HCA Nashville , TN 37201
Posted 5 days ago
This position is incentive eligible.
Introduction
Last year our HCA Healthcare colleagues invested over 156,000 hours volunteering in our communities. As a Director of IPS Risk Management with HCA Healthcare you can be a part of an organization that is devoted to giving back!
Benefits
HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
Comprehensive medical coverage that covers many common services at no cost or for a low copay. Plans include prescription drug and behavioral health coverage as well as free telemedicine services and free AirMed medical transportation.
Additional options for dental and vision benefits, life and disability coverage, flexible spending accounts, supplemental health protection plans (accident, critical illness, hospital indemnity), auto and home insurance, identity theft protection, legal counseling, long-term care coverage, moving assistance, pet insurance and more.
Free counseling services and resources for emotional, physical and financial wellbeing
401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service)
Employee Stock Purchase Plan with 10% off HCA Healthcare stock
Family support through fertility and family building benefits with Progyny and adoption assistance.
Referral services for child, elder and pet care, home and auto repair, event planning and more
Consumer discounts through Abenity and Consumer Discounts
Retirement readiness, rollover assistance services and preferred banking partnerships
Education assistance (tuition, student loan, certification support, dependent scholarships)
Colleague recognition program
Time Away From Work Program (paid time off, paid family leave, long- and short-term disability coverage and leaves of absence)
Employee Health Assistance Fund that offers free employee-only coverage to full-time and part-time colleagues based on income.
Learn more about Employee Benefits
Note: Eligibility for benefits may vary by location.
Would you like to unlock your potential with a leading healthcare provider dedicated to the growth and development of our colleagues? Join the HCA Healthcare family! We will give you the tools and resources you need to succeed in our organization. We are looking for an enthusiastic Director of IPS Risk Management to help us reach our goals. Unlock your potential!
Job Summary
Position Summary
The Director of Information Protection & Security (IPS) Risk Management leads the risk management function for IPS. In this critical leadership position, you will be responsible for developing and overseeing our organization's comprehensive cybersecurity risk management program. This role will be responsible for developing and implementing a robust cybersecurity risk management strategy aligned with industry best practices and evolving threats. To be successful in this role, the Director of Risk Management must be able to clearly communicate cyber risks to all levels of the organization.
This leader will be key in implementing a risk management program that results in the identification, prioritization, and reduction of cybersecurity and ensures compliance for all in-scope facilities. This trusted advisor will help raise the protection bar by building strong relationships with technical and non-technical stakeholders to make risk visible, facilitate well-informed decision, and drive accountability. The ability to clearly communicate and report cybersecurity risk, and manage organizational relationships, will be key to the success of this role. In addition, this role must be able to establish a outcome-driven metrics approach to risk management and utilize protection level agreements as a mechanism to establish risk thresholds.
This position is expected to promote a culture that supports operating with an acceptable level of risk, developing standardized risk management criteria including but not limited to threats, vulnerabilities, likelihood, impact, and maturity, establishing risk tolerance, planning risk analysis (e.g. Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining the risk register to prioritize risk reduction actions and activities is implemented. This position is also responsible for evolving the organization's current risk treatment framework. This position is also responsible for collaborating with Information Security on the development, configuration, and implementation of the Risk Management Archer GRC application.
This position requires a candidate who can, with minimal guidance, analyze business requirements and processes, understand colleague behaviors, facilitate and lead meetings with key stakeholders within the organization, provide industry expertise and knowledge in the identification and mitigation of organizational risk, and enable decision making to support the adherence to industry standards and federal regulations.
The Director of IPS Risk Management provides guidance, direction, and mentorship to staff members to support the overall team goals and deliverables. A qualified candidate must be a highly motivated self-starter and be committed to delivering quality outcomes that meet team and organizational goals.
