Avatar for Summa Health
Summa Health
Actively Hiring
Integrated healthcare system providing patient-centered care

Chief Information Security Officer

  • Akron
  • |10 years of exp
  • |Full Time
Posted: 3 weeks ago
Job Location
Akron
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
SaaS
PaaS
Risk Management
Training
Planning
ITIL
Financial Management
Iaas
HL7
Forecasting
Incident Response
Business Impact Analysis
EDI
SoC
Vulnerability Management
Data protection
Threat Intelligence
Epic
PCI DSS
COBIT
IT Change Management
Continuity Planning
Business Continuity
Fhir
Vendor Risk Management
HITRUST
NIST CSF
Cloud Platforms
Awareness Campaigns
HITECH
Generative AI
IT Budget
Third-Party Risk Management
TJC
EDI 834
Agentic AI Workflows
Capital Budgets
Ransomware
Cloud Security Certification
EHR Platforms
HIPAA Security Rule
Vendor Risk Assessments
EDI 837
Incident Response Plan
Operational Budgets
BEC
Information Security Budget
Business Associate Agreement (BAA)
Business Associate Oversight
AI Threat Surface
HIPAA Security Rule Compliance
OCR Audit Readiness
Ohio Department of Insurance Requirements
Third-Party Breach
Business Associate Agreement (BAA) Oversight
Security Contract Requirements
Security Talent
Behavioral Change Initiatives
45 CFR Subchapter C, Section 164.308(a)(2)

About the job

Job Title: Director, Chief Information Security Officer (CISO)

Reports to: Chief Information Officer (CIO)

Department: IT&S – Office of the CIO

Date: 04/22/2026

Written by: Chief Information Officer

Summary of Position:

Under general direction of the CIO, the CISO is a senior executive accountable for building, owning, and delivering Summa Health System’s enterprise cybersecurity program across both the health system and the SummaCare health plan. This is a delivery role: the CISO authors strategy, holds direct accountability for architecture and implementation, and manages cybersecurity risk to acceptable levels aligned with business objectives.

The CISO maintains ongoing technical currency — including on the AI threat surface, cloud platforms, and emerging attack vectors — and applies it pragmatically in support of patient care, business operations, and regulatory obligations. The dual provider-and-payer mandate is defining: the CISO must be fluent in HIPAA Security Rule compliance, OCR audit readiness, and health plan obligations including Ohio Department of Insurance requirements, and serves as designated Information Security Official for Summa Health pursuant to 45 CFR Subchapter C, Section 164.308(a)(2).

Dimensions of Position

Operating Budget: As defined by annual IT&S budget cycle

Revenue: Direct impact through cybersecurity risk reduction, IT optimization, and business transformation enablement

Expenses: Cybersecurity investments and IT-enabled business transformation initiatives

Minimum Qualifications:

  1. Formal Education Required:

o Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, Business Administration, or related field — or equivalent combination of education and experience. Advanced degree (MS, MBA, or equivalent) preferred.

  1. Experience and Training Required:

o Ten (10)+ years of progressive information security experience, with at least five (5) in a senior leadership role carrying direct delivery accountability — not solely advisory or governance.

o Healthcare experience required, with demonstrated understanding of EHR platforms (Epic preferred), HL7/FHIR, EDI, and clinical workflow constraints affecting security program design.

  1. Certifications required:

o Three (3) current, non-lapsed certifications, with at least one being a cloud security certification or recognized equivalent. Accepted certifications listed below under Certifications preferred.

  1. Certifications preferred:

o ISC2 Certified Information Systems Security Professional (CISSP)

o ISC2 Certified Cloud Security Professional (CCSP)

o ISACA Certified Information Security Manager (CISM)

o ISC2 Healthcare Information Security and Privacy Practitioner (HCISPP)

  1. Other Skills, Competencies and Qualifications:

o Advanced knowledge of how cybersecurity capabilities support foundational business and clinical/operational workflows, including EHR platforms, interoperability standards (HL7/FHIR, EDI 834/837), and hybrid on-premises and cloud environments (IaaS, PaaS, SaaS).

o Advanced knowledge of cybersecurity governance frameworks (NIST CSF, HITRUST, HIPAA Security Rule, PCI DSS, COBIT, ITIL), information assurance principles (confidentiality, integrity, availability, authenticity, non-repudiation), and risk management processes including cyber threats, vulnerabilities, incident response, IT Change Management, and Business Continuity.

o Advanced knowledge of third-party and vendor risk management (outsourced service assessment, contractual security requirements, Business Associate oversight); and IT budget, planning, forecasting, and financial management to justify security investments by risk reduction and business impact.

o Working knowledge of emerging technology risk domains — including analytics, generative AI, and agentic AI workflows — and the ability to evaluate and integrate safeguards for data protection, misuse, and regulatory risk.

