Vail Health has become the world’s most advanced mountain healthcare system. Vail Health consists of an updated 520,000-square-foot, 56-bed hospital. This state-of-the-art facility provides exceptional care to all of our patients, with the most beautiful views in the area, located centrally in Vail. Learn more about Vail Health here.
Some roles may be based outside of our Colorado office (remote-only positions). Roles based outside of our primary office can sit in any of the following states: AZ, CO, CT, FL, GA, ID, IL, KS, MA, MD, MI, MN, NC, NJ, OH, OR, PA, SC, TN, TX, UT, VA, WA, and WI. Please only apply if you are able to live and work primarily in one of the states listed above. State locations and specifics are subject to change as our hiring requirements shift.
ABOUT THE OPPORTUNITY
The Director of IT Security / Chief Information Security Officer (CISO) is responsible for developing, implementing, and maintaining the organization’s information security program to ensure the confidentiality, integrity, and availability of all digital assets, including electronic protected health information (ePHI). This role serves as the HIPAA Security Officer and leads enterprise cybersecurity efforts, risk management, incident response, and security governance. The CISO partners with clinical, operational, and IT leadership to align security with business and patient care objectives while ensuring compliance with regulatory requirements and safeguarding against evolving cyber threats.
WHAT YOU WILL DO:
· Serves as the Director of IT Security / Chief Information Security Officer (CISO), ensuring compliance with all privacy and security regulations.
· Leads and mentors a team of security professionals, fostering growth, accountability, and operational excellence.
· Develops and maintains the enterprise cybersecurity strategy aligned with healthcare-specific risks.
· Leads security governance, risk management, and compliance (GRC) programs across the organization.
· Performs regular risk assessments and manages mitigation plans to protect electronic protected health information (ePHI).
· Oversees security operations, incident response, threat detection, and vulnerability management.
· Partners with IT, clinical, and business leadership to embed security into all technology initiatives.
· Develops and enforces security policies, procedures, and training to promote a strong security culture.
· Manages third-party security risks, including vendor assessments and contractual security requirements.
· Leads response and recovery for cybersecurity incidents, including coordination with legal and compliance.
· Provides executive leadership with regular reporting on cybersecurity posture, risks, and remediation status.
· Models the principles of a Just Culture, Organizational Values, and Leadership Competencies.
· Performs other duties as assigned. Must be HIPAA compliant.
WHAT YOU WILL NEED:
Experience:
Licenses:
Certification(s):
Computer/Typing:
The posted salary range for this position applies to Colorado and may be adjusted based on geographic location. Vail Health considers a variety of factors in making compensation decisions, including but not limited to experience, education, licensure and/or certifications, geographic location, market demand and other business and organizational needs.
Benefits at Vail Health (Full Time) Include:
Pay is based upon relevant education and experience per year.
Redde Northgate plc
Wonders Corporation
Convatec
Questronix Corporation
BlackStone eIT