Job Description
The Vice President, Information Security serves as the senior leader responsible for establishing, executing, and continuously enhancing LCS’ enterprise information security strategy. This role provides strategic leadership and oversight for cybersecurity, information security governance, and the technology responsibilities related to risk management, privacy protection, and regulatory compliance across LCS's portfolio of communities nationwide.
This role partners with executive leadership, community leaders, operational departments, technology teams, and third-party service providers to protect organizational assets, resident information, employee data, business operations, and critical technology infrastructure. This position leads a team of information security professionals and is responsible for developing a security-first culture while balancing operational effectiveness, regulatory requirements, and business objectives.
The Vice President, Information Security plays a critical role in safeguarding resident trust, ensuring compliance with healthcare and privacy regulations, mitigating cybersecurity threats, and enabling secure business growth throughout the LCS organization.
This position reports to the SVP, Chief Information Officer.
Experience is Everything.
At LCS, experience is everything. We provide you the opportunity to use your talents in a progressive, growing organization that makes a positive difference in the lives of the seniors we serve. If you are seeking an organization that gives back, you’ll love working here. Our principles and hospitality promises define our company culture. LCS employees can be found participating in volunteer activities, getting involved in our committees or collaborating with team members in our innovative workspace. You’ll find several opportunities to grow as a professional, serve the community, and enhance the lives of seniors.
What You’ll Do:
- Information Security Strategy & Leadership
- Develop and execute a comprehensive enterprise information security strategy aligned with LCS business objectives, operational priorities, and technology roadmaps.
- Establish long-term cybersecurity vision, goals, and performance measures for corporate operations and managed communities.
- Serve as the organization's senior information security advisor to executive leadership and key stakeholders.
- Provide regular updates to executive leadership regarding the organization's security posture, emerging threats, vulnerabilities, and risk mitigation initiatives.
- Foster a culture of security awareness, accountability, and risk management throughout the organization.
- Collaborate in the development of risk appropriate strategies for adoption of new technologies such as AI.
- Cybersecurity Governance & Risk Management
- Establish and maintain enterprise-wide information security governance frameworks, policies, standards, and procedures.
- Lead cybersecurity risk assessment programs across corporate systems, community operations, cloud environments, and third-party platforms.
- Direct enterprise vulnerability management, threat assessment, and risk remediation strategies.
- Oversee cybersecurity audits, compliance reviews, and security assessments.
- Develop and maintain security metrics, dashboards, and executive reporting to measure program effectiveness.
- Ensure information security risks are appropriately identified, evaluated, escalated, and managed.
- Community Security Oversight
- Establish information security standards and controls for approximately 130 managed senior living communities across the United States.
- Collaborate with operational leaders and community executive directors to ensure consistent implementation of cybersecurity and data protection requirements.
- Develop scalable security approaches that support diverse operating environments while maintaining enterprise security standards.
- Provide advisory services related to security risks associated with community-based systems, devices, networks, and operational processes.
- Support acquisition, integration, and transition activities by ensuring information security requirements are addressed during community onboarding and disengagement activities.
- Security Operations & Incident Response
- Provide executive oversight of enterprise security monitoring, threat detection, incident response, and recovery activities.
- Lead response efforts for significant cybersecurity incidents, breaches, and business disruptions.
- Partner with infrastructure technology leaders to direct security operations programs including identity and access management, endpoint security, network security, cloud security, and threat intelligence functions.
- Ensure business continuity and disaster recovery considerations are integrated into security planning.
- Oversee post-incident reviews and continuous improvement initiatives.
- Regulatory Compliance & Privacy
- Ensure compliance with applicable federal, state, and industry regulations relating to information security, privacy, and data protection. These include but are not limited to HIPAA and SOC compliance.
- Partner with Legal, Compliance, HR, Risk Management, and Operations leadership to address regulatory and privacy-related requirements.
- Oversee security controls supporting protection of resident, patient, employee, financial, and business information.
- Monitor evolving regulatory requirements and implement necessary changes to maintain organizational compliance.
- Support internal and external audits related to cybersecurity and information security controls.
- Third-Party Risk Management
- Establish and oversee third-party cybersecurity risk management programs.
- Evaluate security controls of vendors, service providers, software applications, and business partners.
- Ensure appropriate security requirements are incorporated into contracts, service agreements, and vendor relationships.
- Monitor ongoing vendor compliance with organizational security standards.
- Team Leadership & Organizational Development
- Manage departmental budgets, resource planning, and vendor relationships.
- Drive accountability through clearly defined objectives, performance metrics, and operational priorities.
- Responsible for the effective management and leadership of a team. This includes, but is not limited to: hiring, training, coaching, evaluating and managing performance, allocating compensation, effectively handling employee relations issues, managing terminations.
- Perform other duties and responsibilities as assigned.
What We’re Looking For:
- Required:
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business Administration, or a related field; or equivalent years of experience.
- Minimum of 15 years of progressive information security or cybersecurity experience.
- Minimum of 7 years of leadership experience managing information security teams and enterprise security programs.
- Experience developing and executing enterprise cybersecurity strategies within complex, multi-site organizations.
- Experience leading cybersecurity governance, risk management, compliance, and security operations functions.
- Demonstrated experience managing significant cybersecurity incidents and organizational risk mitigation efforts.
- The following technical knowledge is required:
- Cybersecurity frameworks (NIST, CIS, ISO 27001)
- Security operations and incident response
- Vulnerability management and threat intelligence
- Identity and access management
- Cloud security platforms and controls
- Security monitoring and SIEM technologies
- Data protection and privacy regulations
- Third-party risk management
- Business continuity and disaster recovery planning
- Security architecture and infrastructure protection
- Preferred:
- Master's degree.
- Healthcare, senior living, hospitality, or highly regulated industry experience.
- Experience presenting security strategy, risk assessments, and recommendations to executive leadership and governing bodies.
- One or more of the following certifications preferred:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- GIAC Certifications
- CCSP (Certified Cloud Security Professional)
Why Join Us?
- Industry Leader.
- Inclusive & collaborative culture.
- Top Workplace USA.
- Top Workplace Iowa.
- Charity and community involvement.
- Outstanding advancement opportunities.
- Ongoing career development.
Benefits
Competitive pay, great benefits and vacation time. We are an equal opportunity employer with benefits including medical, dental, life insurance, disability, 401(K) with company match and paid parental leave.
Our Commitment
LCS creates living experiences that enhance the lives of seniors. You’ll see this commitment in our people. They’re talented, dedicated professionals who truly care about residents, with each conducting his or her work with integrity, honesty and transparency according to the principles of LCS. We strive to help every community succeed—strengthening available resources, establishing proven practices that lead to long-term growth and value for those living in, working for and affiliated with the community. Check us out on our website: https://www.lcsliving.com
Additional Information
Travel frequency: 0-10%
Estimated Salary: $171,000 - $214,000
The actual title & salary will carefully consider a wide range of factors, including your skills, qualifications, experience, and other relevant factors.
A POST-OFFER BACKGROUND CHECK, INCLUDING REFERENCES IS REQUIRED.
LCS IS AN EQUAL OPPORTUNITY EMPLOYER.