
Real job — pulled straight from Capital Health’s careers page · Verified August 15, 2026 · No reposts.
Job description
Capital Health is hiring a Information Security Officer — a full-time, based in Lawrenceville, IL role. Apply directly on Capital Health's careers page below.
Information Security Officer (ISO)
Location: CH IT Lawrenceville
Time Type: Full time
Job Description
Capital Health is the region's leader in providing progressive, quality patient care with significant investments in our exceptional physicians, nurses and staff, as well as advanced technology. Capital Health is a dynamic health care resource accredited by the DNV that includes two hospitals, an outpatient center, satellite ED, and an expansive network of primary and specialty care. Capital Health Medical Group is made up of more than 600 physicians and other providers who offer primary and specialty care, as well as hospital-based services, to patients throughout the region.
Capital Health recognizes that attracting the best talent is key to our strategy and success as an organization. As a result, we aim for flexibility in structuring competitive compensation offers to ensure we can attract the best candidates.
The listed pay range or pay rate reflects compensation for a full-time equivalent (1.0 FTE) position. Actual compensation may differ depending on assigned hours and position status (e.g., part-time).
Scheduled Weekly Hours:
40Position Overview
SUMMARY (Basic Purpose of the Job)
The Information Security Officer (ISO) serves as the executive leader responsible for protecting Capital Health’s digital environment and building organizational resilience against cyber threats. This role defines the organization’s cybersecurity strategy, safeguarding the confidentiality and availability of patient data, clinical systems and connected medical technologies by establishing clear policies and governance that align with healthcare regulations and industry standards. The ISO also acts as a principal advisor to leadership, working across clinical, legal and technical teams to embed security into daily operations and build a culture of digital trust. Additionally, the role oversees risk management and business continuity planning to ensure the organization can defend against emerging threats and quickly resume serving the community in the event of a disruption.
MINIMUM REQUIREMENTS:
Education: Bachelor’s degree in Information Security, Computer Science, Information Technology, Business, Engineering, or related field required. Master’s degree preferred.
Experience: Ten years of progressive experience in cybersecurity, with a proven track record of building and maturing enterprise-level security programs. Direct experience leading security initiatives in healthcare or another highly regulated environment, with a deep understanding of operational needs and regulatory rules. Significant experience architecting and securing complex digital environments – including cloud-native platforms, DevSecOps pipelines, clinical systems and APIs - to ensure safety and security are built into the design from the start. Extensive experience acting as a trusted advisor to executive leadership, boards and governance committees on cyber risk and digital trust. Preferred certifications include: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), HCISPP or healthcare-specific security certification and cloud security certifications (Azure, AWS, or equivalent).
Other Credentials:
Knowledge and Skills: Deep working knowledge of healthcare security standards (HIPAA/HITECH, NIST CSF, ISO 27001) and clinical accreditation expectations (DNV). Specific understanding of securing medical devices and healthcare-specific operational technology (IEC 62443). Strong technical depth in cloud-native systems, DevSecOps, AI governance and the security of internally developed applications. Expert knowledge of the Secure Software Development Lifecycle (SSDLC) and modern application security principles. Advanced understanding of enterprise risk management and the ability to make data-driven, risk-based decisions. Professional proficiency in translating complex technical concepts into clear, actionable reports for executive and board-level presentations.
Mental, Behavioral and Emotional Abilities: A leadership style focused on supporting the clinical mission and ensuring security enables – rather than hinders – patient care. Natural ability to build trust and influence others within a complex, matrixed organization, from clinicians to executives. High level of interpersonal effectiveness and the ability to mentor technical teams to increase their maturity. A proactive drive to modernize and scale security capabilities while balancing innovation with practical operational realities. Proven ability to take ownership of difficult security decisions and remain accountable for the organization’s resilience. Demonstrated ability to think long-term and manage the organizational shifts required to align security with business goals.
