VHC Health

Director, Cybersecurity Compliance

VHC Health  •  Arlington, VA (Onsite)  •  7 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Position Title

Director, Cybersecurity Compliance

Purpose & Scope:

The Director of Cybersecurity Compliance leads the healthcare organization’s information security governance, risk, and compliance (GRC) program. This role is accountable for defining regulatory requirements, establishing risk management frameworks, and independently assessing the effectiveness of cybersecurity controls to ensure alignment with healthcare regulations, patient privacy obligations, and industry standards.

This leader serves as the independent oversight function for cybersecurity, ensuring that controls implemented by cybersecurity and IT teams meet regulatory, audit, and risk expectations without introducing bias from operational ownership. The Director partners closely with cybersecurity operations, clinical leadership, legal, and compliance to embed security and compliance into workflows while maintaining safe and uninterrupted patient care.

Education:

Bachelor’s degree in Information Security, Information Technology, Healthcare Administration, or related field. Master’s preferred.

Experience:

10+ years of experience in IT security, risk, or compliance, with significant experience in healthcare

5+ years in a leadership role within a healthcare or regulated environment

Knowledge and Skills

  • Deep knowledge of healthcare regulations (HIPAA/HITECH) and security frameworks (NIST, HITRUST, ISO)
  • Strong understanding of risk management methodologies and audit practices
  • Experience with GRC platforms and compliance tooling
  • Ability to independently assess control effectiveness and identify gaps
  • Strong understanding of PHI handling, privacy requirements, and breach response obligations
  • Ability to translate regulatory requirements into practical governance structures

Certification/Licensure:

  • CISSP, CISM, CISA, or CRISC, preferred
  • HCISPP (Healthcare Information Security and Privacy Practitioner), preferred
  • HITRUST CCSFP, preferred
VHC Health

About VHC Health

VHC Health® is a leading not-for-profit health system serving the Washington, DC metropolitan area since 1944. Anchored by a 453-bed teaching hospital, we provide exceptional care through advanced technology and patient-centered practices. We provide primary and specialty care to advanced specialties, including a Level II Trauma Center and a Level III Neonatal Intensive Care Unit.

With a growing network of locations, we bring top-quality healthcare closer to where patients live and work. Recognized by numerous awards and proudly holding the Magnet® designation for nursing excellence, VHC Health is committed to quality, safety, and patient experience. Partnering with distinguished providers, we strive to improve health outcomes and enhance the well-being of the communities we serve.

Join the VHC Health team: https://www.vhchealth.org/careers/

If you have questions, please contact our recruitment team at: 703.558.8109 or recruitment@vhchealth.org.

Get a behind-the-scenes look at Life At VHC Health:

- https://www.facebook.com/LifeatVHCHealth

- https://twitter.com/LifeatVHCHealth

- https://www.instagram.com/lifeatvhchealth

Industry
Healthcare & Social Services
Company Size
1,001-5,000 employees
Headquarters
Arlington, VA
Year Founded
1944
Social Media