The Manager, Cybersecurity is responsible for leading COPC’s cybersecurity program, protecting the confidentiality, integrity, and availability of clinical, financial, and administrative systems across all COPC practice sites. This position oversees security operations, threat detection and incident response, vulnerability management, identity and access management, and security awareness training, and manages the analysts and engineers who support these functions. Using sound judgment and technical expertise, the Manager translates enterprise risk into actionable controls, partners with IT, Compliance, and clinical leadership to safeguard patient data and support HIPAA and SOC compliance, and helps mature COPC’s security posture as the organization grows. The role serves as a key escalation point during security incidents and is accountable for maintaining a defensible, well-documented cybersecurity program across a multi-site healthcare enterprise.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
· Develop, implement, and continuously mature COPC's cybersecurity program, including policies, standards, and procedures aligned to recognized frameworks such as NIST CSF and SOC.
· Lead day-to-day security operations, overseeing SIEM, endpoint detection and response (EDR), firewalls, and intrusion detection/prevention systems to identify, triage, and respond to threats in real time.
· Own and continuously improve COPC's security incident response plan; lead investigation, containment, eradication, and recovery efforts for security incidents, and coordinate tabletop exercises to validate readiness.
· Manage the vulnerability management program, including recurring vulnerability scanning, patch prioritization, coordination of penetration testing, and tracking of remediation across servers, endpoints, network devices, and cloud environments.
· Lead and develop a high-performing team, which includes interviewing and selection of new employees, onboarding, coaching, training, professional development, conflict resolution and disciplinary action and follow-up. Ensure completion of performance reviews and related actions for direct and indirect reports and address personnel processes/issues including conflict management, goal attainment and disciplinary action (as needed).
· Lead and mentor Cybersecurity team members while ensuring consistency and accountability across COPC, ensuring scope, deliverables and budgets achieve expectations; foster a culture of accountability, collaboration, continuous improvement, and innovation.
· Partner with IT infrastructure, network, applications, and EHR teams to embed security requirements into system design, cloud migrations, integrations, and new technology deployments across all COPC practice sites.
· Administer identity and access management controls, including privileged access management, multi-factor authentication, periodic access reviews, and enforcement of least-privilege principles across clinical and business systems.
· Own third-party and vendor risk management, including security assessments of business associates and vendors handling protected health information, and ensure Business Associate Agreements reflect appropriate security obligations.
· Ensure ongoing compliance with HIPAA, SOC, and other applicable regulatory and payer security requirements; support internal and external security audits, risk assessments, and regulatory inquiries.
· Design, implement, and measure the effectiveness of COPC's security awareness training while managing a regular phishing simulation program for all workforce members.
· Partner with the CIO to manage the security tooling budget and licensing, while evaluating emerging security technologies to recommend investments that reduce organizational risk.
· Maintain data loss prevention, encryption, and secure backup controls, and participate actively in business continuity and disaster recovery planning and testing.
· Prepare and present security metrics, risk assessments, and program updates to IT leadership, executive stakeholders, and the Compliance Committee.
· Serve as a subject matter expert and primary escalation point for security-related questions and incidents across the organization, including escalation of urgent matters to the CIO; provide after-hours response as needed.
· Other duties as assigned.

At Central Ohio Primary Care (COPC), we’re building something different: a healthcare model where people always come first — our patients and our team members.
As a physician-owned and led organization, we understand that great care begins with those who provide it. We support our physicians, advanced practice providers, clinical staff, and administrative teams with a collaborative environment that values compassion, innovation, and excellence.
Whether you’re delivering direct patient care or working behind the scenes, your role at COPC contributes to better health outcomes across central Ohio. We care for patients at every stage of life, including preventive care, diagnosis, chronic condition management, and treatment.
Join us at COPC and be part of a team that’s making a meaningful impact on individuals, families, and the communities we serve.