Talent.com
St. Charles Health System
Chief Information Security OfficerSt. Charles Health System • Bend, OR, United States
Chief Information Security Officer

Chief Information Security Officer

St. Charles Health System • Bend, OR, United States
5 days ago
Salary
$176,675.00–$265,000.00 yearly
Job type
  • Full-time
Job description

System Director, Information Security (CISO)

Salary range: $176,675- $265,000/year Relocation Assistance: This role offers in-state or out-of-state relocation assistance for candidates who have not worked at St. Charles Health System in the last year.

Reports To Position: SVP, Chief Information & Digital Officer

Department: Information Security

Date Last Reviewed: August 2026

Our Vision: Creating America's healthiest community, together.

Our Mission: In the spirit of love and compassion, better health, better care, better value

Our Values: Accountability, Caring and Teamwork

Department Summary: The St. Charles Health System's Information Security department identifies, assesses, reports, and helps to mitigate technical, physical, and administrative risks to St. Charles' regulated and confidential information.

Position Overview: The System Director Information Security (CISO) collaborates internally and externally to identify, assess, report, and help mitigate risks to St. Charles' physical and digital regulated and confidential information in alignment with business goals and objectives. This role leads the information security department and partners closely with IT, Privacy, Compliance, Internal Audit, HR, Legal, and other departments. The CISO develops strategy, policy, and oversees information security operations (e.g., network monitoring, threat intelligence, vulnerability management, penetration testing, data loss prevention, incident response, advisory services), third-party risk management, e-Discovery, information security risk management, awareness and education, program management, and governance. The CISO has demonstrated experience with the technical, administrative, and regulatory requirements and best practices relating to information security, privacy, and healthcare operations.

This position directly manages caregivers in the information security department.

Essential Functions and Duties:

Develops, implements, and oversees a strategic, enterprise-wide information security program to ensure the integrity, confidentiality, and availability of St. Charles' regulated and confidential information and systems.

Identifies, evaluates, and reports on information security risks in a manner that meets compliance and regulatory requirements and aligns with the organization's overall risk posture.

Establishes and facilitates information security governance through leadership and active participation in organizational governance bodies, including data governance, external data governance, technology governance, and safety governance committees.

Reports on the status of identified information security risks, provides regular updates on the evolving threat landscape, and secures executive approval for strategic initiatives to reduce St. Charles' risk exposure.

Develops, maintains, and publishes current information security policies, standards, procedures, and guidelines.

Oversees enterprise information security risk management and mitigation activities to ensure timely and effective remediation.

Collaborates with executive leadership to define acceptable levels of information security risk and ensures alignment with organizational objectives.

Partners with the System Privacy Officer to conduct risk assessments and evaluations related to HIPAA Privacy and Security Rule compliance and the Health Industry Cybersecurity Practices.

Establishes and oversees cybersecurity risk frameworks specifically governing Internet of Medical Things (IoMT) devices, clinical networks, and biomedical integration.

Drives the adoption and continuous maturity of enterprise security frameworks, aligning operations with the NIST Cybersecurity Framework (CSF), NIST AI Risk Management Framework, and HITRUST standards.

Leads and directs a dedicated technical security team responsible for executing the following core operational functions:

Security Operations & Incident Response (SOC):

  • 24/7/365 security monitoring, threat hunting, log aggregation, and event correlation using SIEM/SOAR platforms.
  • Rapid triage, containment, escalation, and post-incident root-cause analysis for security events across network, endpoint, and cloud environments.

Engineering & Architecture Implementation:

  • Design, deployment, and ongoing administration of Endpoint Detection & Response (EDR/XDR).
  • Identity & Access Management (IAM) technical oversight, including privileged access management (PAM), multi-factor authentication (MFA), and directory service security controls.

Vulnerability Management & Offensive Security:

  • Continuous vulnerability scanning, patch verification, and risk-prioritized remediation tracking across clinical, enterprise, and infrastructure assets.
  • Coordination and execution of internal/external penetration testing, red teaming exercises, and social engineering scenarios.

