Job Closed
This listing is no longer active.
Clinical and operations software solutions for assisted living providers
Director of Information Security
Location
Wisconsin
Posted
104 days ago
Salary
0
Seniority
Mid Level
Job Description
Director of Information Security
ECP
ECP is a market-leading SaaS software solution that enables senior living communities to better care for their residents. ECP is used in over 8,000 communities. We're looking to further expand by increasing the number of customers that use our software and increasing the scope of how we serve our customers by developing and releasing new products. ECP is seeking a Director of Information Security to lead and execute our cybersecurity and compliance strategy. This is a hands-on role responsible for ensuring the confidentiality, integrity, and availability of our systems and customer data within the context of healthcare regulations (HIPAA) and SOC 2 Type II compliance. The ideal candidate brings a blend of technical expertise, regulatory understanding, and practical execution, partnering closely with our Infrastructure and IT teams to strengthen our security posture across the company. You’ll manage annual audits, harden systems, guide best practices, and foster a culture of security awareness. This position reports to the VP of Engineering and collaborates cross-functionally with DevOps, Infrastructure, Compliance, and IT. Note: We are open to remote candidates located in the U.S. Cybersecurity: - Develop and execute ECP’s information security strategy, aligned with business goals and risk tolerance. - Maintain and evolve SOC 2 Type II compliance, including evidence gathering, documentation, and audit coordination. - Ensure compliance with HIPAA and other healthcare data protection standards. - Establish, implement, and maintain security policies, procedures, and standards consistent with regulatory and customer expectations. - Manage third-party risk and vendor security assessments. - Lead the incident response program, including detection, investigation, communication, and remediation. - Oversee vulnerability management, penetration testing, and security monitoring. - Partner with Infrastructure and DevOps teams to secure servers, cloud environments (AWS/Azure), and CI/CD pipelines. - Integrate secure development lifecycle (SDLC) practices into engineering workflows. - Stay current on emerging security threats, technologies, and frameworks, and advise leadership accordingly. IT & Platform Security: - Collaborate with internal IT to harden employee laptops and mobile devices, ensuring encryption, endpoint protection, and compliance with policy. - Manage and optimize the company’s mobile device management (MDM) platform. - Support and guide internal IT in maintaining secure onboarding/offboarding and access management processes. - Coordinate internal penetration testing efforts and develop recommendations for infrastructure hardening. - Assist with network and system security, including identity management and monitoring. - Develop and lead employee security and HIPAA awareness training programs. - Maintain visibility into and tracking of vulnerabilities and remediation efforts.
Job Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 5+ years of experience in information security, infrastructure security, or a related role.
- Prior experience in a SaaS or healthcare technology environment required.
- Demonstrated experience leading SOC 2 Type II audits and ensuring HIPAA compliance.
- Strong understanding of AWS cloud security, identity and access management, and data protection best practices.
- Hands-on experience with endpoint management, laptop hardening, and mobile device management (MDM) tools.
- Strong troubleshooting, analytical, and problem-solving skills.
- Excellent communication skills with the ability to work effectively across technical and non-technical teams.
- Ability to thrive in a collaborative, fast-paced environment.
- Preferred:
- Certifications such as CISSP, CISM, CISA, Security+, or HCISPP (Healthcare Information Security & Privacy Practitioner).
- Familiarity with frameworks such as NIST CSF, CIS Controls, or ISO 27001.
- Experience scripting or automating security tasks (Python, PowerShell, Bash).
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Director of Information Security
ECPClinical and operations software solutions for assisted living providers
ECP is a market-leading SaaS software solution that enables senior living communities to better care for their residents. ECP is used in over 8,000 communities. We're looking to further expand by increasing the number of customers that use our software and increasing the scope of how we serve our customers by developing and releasing new products. ECP is seeking a Director of Information Security to lead and execute our cybersecurity and compliance strategy. This is a hands-on role responsible for ensuring the confidentiality, integrity, and availability of our systems and customer data within the context of healthcare regulations (HIPAA) and SOC 2 Type II compliance. The ideal candidate brings a blend of technical expertise, regulatory understanding, and practical execution, partnering closely with our Infrastructure and IT teams to strengthen our security posture across the company. You’ll manage annual audits, harden systems, guide best practices, and foster a culture of security awareness. This position reports to the VP of Engineering and collaborates cross-functionally with DevOps, Infrastructure, Compliance, and IT. Note: We are open to remote candidates located in the U.S. Cybersecurity: - Develop and execute ECP’s information security strategy, aligned with business goals and risk tolerance. - Maintain and evolve SOC 2 Type II compliance, including evidence gathering, documentation, and audit coordination. - Ensure compliance with HIPAA and other healthcare data protection standards. - Establish, implement, and maintain security policies, procedures, and standards consistent with regulatory and customer expectations. - Manage third-party risk and vendor security assessments. - Lead the incident response program, including detection, investigation, communication, and remediation. - Oversee vulnerability management, penetration testing, and security monitoring. - Partner with Infrastructure and DevOps teams to secure servers, cloud environments (AWS/Azure), and CI/CD pipelines. - Integrate secure development lifecycle (SDLC) practices into engineering workflows. - Stay current on emerging security threats, technologies, and frameworks, and advise leadership accordingly. IT & Platform Security: - Collaborate with internal IT to harden employee laptops and mobile devices, ensuring encryption, endpoint protection, and compliance with policy. - Manage and optimize the company’s mobile device management (MDM) platform. - Support and guide internal IT in maintaining secure onboarding/offboarding and access management processes. - Coordinate internal penetration testing efforts and develop recommendations for infrastructure hardening. - Assist with network and system security, including identity management and monitoring. - Develop and lead employee security and HIPAA awareness training programs. - Maintain visibility into and tracking of vulnerabilities and remediation efforts.