  1. Level of Physical Demands:

o Sedentary: Exerts up to ten pounds of force occasionally and/or a negligible amount of force frequently.

Direct Management Reporting Relationships

Indicate the title which this position reports to, as well as the various titles reporting directly to this position. Include FTE counts.

Position Reports to: Chief Information Officer (CIO)

Positions Reporting to this position: Note: this includes FTEs over which this position has hire, fire and performance review responsibilities.

  1. Information Security Department Associates (25)

Indirect (Matrix) Management Reporting Relationships

Indicate any position(s) to which this position has an indirect reporting relationship, as well as the position(s) over which this position has indirect management authority. Include FTE counts.

Position Indirectly Reports to: As assigned

Positions Indirectly Reporting to this position: As assigned

Cross-functional collaboration:

· IT leaders across infrastructure, applications, and clinical informatics.

· Compliance, Privacy, Risk, Public Relations, and Legal.

· Clinical Leadership, Finance, HR, and Operations to align security with business strategy.

· SummaCare leadership to address health plan-specific security and regulatory obligations.

· External partners, regulators, auditors, and cybersecurity organizations.

Essential Functions

The following essential functions are carried out consistent with Summa’s mission, values, and philosophies. This role is accountable for delivery, not only oversight.

  1. Security Strategy and Governance

o Author and maintain Summa’s enterprise security strategy and multi-year roadmap; strategy is owned internally, not outsourced to consultants.

o Integrate security governance into Summa’s corporate governance structure; own policies, standards, procedures, and guidelines across the health system and SummaCare.

  1. Risk Management

o Maintain an information asset classification and risk management framework aligned to NIST CSF and HITRUST.

o Ensure risk, vulnerability, and threat assessments are conducted on a regular cadence.

  1. Architecture and Technology

o Own security architecture decisions across on-premises and cloud; review and challenge vendor and internal architecture proposals directly.

o Approve authentication methods, encryption standards, mobile device security, and secure remote work policies.

  1. AI Security Governance

o Own Summa’s AI security governance framework as an active, present-day accountability.

  1. Security Operations and Incident Management

o Lead the SOC, incident response, threat intelligence, and vulnerability management functions.

o Establish and maintain a tested, Board-reportable incident response plan.

o Coordinate organizational response to security incidents; ensure readiness for ransomware, BEC, and third-party breach scenarios specific to healthcare.

  1. Third-Party and Vendor Risk Management

o Own the security component of third-party risk management, including Business Associate Agreement (BAA) oversight, vendor risk assessments, and security contract requirements.

  1. Business Continuity

o Coordinate business impact analysis and security-related continuity planning across health system and health plan operations.

  1. Financials

o Develop, manage, and defend the information security budget; plan and monitor operational and capital budgets consistent with Summa Health System goals.

  1. Managing & Leading People

o Create and communicate a shared vision aligned to organizational goals; recruit, develop, and retain security talent; build a team that reflects the program’s ambitions.

  1. Service Excellence, Planning & Organizational Culture

o Build a security culture across Summa’s workforce through training, awareness campaigns, and behavioral change initiatives; maintain relationships with clinical, operational, and administrative leaders that enable security as a collaborative partner.

  1. Regulatory Compliance

o Adhere to applicable regulations in daily activities and work processes, including HIPAA, HITECH, OCR, CMS, TJC, and Ohio-specific obligations across provider and health plan environments.

Additional Job Duties (note these areas of responsibility should not duplicate those previously covered above):

  1. Cybersecurity Program Management: Design and integrate a cybersecurity program that enables strategic objectives. Ensure plans of action, milestones, or remediation are in place for weaknesses from assessments, audits, and incidents. Serve as designated Information Security Official for Summa Health, pursuant to 45 CFR Subchapter C, Section 164.308(a)(2).

  2. Location and Work Model: Primary location is Akron, Ohio; on-site presence expected. Hybrid arrangements considered for exceptional candidates; relocation support available. Periodic travel required.

Note: The above duties outline functions typically performed in this position. This description is not all-inclusive nor does it limit supervisors’ discretionary authority to assign additional tasks of a similar nature or level.

About the company

Summa Health company logo

Summa Health

Actively Hiring
Integrated healthcare system providing patient-centered care5000+ Employees
Company Location
Akron
Company Size
5000+
Learn more about Summa Health image

Funding

AMOUNT RAISED
$1.5M
FUNDED OVER
1 round
Round
S
$1500000
Seed - Jan 2024