ESSENTIAL FUNCTIONS
Define and execute the enterprise cybersecurity strategy and multi-year roadmap to ensure protection stays ahead of evolving threats
Act as the principal advisor to the Board and leadership, providing clear reporting on cyber risk, resilience and maturity
Establish the policies, standards and accountability frameworks that govern how data and systems are protected across the health system
Lead the enterprise cybersecurity risk program, ensuring that risks are identified, prioritized and managed in line with healthcare regulations
Partner with Clinical Engineering to secure medical devices (BioMed) and connected technologies that directly impact patient care
Oversee the design of secure environments, ensuring “security-by-design” is built into cloud platforms and infrastructure
Integrate security into the software development lifecycle, ensuring internally developed applications are secure from the start
Drive the maturity of DevSecOps practices, integrating security into CI/CD pipelines and automation frameworks
Strengthen identity management and privileged access controls to enforce a “least-privilege” approach across the enterprise
Improve visibility and control over sensitive data (PHI, PII and PCI) across all clinical and operational platforms
Strengthen and elevate the organization’s ability to detect and respond to incidents through advanced monitoring and automation
Lead enterprise-wide incident response planning and coordinate executive communication during cybersecurity events
Oversee disaster recovery and business continuity planning to guarantee that clinical services can resume quickly after a disruption
Establish vendor security governance, ensuring partners and cloud services meet strict security and contractual standards
Partner with Procurement to embed cybersecurity into vendor selection, onboarding and Business Associate Agreements (BAAs)
Establish governance and security standards for Artificial Intelligence (AI), automation and intelligent agents
Ensure the secure exchange of data across EHR systems, cloud services and enterprise integration platforms
Partner with Legal and Compliance teams to maintain alignment with HIPAA, NIST and DNV accreditation expectations
Perform other duties as assigned
PHYSICAL DEMANDS AND WORK ENVIRONMENT:
- Occasional physical demands include: Standing , Walking , Climbing (e.g., stairs or ladders) , Carry objects , Push/Pull , Twisting , Bending , Reaching forward , Reaching overhead , Squat/kneel/crawl , Wrist position deviation , Pinching/fine motor activities
- Continuous physical demands include: Sitting , Keyboard use/repetitive motion
- Lifting Floor to Waist 15 lbs. Lifting Waist Level and Above 10 lbs.
- Sensory Requirements include: Accurate Near Vision, Accurate Far Vision, Color Discrimination, Minimal Depth Perception, Accurate Hearing
- Anticipated Occupational Exposure Risks Include the following: N/A
This position is eligible for the following benefits:
Medical Plan
Prescription drug coverage & In-House Employee Pharmacy
Dental Plan
Vision Plan
Flexible Spending Account (FSA)
- Healthcare FSA
- Dependent Care FSA
Retirement Savings and Investment Plan
Basic Group Term Life and Accidental Death & Dismemberment (AD&D) Insurance
Supplemental Group Term Life & Accidental Death & Dismemberment Insurance
Disability Benefits – Long Term Disability (LTD)
Disability Benefits – Short Term Disability (STD)
Employee Assistance Program
Commuter Transit
Commuter Parking
Supplemental Life Insurance
- Voluntary Life Spouse
- Voluntary Life Employee
- Voluntary Life Child
Voluntary Legal Services
Voluntary Accident, Critical Illness and Hospital Indemnity Insurance
Voluntary Identity Theft Insurance
Voluntary Pet Insurance
Paid Time-Off Program
The pay range listed is a good faith determination of potential base compensation that may be offered to a successful applicant for this position at the time of this job advertisement and may be modified in the future. When determining base salary and/or rate, several factors may be considered including, but not limited to location, years of relevant experience, education, credentials, negotiated contracts, budget, market data, and internal equity. Bonus and/or incentive eligibility are determined by role and level.
The salary applies specifically to the position being advertised and does not include potential bonuses, incentive compensation, differential pay or other forms of compensation, compensation allowance, or benefits health or welfare. Actual total compensation may vary based on factors such as experience, skills, qualifications, and other relevant criteria.
Get Information Security Officer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs
Frequently asked questions
What skills are required for Information Security Officer at Capital Health?
The required skills for Information Security Officer at Capital Health include: HIPAA, ISO 27001, DevSecOps, CISSP, CISM, CISA, AWS, Azure.
What is the seniority level for Information Security Officer at Capital Health?
Information Security Officer at Capital Health is a Senior / Manager level position.
How do I apply for Information Security Officer at Capital Health?
You can view the full description and apply for Information Security Officer at Capital Health on EchoJobs: https://echojobs.io/job/capital-health-information-security-officer-iso-zrtc7.



