Dir, Security Operations
PDS Health - Irvine, CA
Hiring: Dir, Security Operations Company: PDS Health Location: Irvine, CA Job Posted Time: 2026-09-15 14:27:31 Employment Type: Hybrid Target Skills & Keywords : AI, Electronic Health Records, HIPAA, PCI DSS, Penetration Testing, Risk Management, SIEM, SaaS About the job Experience: •10+ years of progressive experience in security operations, information security, technology risk, or security engineering in an enterprise environment. •5+ years in a security leadership position. Required Skills: •Develop, implement, enforce, and monitor a comprehensive, intelligence-led security program covering networks, endpoints, cloud and SaaS services, applications, AI systems, web and digital assets, and the human layer. •Maintain effective 24x7 security monitoring, triage, escalation, and response coverage through the right combination of internal teams, automation, and managed security services; establish service-level objectives, playbooks, quality controls, and clear handoffs across security and IT operations. •Advance risk-based detection engineering, threat intelligence, and proactive threat hunting mapped to adversary behaviors, critical business services, identity pathways, and known control gaps. •Lead a risk-based vulnerability, exposure, and attack-surface management program that prioritizes exploitability, asset criticality, and clinical impact - not severity scores alone, with transparent ownership, remediation targets, and governance across infrastructure, applications, cloud, endpoints, medical and dental technology, and third parties. •Establish security guardrails and governance for automation, robotic process automation, and citizen development, enabling low-code/no-code innovation while managing the risks of unmanaged applications, data flows, and integrations. •Oversee cloud and SaaS security operations, including posture management, secure configuration, workload protection, and identity threat detection across multi-cloud and hybrid environments. •Direct application and web/digital asset security, including secure development lifecycle practices, web application protection, external attack-surface management, and penetration testing and control validation. •Own the human layer of defense{{:}} security awareness training, phishing simulation, and insider-risk programs and campaigns across all PDS Health team members and supported practices. Qualifications: •Bachelor’s Degree in Arts/Sciences (BA/BS) Cybersecurity, IT / Information Security, Computer Science, Engineering, or a related discipline, equivalent progressive experience will be considered. •Healthcare industry experience, including protecting ePHI and securing clinical environments, and demonstrated ability to conduct and lead risk assessments against HIPAA/HITECH, HITRUST CSF, ISO/IEC 27001, PCI-DSS, and NIST frameworks. •Two or more information security certifications such as CISSP, CISM, CISA, HCISPP, or equivalent. •Demonstrated leadership of significant cyber incidents and cross-functional response involving executive stakeholders, technical teams, legal or external stakeholders. •Solid functional working knowledge of securing or governing AI systems, automation platforms, and low-code/no-code (citizen development) environments, and of the threat landscape these technologies create. •The ability to communicate clearly with audiences, ranging from operational staff to senior executives. •Master’s degree in Arts/Sciences (MA/MS) Cybersecurity, IT / Information Security, Computer Science, Engineering, or a related discipline. •One or more risk, cloud, or specialized certifications such as CRISC, CCSP, HCISPP, GIAC (incident response, forensics, or security operations), or equivalent. Compensation: •$169,000 - $227,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!