports continuous improvement of healthcare information security controls. It is primarily remote with limited travel.
The summary above was generated by AI
Job Summary & Responsibilities
Position Overview:
The IT Security Program Manager is responsible for executing and managing the day-to-day operations of Recovery Centers of America's cybersecurity program. Reporting to the manager of infrastructure under the IT OPS director and ensures that RCA's security posture remains compliant with HIPAA, HITECH, and NIST 800-53 standards while continuously improving the effectiveness of the organization's security controls and risk management framework.
 
This role will coordinate and perform audits, oversee third-party risk management, manage RCA's security awareness and phishing programs, drive policy governance, and ensure the timely resolution of open risk items and vulnerabilities. The ideal candidate is an organized, hands-on leader with a strong understanding of healthcare security and compliance who can align security initiatives with RCA's mission of saving one million lives.
 
Essential Duties and Responsibilities
 
Program Management & Governance
* Manage the daily operations of RCA's cybersecurity program under the guidance of the CISO.
* Coordinate and track the completion of internal and external security audits, including HIPAA, SOC 2, and NIST-based assessments.
* Maintain and monitor the Information Security Risk Register, ensuring timely resolution of identified issues and mitigation of critical findings.
* Lead tabletop exercises and incident response simulations to test and improve RCA's preparedness and business continuity planning.
* Collaborate with RCA leadership and department heads to ensure that security policies and controls are understood and effectively implemented across all business units.
 
Third-Party Risk & Vendor Management
* Manage the third-party risk assessment program, ensuring that all vendors with access to PHI or critical systems undergo security evaluation and periodic reassessment.
* Review BAAs, security questionnaires, and compliance attestations; ensure corrective action for identified gaps.
* Partner with Procurement and Legal to integrate security requirements into new and existing vendor contracts.
 
Policy, Compliance, and Reporting
* Work with the CISO to review, update, and publish information security policies, standards, and procedures in accordance with HIPAA, HITECH, and NIST frameworks.
* Develop dashboards and recurring reports to track security metrics, compliance posture, and program maturity for presentation to the CISO and executive leadership.
* Monitor and interpret changes to regulatory requirements, ensuring timely updates to RCA's compliance program.
 
Security Awareness & Training
* Administer and optimize RCA's KnowBe4 Security Awareness and Phishing Training Program.
* Track user engagement and training completion rates, and provide metrics and recommendations to leadership.
* Develop creative awareness campaigns to strengthen RCA's security culture.
 
Vulnerability & Infrastructure Management
* Identify and track critical infrastructure vulnerabilities, working with IT and Infrastructure teams to ensure remediation and continuous monitoring.
* Oversee MDM security, ensuring appropriate device controls, encryption, and enforcement of mobile security policies.
* Support the CISO in analyzing threat intelligence, vulnerability trends, and endpoint security performance (e.g., CrowdStrike, firewall alerts).
 
Risk and Compliance Leadership
* Ensure continuous compliance with HIPAA, HITECH, and NIST 800-53 / 800-171 requirements.
* Coordinate with Compliance, Legal, and Clinical leadership to ensure consistent risk management practices.
* Participate in post-incident reviews, documenting lessons learned and recommending process improvements.
 
Education
* Bachelor's degree in Information Security, Computer Science, Information Technology, or related field required.
 
Experience
* Minimum of 5--7 years of progressive experience in cybersecurity, IT risk management, or audit within a regulated environment (preferably healthcare).
* At least 2 years in a program management or leadership role overseeing information security functions.
* Strong working knowledge of HIPAA, NIST 800-53, HITRUST, and security risk management frameworks.
 
Certifications (preferred but not required)
* Security +, CISSP, CISM, CRISC, HCISPP, or equivalent security certification.
* PMP or similar project management certification is a plus.
 
Technical Skills
* Understanding of endpoint protection, SIEM tools, MDM platforms (e.g., Intune), and vulnerability management solutions.
* Experience with vendor risk tools, audit tracking systems, and compliance reporting.
* Familiarity with Microsoft 365 Security Suite, KnowBe4, and GRC platforms.
 