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Equipment Service Technician provides excellent technical services and customer service experiences maintaining strong relationships with manufacturers, suppliers, and sales representatives. As such, you must be a positive, energetic leader who excels in working in a collaborative environment. - Perform all on-site installation, repair, maintenance, and troubleshooting tasks on packaging machinery, providing instructional training to customers - Continual training of equipment and resources necessary to perform the functions of the department - Attend Branch and Technical Service meetings scheduled by Service Manager or Branch Manager - Consistently deliver excellent customer service experiences by offering knowledge, advice, and answering questions and concerns - Manage excellent vendor relationships by providing timely communications, problem-solving, and site visits to key suppliers when necessary - Coordinate with VP of Sales and Sales Representatives to provide excellent customer support - Diagnose errors or technical problems by visual and auditable inspection of machines and determine proper solutions - Dismantle machines and equipment to gain access to and resolve issues - Diagnose, install, and repair electrical apparatus such as transformers and wiring, electrical, electronic components of machinery and equipment - Produce timely and detailed service reports - Monitor work procedures, work schedules, and expedite workflow - Create and submit a completed expense report each month - Assist with office/warehouse needs as time permits Qualifications - A minimum of 3-5 years of experience in machinery and conveyor equipment experience is required - High school diploma or its equivalent is required Requirements - Exceptional customer service and must be people-oriented with the ability to build business relationships - Proficient computer skills including MS Office Suite, Allen Bradley or equivalent PLCs, smartphones, and tablets - Local travel and overtime required - Minimal overnight travel required - Dependable transportation required, valid driver’s license, and proof of insurance - Familiarity with scheduling and expediting the turnaround time on service calls - Analytical, problem solving, business analysis, and project management skills Benefits - Premium benefits package including PTO, Employee Assistance Programs, 401k matching, Health Insurance, Medical Insurance, Dental Insurance, Vision Insurance, and much more
Security Solutions Senior Manager - Threat and Vulnerability Management
World Wide Technology Healthcare SolutionsFounded in 1990, World Wide Technology (WWT) is a global systems integrator with $13.4 billion in annual revenue that provides digital strategy, innovative technology and supply chain solutions to large public and private organizations.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Senior Manager is a transformational security leader responsible for evolving and modernizing enterprise Threat & Vulnerability Management (TVM) capabilities. This role moves beyond operational execution to drive threat-informed strategy, exposure intelligence integration, and AI-enabled optimization of remediation and risk reduction programs. - Lead the transformation of customer enterprise TVM capabilities toward threat-informed, intelligence-driven exposure management - Integrate threat intelligence, exploitability data, adversary TTPs, and business context into prioritization models - Mature CTEM practices into a continuous, measurable exposure management lifecycle - Define and implement risk quantification models that align remediation priorities with business impact - Design scalable customer governance frameworks that support dynamic threat response - Drive automation of vulnerability triage, prioritization, and validation workflows - Integrate AI/ML-based insights to improve exploit prediction, risk scoring, and remediation sequencing - Lead tooling rationalization and integration across scanners, asset inventories, CMDB, cloud platforms, and SOAR systems - Implement closed-loop remediation validation and continuous exposure monitoring - Identify opportunities to reduce manual operational overhead through orchestration and intelligent workflow design - Champion predictive analytics to proactively identify emerging exposure concentrations before exploitation - Develop executive customer-level exposure intelligence dashboards integrating threat context and business impact - Introduce KPIs that measure risk burn-down, exploitability reduction, and control effectiveness - Identify systemic exposure drivers (architecture, configuration drift, shadow IT) and implement structural remediation improvements - Continuously refine prioritization algorithms using threat intelligence feedback loops - Serve as a strategic advisor to CISO and security leadership on evolving threat exposure posture - Translate strategic security objectives into AI-enabled, scalable TVM operating models - Lead cross-functional transformation initiatives spanning security, IT, DevOps, and cloud engineering - Mentor teams to adopt automation-first and threat-informed mindsets - Support business development and thought leadership in exposure management modernization Qualifications - 8–12 years in cybersecurity with leadership experience in vulnerability, exposure, or risk management programs - Demonstrated experience modernizing or transforming security operations programs - Strong understanding of threat intelligence, exploitability analytics, and adversary tactics - Experience integrating automation and orchestration within security workflows - Proven ability to design governance and performance models aligned to risk outcomes - Experience presenting strategic transformation initiatives to executive leadership Requirements - Experience implementing CTEM or continuous exposure management frameworks - Experience integrating AI/ML tools into security operations or vulnerability management - Background in security architecture or threat intelligence - Experience in regulated industries (financial services, healthcare, etc.) - Certifications such as CISSP, CISM, PMP, or equivalent - Experience with enterprise vulnerability management and orchestration platforms - Familiarity with risk quantification methodologies Benefits - Health and Wellbeing: Health, Dental, and Vision Care, Onsite Health Centers, Employee Assistance Program, Wellness program - Financial Benefits: Competitive pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Tuition Reimbursement - Paid Time Off: PTO and Sick Leave (starting at 20 days per year) & Holidays (10 per year), Parental Leave, Military Leave, Bereavement - Additional Perks: Nursing Mothers Benefits, Voluntary Legal, Pet Insurance, Employee Discount Program
• Lead and conduct security operations to maintain confidentiality, availability, and integrity of data • Ensure excellent customer service for internal and external customers • Manage security tools and technologies (e.g., Palo Alto Firewall features) • Troubleshoot Prisma Access for secure remote connectivity • Design and implement security-related solutions • Collaborate with systems and network engineers to ensure compliance • Draft recommendations on security policies and procedures • Assist in managing an Incident Response Team