Major Responsibilities:
Quality
Work as part of the IPS department's leadership team to develop company requirements, strategies, priorities, processes, implementation plans, and assurance necessary to protect the company against information protection and security risks that could impact patients, employees, and the financial success of the business
Remain knowledgeable of legislative, regulatory, contractual, and other compliance requirements (e.g. HIPAA, PCI, SOX, Joint Commission) as well as departmental policies, standards, and procedures and participating in revision processes
Develop and lead the strategy to mature the risk management roadmap, create new roadmaps where needed, and ensure all roadmaps align with business objectives for the key focus areas
Provide periodic analysis of Company IPS-related risk position, based on analysis of current controls status and current threat landscapes
Monitor developments in related industries and communicate on the potential impact on or applicability to the organization
Ensure metrics are identified within risk management and remediation strategy that help demonstrate risk reduction and report progress to IPS leadership and company executive leadership
Develop risk register and be aware of associated remediation plans to respond to previously unidentified or inadequately addressed risk areas
Build rapport, credibility, and cohesion across IPS and other stakeholders across the enterprise
Partner with Internal Audit and IPS Leadership to ensure periodic reviews of the risk management program are performed to obtain independent assessments of the program's effectiveness
Partner with key stakeholders (e.g. Security Architects, DISAs) within IPS as well as with Internal Audit, Enterprise Risk Management, Legal, and ITG to ensure appropriate oversight and governance of the program
Ensure the team is involving all relevant stakeholders in major decisions; recognizing multiple agendas and making/communicating final decisions in ways that foster maximum ownership and minimum resistance
Service
Lead the team in providing risk-based security perspective through consulting and collaboration
Lead the team in facilitating and guiding business decisions and solutions
People
Accountable for the successful completion of organizational objectives through team members
Establish mutual objectives and targets for team members
Mentor team members, including developing and monitoring their personal development plans, and provide feedback via the annual performance review process
Promote a culture of collaboration, work/life balance, and open communication
Encourage new ways of thinking and problem solving
Create a team environment where members embrace change and adopt new practices
Stay engaged with team members through 1:1s, rounding, and performance review activities
Growth
Monitor developments in related industries and communicate on the potential impact on or applicability to the organization
Build rapport, credibility, and cohesion within IPS and with other stakeholders across the enterprise
Participate in educational opportunities to build and maintain team knowledge of evolving risk, information security, and privacy concepts
Finance
Other Skills/Duties
Performs other duties as assigned
Ability to effectively manage multiple priorities in a fast-paced environment
Excellent written and verbal communication skills; interpersonal and collaborative skills; the ability to communicate privacy, security, and risk-related concepts to technical and nontechnical audiences; persuasive, encouraging, motivating, and inspiring; the ability to listen and understand
Exposure to strategy, management, and/or operations in a number of healthcare and/or business functional areas
Independent, yet collaborative; respected by peers and others
The ability to think and act: decisiveness, assertiveness, with the ability to achieve results quickly
High degree of initiative, dependability, and the ability to work with minimal supervision
A sense of responsibility and accountability - someone who takes ownership and initiative
Creative thinker, always looking for a "better way" to deliver value; not stopped or discouraged by adversity
Respect for diversity of experience, characteristics, viewpoints, and opinions
Adaptable and flexible, with the ability to handle ambiguity and sometimes changing priorities
Demonstrated ability to effectively lead teams with diverse interests and skills
Strong organizational and interpersonal skills
Ability to elicit cooperation from a wide variety of resources, including peers, IPS management, other business units, and company leadership
Ability to define, learn, understand, and apply new technologies, methods, and processes
Knowledge of HIPAA and other healthcare security and data protection regulations
Professional demeanor, appearance, and positive attitude
Education & Experience:
Bachelor's degree Required
Master's degree Preferred
3+ years of experience in a leadership role Required
7+ years of experience in information technology, information security, privacy, and/or healthcare Required
Or equivalent combination of education and/or experience
Licenses, Certifications, & Training:
Knowledge, Skills, Abilities, Behaviors:
Service and Quality Excellence: Ability to demonstrate an uncompromising commitment to delivering exceptional care to create an unmatched value proposition for our patients.
Honor our Mission and Values: Ability to build trust and act with authenticity to cultivate a culture of integrity, inclusion, and mutual respect.
Effective Decision Making: Ability to make timely, informed decisions that are in the best interest of our patients, employees, providers, community and HCA.
Attain and Leverage Strategic Relationships: Ability to develop and strengthen collaborative relationships with both internal and external stakeholders to advance the care of our patients and the growth of HCA.
Lead and Develop Others: Ability to lead others to accomplish organizational goals and objectives; provide meaningful coaching and mentoring to increase the capabilities of individuals and teams and drive employee engagement.
Communicate with Impact: Ability to deliver information in a clear, concise, and compelling manner to effectively engage others and achieve desired results.
Achieve Success through Change: Ability to identify opportunities for improvement and innovation, remove barriers and resistance, and enable desired behaviors.
Drive Execution and Financial Results: Ability to commit to the success and financial wellbeing of HCA by challenging others to excel and hold themselves and others accountable for achieving results.
HCA Healthcare (Corporate), based in Nashville, Tennessee, supports a variety of corporate roles from business operations to administrative positions. Like our colleagues in any HCA Healthcare hospital, our corporate campus employees enjoy unparalleled resources and opportunities to reach their potential as healthcare leaders and innovators. From market rate compensation to continuing education and career advancement opportunities, every person has a solid foundation for success. Nashville is also home to our Executive Development Program, where exceptional employees are groomed to take on CNO- and COO-level roles in our hospitals. This selective program focuses on ethics, leadership and the financial and clinical knowledge required of professionals at this level of the industry.
HCA Healthcare has been recognized as one of the World's Most Ethical Companies by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"There is so much good to do in the world and so many different ways to do it."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
Be a part of an organization that invests in you! We are reviewing applications for our Director of IPS Risk Management opening. Qualified candidates will be contacted for interviews. Submit your application and help us raise the bar in patient care!
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
HCA