Core Competencies
* Strong analytical and problem-solving skills.
* Excellent written and verbal communication skills, with the ability to translate technical risks for non-technical stakeholders.
* Highly organized and detail-oriented, with the ability to manage multiple priorities simultaneously.
* Demonstrated ability to build cross-functional relationships and drive accountability.
* Passionate about RCA's mission and maintaining the privacy and security of patient information
 
Travel
* Limited travel is required for this position
* This position is primarily a remote position
 
This job description is not designed to cover or contain a comprehensive listing of all activities, duties, or responsibilities required of the employee. Duties, responsibilities, and activities may change at any time, with or without notice, to meet the evolving needs of the organization. Nothing in this job description alters the at-will nature of employment, and either RCA or the employee may terminate the employment relationship at any time, with or without cause or notice.
 
RCA is committed to providing reasonable accommodations to qualified individuals with disabilities to enable them to perform the essential functions of their role. Employees or applicants requiring accommodation should contact Human Resources to initiate the interactive accommodation process.

This position primarily involves sedentary work, including extended periods of sitting and computer use. The employee must be able to communicate effectively via phone, video conferencing, and written correspondence.
 
Non-Discrimination Statement:
It is the policy of Recovery Centers of America (RCA) to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, age, disability, marital status, citizenship, genetic information, or any other characteristic protected by law.
 
State Specific Responsibilities:
Follows organizational cybersecurity policies, including acceptable use, password management, and multi-factor authentication requirements. Immediately reports suspected security incidents, unauthorized access, or data breaches in accordance with company policy and regulatory requirements. Maintains strict confidentiality of PHI and adheres to the principle of least privilege, accessing only the minimum necessary data required to perform job functions.

Similar Jobs

11 Minutes Ago
Easy Apply
Remote or Hybrid
Easy Apply
152K-190K Annually
Junior
152K-190K Annually
Junior
Cloud • Information Technology • Security • Software • Cybersecurity
Design, train, fine-tune, optimize, and deploy large-scale machine learning systems for cloud security use cases. Build end-to-end ML pipelines, develop transformer and embedding models, productionize open-weight language models, and optimize inference for latency, cost, and quality. Architect resilient ML services across AWS and GCP using cloud-native microservices while collaborating with engineering teams on AI strategy and solving complex problems involving massive datasets.
Top Skills: AWSDeep LearningGCPHugging FaceJaxLarge Language ModelsLoraMicroservicesOnnx RuntimePeftPythonPyTorchQloraTensorFlowTensorrt-LlmTransformer ModelsVllm
11 Minutes Ago
Remote
USA
152K-175K Annually
Senior level
152K-175K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Secure Runpod’s multitenant GPU cloud infrastructure across bare-metal and virtualized environments. Responsibilities include designing workload and network isolation, hardening Linux kernels and container platforms, testing hypervisor and hardware security, developing low-level controls in C, Go, or Rust, securing GPU and PCIe interactions, and responding to infrastructure security incidents with forensic capabilities for ephemeral containers.
Top Skills: ApparmorBare-Metal Cloud InfrastructureCC.V.E.SCgroupsContainerdDockerEbpfGoGpu ArchitectureKubernetesKvmLinuxLinux KernelNamespacesPciePythonQemuRustSelinuxVirtualized Networking
13 Minutes Ago
Remote or Hybrid
153K-261K Annually
Entry level
153K-261K Annually
Entry level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Leads business development for BAE Systems’ Advanced Mission Solutions portfolio, shaping domestic and international growth strategies, identifying and qualifying opportunities, and developing customer engagement and campaign plans. Builds relationships with defense customers, industry partners, and internal teams; translates mission needs into product and technical roadmaps; supports capture, pricing, market analysis, compliance, and business-winning activities. Requires F-16 customer relationships, fighter aircraft knowledge, government contracting expertise, and approximately 50% international travel.
Top Skills: C4IsrDirect Commercial Sales (Dcs)F-16F-35Foreign Military Sales (Fms)

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account