PRIMARY FUNCTION
The SVP, Chief Information Security Officer (CISO), Infrastructure and Architecture is responsible for enterprise security, risk strategy, software architecture, and Azure cloud cost governance for Pediatric Associates (PAFC). The CISO owns the security mandate, builds and leads the team, sets the security and architecture roadmaps, and ensures secure-by-design delivery, operational reliability, and unit-cost efficiency across PAFC's digital ecosystem, including patient and provider portals and data platforms.
ESSENTIAL DUTIES AND RESPONSIBILITIES
This list may not include all the duties that may be assigned.
- Enterprise Security & Architecture Leadership : Own enterprise security and reference architectures across all subsidiaries (clinical, corporate, and data environments). Be accountable for overall risk posture, platform performance, scalability, and compliance.
- Executive Advisory : Provide senior leadership, CEO, and Board with clear, metrics-driven guidance on security, platform architecture, reliability, scalability, and cost.
- Risk Communication : Deliver regular briefings to senior leadership and the Board on security posture, threat landscape, cost exposure, and mitigation plans. Ensure risks are translated into business impact and prioritize remediation.
- Operational Standards : Direct day-to-day enforcement of security and architecture standards : identity, network, endpoint, data protection, EHR / portal integrations, APIs, runtime services. Mandate measurable uptime, scalability, and performance benchmarks.
- Security Program Maturity : Assess maturity of security and architecture capabilities. Own the roadmap. Secure leadership buy-in and drive execution.
- Third-Party & M&A Risk : Lead third-party risk management and M&A security diligence. Ensure rapid integration of acquired practices into a unified, secure, and scalable architecture.
- Cloud Cost Governance : Enforce tagging, ownership, budgets, and alerts for all cloud resources. Lead periodic cost and performance reviews with Engineering & Infrastructure. Optimize spend through reservations, auto-scaling and storage lifecycle. Tie cloud cost explicitly to platform performance, scalability, reliability, and risk reduction.
- Organization Building : Build and scale a high-performing team spanning Governance, Risk, Compliance, DevSecOps, and Cloud / Platform Security. Establish and enforce a Detection & Response strategy and ensure resilient Business Continuity and Disaster Recovery capabilities. Define clear ownership, accountability, and measurable outcomes across all domains.
SUPERVISORY RESPONSIBILITIES
Hire, lead, and develop leaders and individual contributors across Security, Architecture, and Engineering / Operations.
QUALIFICATIONS
EDUCATION :
Master's degree in information systems, Cybersecurity, Computer Science or related technical field required. Demonstrated expertise and a solid educational background can serve as an alternative to a formal degree.EXPERIENCE :
Prior experience as a CISO or senior security / architecture leader in healthcare, with a track record of architecting, securing and scaling cloud-native, consumer-facing platforms and software engineering environments.Prior experience in a large, complex healthcare organization with substantial digital assets.Proven Azure'first cloud architecture and security at scale, embedded DevSecOps in product engineering.Demonstrated FinOps ownership with sustained unit'cost reductions while meeting SLO / SLA.KNOWLEDGE, SKILLS, AND ABILITIES
Proven ability to build and mature enterprise-grade security, risk, and architecture programs across complex organizations.Expertise in cloud security, modern software architecture, and DevSecOps practices (CI / CD, SAST / DAST / IAST / SCA, IaC, container security, supply chain security).Strong background in software engineering principles with the ability to guide secure design, code quality, scalability, and reliability for large-scale platforms.Hands-on experience in platform operations : running and scaling SaaS, PaaS, and consumer-facing cloud-native solutions with defined SLAs / SLOs for performance, availability, and cost efficiency.Ability to implement and lead global security and platform programs, including incident response, threat intelligence, DLP / DR / BCP, IAM, SOC operations, security architecture, security policy / advocacy, and third-party / vendor risk.Deep knowledge of industry frameworks, standards, and regulations (SOC 2, CSA, NIST, GDPR, DPA, ISO 270xx).Business acumen : able to translate technical vulnerabilities, architectural decisions, and operational costs into enterprise risk, ROI, and board-level narratives.Superior written, verbal, and presentation skills; able to brief senior leadership and technical teams effectively.Ability to serve as both a security and architecture authority, bridging engineering, infrastructure, and business priorities.Strong industry connectivity to attract, hire, and retain high-performing talent.Results-driven, with the ability to execute in fast-paced, complex environments and lead change.High ethical standards, integrity, humility, authenticity, credibility, and character.TYPICAL WORKING CONDITIONS
Non-patient facingMay be either full time remote / telework or rotate working in the office and remote / teleworkThis job must be U.S. - basedIndoor office work; operating computer; sittingManual dexterityMay require travel