Manager of Information Security
Location : Birmingham, AL
Why VIVA HEALTH?
VIVA HEALTH, part of the renowned University of Alabama at Birmingham (UAB) Health System, is a health maintenance organization providing quality, accessible health care. Our employees are a part of the communities they serve and proudly partner with members on their healthcare journeys.
VIVA HEALTH has been recognized by Centers for Medicare & Medicaid Services (CMS) as a high-performing health plan and has been repeatedly ranked as one of the nation's Best Places to Work by Modern Healthcare.
Benefits
- Comprehensive Health, Vision, and Dental Coverage
- 401(k) Savings Plan with company match and immediate vesting
- Paid Time Off (PTO)
- 9 Paid Holidays annually plus a Floating Holiday to use as you choose
- Tuition Assistance
- Flexible Spending Accounts
- Healthcare Reimbursement Account
- Paid Parental Leave
- Community Service Time Off
- Life Insurance and Disability Coverage
- Employee Wellness Program
- Training and Development Programs to develop new skills and reach career goals
- Employee Assistance Program
See more about the benefits of working at Viva Health -
Job Description
The Manager of Information Security oversees and mentors a team of security engineers while remaining hands-on in designing, implementing, and monitoring security measures that safeguard the organization's digital assets. This individual will need a broad and strategic knowledge of principles, practices, and procedures in information security to plan, design, develop, execute, and support critical systems and projects.
This role will lead the planning, design, enforcement, and audit of enterprise-wide security policies and procedures which safeguard the integrity of and access to enterprise systems, files, and data elements while actively engaging in tactical execution. This position will continuously assess, refine, and implement data security strategies proactively advising leadership with actionable risk assessments and security briefings.
This individual evaluates and deploys emerging technologies, collaborates across IT Operations and Development, and strengthens organizational resilience by championing employee education, security culture, security best practice, and continuous improvement. This role drives value by balancing leadership responsibilities with direct technical contributions, ensuring scalable protection aligned with future business growth.
Key Responsibilities
Direct and actively contribute to day-to-day security operations.Perform hands on technical work in daily security operations while guiding team performance.Lead the development and enforcement of comprehensive, scalable security policies and frameworks.Recommend, implement, and optimize security protections across enterprise systems.Conduct and oversee vulnerability assessments, mitigation, and remediation strategies.Monitor and interpret threat intelligence using organizational tools.Research, identify, and deploy solutions that strengthen the organizations cyber defense posture.Detect, investigate, and resolve potential security breaches.Participate in the vetting and management of third-party vendors and business associates.Drive enterprise-wide risk assessments with quantifiable, business-aligned outcomes.REQUIRED QUALIFICATIONS :
Bachelor’s Degree in Information Systems or related field or equivalent work experience7 years of I.T. environment experience with progressive responsibilities3+ years management experience in I.T.Expertise in risk assessment tools, methodologies, and data-driven decision-makingProficiency of security platforms such as : endpoint detection and response (EDR), internet traffic for both onsite remote users, and intrusion prevention (IDS / IPS / DLP)Knowledge of databases (MSSQL / MongoDB / MySQL)Advanced skills in Azure cloud including Purview and DefenderHands on experience in penetration testing and vulnerability managementKnowledge of firewall and intrusion detection / prevention protocolsProven ability to lead system administration and security across diverse environments (Windows, UNIX, Linux)Skilled in drafting, enforcing, and scaling security policies, standards, and proceduresStrong communicator who can translate complex security risks into actionable business terms for executivesAbility to read and use the results of mobile code, malicious code, and anti-virus softwarePREFERRED QUALIFICATIONS :
CISSP, CISM, or equivalent advanced certificationsKnowledge of disaster recovery, computer forensic tools, technologies, and methodsStrong understanding of software development frameworks and code reviewKnowledge of virtualization technologyEqual Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.