We are Marathon Health. We’re building better, together.
Information Security Manager
Location
United States
Posted
2 days ago
Salary
$115K - $145K / year
Seniority
Mid Level
Job Description
Information Security Manager
Marathon Health
• Responsible for leading a team of security analysts to protect enterprise systems and PHI, ensuring compliance with HITRUST, HIPAA, SOC 2 and related regulatory frameworks while maturing detection, response, and governance capabilities. • Handle day-to-day management of security operations and continuous compliance monitoring. • Driving cybersecurity maturity with continuous improvement of controls. • Continuously evaluating and managing the cyber and technology risk posture of the organization. • Lead Marathon Health’s internal and outsourced security teams to execute on the roadmap defined by our CISO. • Lead the security team response to security incidents and breaches. • Manage the prospect, client and 3rd party security assessment fulfillment process. • Identify and manage vulnerabilities. • Maintain and continuously improve SOC2/HITRUST CSF certification; ensure security control ownership, evidence collection, and audit readiness are operationalized across all responsible domains.
Job Requirements
- Bachelor’s degree in computer science, information systems or cybersecurity or related field
- A minimum of 2 years’ experience in people leadership within security, including serving as the final decision-maker for hiring, development, and performance management, or equivalent combination of education and experience.
- Experience in healthcare technology, health systems, or digital health, with working knowledge of HIPAA, PHI governance, and clinical system dependencies.
- Experience owning or co-owning HITRUST CSF certification (or equivalent compliance framework such as SOC 2, ISO 27001).
- HITRUST Certified Common Security Framework Practitioner (CCSFP) or equivalent HITRUST training
- One or more professional security certifications: CISSP, CISM, or CISA.
- AWS Security Specialty or equivalent cloud security certification
- CRISC (Certified in Risk and Information Systems Control)
- AI governance or responsible AI certifications (e.g., ISACA AI Audit certificate, Certified AI Governance Professional)
- Travel is required for up to 15%, team meetings, clinic visits, audit support
Benefits
- Comprehensive Health & Wellness Benefits: Choice of 2 medical plans, 2 dental plans, and vision coverage, unlimited free mental health benefits and EAP resources, Rewards for challenges and healthy lifestyle activities
- Family Friendly & Reproductive Health Benefits: Family-building and hormonal health benefits and paid parental leave
- Time-Based Benefits: Generous PTO or FTO, Paid Holidays + A Day for What Matters
- Financial Support: Company paid Basic Life and Disability insurance, Supplemental Life, Spending Accounts, 401(k) with employer match and graded vesting
- Continuing Medical Education (CME) for maintaining and strengthening the knowledge, skills, and expertise of our health center teammates, as applicable
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cyber Security Assessment and Authorization Analyst
Chickasaw Nation Industries, Inc.Service Without Reservation
• Provides support to the Department of Health and Human Services, Indian Health Service (IHS) • Responsible for executing and assisting in the completion of security certifications • Provides support in the development and implementation of a program to manage all aspects of compliance with government regulations • Conducts annual security controls effectiveness testing • Documents findings and advises and monitors remediation efforts on all systems • Conducts information security audits/risk assessments on customer systems and network • Assists system owners in developing security authorization packages • Prepares security authorization packages using approved customer templates • Ensures customer information and information systems are adequately protected from unauthorized access, use, disclosure, disruption, modification, or destruction
• Act as the primary technical point of contact for IRAP assessments and commercial compliance/regulatory inquiries. • Explain Dashboard infrastructure, system architecture, data flows, and security controls to assessors and regulators. • Partner with global Compliance and Security teams to prepare evidence, documentation, and responses for IRAP. • Coordinate with Engineering Teams to validate and implement required controls. • Track changes to ASD ISM, IRAP guidance, Essential Eight, Australian government cloud/security expectations, and applicable privacy or critical infrastructure requirements; assess impact to Dashboard services. • Contribute to audit readiness, remediation efforts, and continuous compliance improvements. • Maintain IRAP control mappings against Cisco CCF controls, including applicability, implementation status, ownership, evidence sources, and compensating controls. • Own the end-to-end IRAP assessment lifecycle, including scope definition, assessor engagement, evidence collection, assessment logistics, report review, and post-assessment remediation tracking. • Translate IRAP findings into prioritized engineering requirements, risk treatment plans, exceptions, and executive-level status reporting. • Review IRAP assessment reports, letters of completion, and customer-facing assurance materials for technical accuracy and consistency.
Senior Security Engineering – Compliance Lead
CiscoWe securely connect everything to make anything possible.
• manage the implementation of security frameworks (SOC, ISO, NIST, etc) with automated compliance pipelines • build and maintain automated data pipelines to provide real-time visibility into control effectiveness for auditors and stakeholders • engineer and enforce automated user access reviews and segregation-of-duties (SoD) testing • perform deep-dive vulnerability analyses on enterprise infrastructure • engineer automated patch management and configuration hardening workflows
Federal Civilian Security Account Executive – Architecture
CiscoWe securely connect everything to make anything possible.
• Develop and execute account plans across assigned agencies. • Build relationships with executive and operational leaders, including CIOs, CISOs. • Identify opportunities to modernize cybersecurity programs and improve operational resilience. • Position Cisco's Security portfolio to address agency priorities including threat protection, Zero Trust, secure access, cloud security, and incident response. • Collaborate with Cisco Account Managers, Security Specialists, Solutions Engineers, and partners to drive customer success. • Navigate government procurement processes, contract vehicles, and funding programs. • Consistently achieve and exceed assigned sales objectives.