Data Loss Prevention (DLP) & Technical Privacy Controls:

  • Configuration and management of DLP agents, email security gateways, encryption tools, and data classification mechanisms to safeguard Protected Health Information (PHI) and corporate data.
  • Medical Device & Endpoint Security:
  • Technical discovery, isolation, and security patching for biomedical equipment, Internet of Medical Things (IoMT) hardware, and clinical workstation configurations.

Designs, implements, and manages organization-wide information security awareness and training programs for employees, contractors, and authorized system users.

Works closely with business units to facilitate information security risk assessment and management processes, engaging stakeholders across the organization to identify and manage residual risk.

Coordinates with the architecture team members to ensure security controls and strategies are aligned with enterprise architecture and technology roadmaps.

Defines and oversees the information security risk assessment process, including internal reporting and governance of remediation efforts for identified findings.

Leads the organizational response to information security incidents and events to protect St. Charles' assets, intellectual property, regulated data, and organizational reputation.

Supports Human Resources, Legal, Compliance, and Privacy functions with internal investigations, regulatory inquiries, audits, and other investigative activities as required.

Monitors the external threat environment for emerging risks and vulnerabilities and advises executive leadership and stakeholders on appropriate response strategies.

Responsible for budget development, regular monitoring, accountability and meeting all operational targets for all areas within span of control.

Hires, directs, coaches, and monitors the performance of all direct reports, to develop and maintain a high-performance team that meets organizational and department goals.

Monitors and ensures all direct reports are current with compliance and safety requirements. Implements and manages all organizational safety directives and goals.

Provides and oversees team's delivery of customer service in a manner that promotes goodwill, is timely, efficient, and accurate.

Collaborates with teams to review processes and identify/implement opportunities for improvements, applying Lean principles, concepts, and tools.

Supports the vision, mission, and values of the organization in all respects.

Supports the Lean principles of continuous improvement with energy and enthusiasm, functioning as a champion of change.

Provides and maintains a safe environment for caregivers, patients, and guests.

Conducts all activities with the highest standards of professionalism and confidentiality. Complies with all applicable laws, regulations, policies, and procedures, supporting the organization's corporate integrity efforts by acting in an ethical and appropriate manner, reporting known or suspected violation of applicable rules, and cooperating fully with all organizational investigations and proceedings.

May perform additional duties of similar complexity within the organization, as required or assigned.

Education:

Required: Bachelor's degree in information technology, information security, or related field.

Preferred: Master's degree in a related field.

Licensure/Certification/Registration:

Required: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or other similar credential(s).

Preferred: Multiple relevant industry certifications.

Experience:

Required: Minimum of seven (7) years of information security experience. Minimum of two (2) years leading and managing information security programs and leadership experience in a regulated environment (preferably healthcare).

Preferred Experience: Comprehensive cybersecurity leadership spanning technical operations, risk and compliance, governance and frameworks, privacy and regulation, cloud and emerging technologies.

Personal Protective Equipment:

Must be able to wear appropriate Personal Protective Equipment (PPE) required to perform the job safely.

Additional Position Information:

Travel: Must be able to travel to business functions/trainings/meetings and all SCHS worksites.

Physical Requirements:

Continually (75% or more): Use of clear and audible speaking voice and the ability to hear normal speech level.

Frequently (50%): Sitting, standing, walking, lifting 1-10 pounds, keyboard operation.

Occasionally (25%): Bending, climbing stairs, reaching overhead, carrying/pushing,

Create a job alert for this search

Chief Information Security Officer • Bend, OR, United States

Similar jobs

Chief Financial Officer

MonteVista HomesBend, OR, United States
Full-time

Under the general direction of the President, the Chief Financial Officer (CFO) is accountable for the financial strategy, financial health, and long-term economic sustainability of MonteVista Home... Show more

 • Promoted

Director, Direct-To-Consumer Ecommerce Hydro Flask

Helen of TroyBend, OR, United States
Full-time

Director, Direct-To-Consumer Ecommerce Hydro Flask.Drive and manage Ecommerce and digital marketing strategies and execution for hydroflask.Develop and scale the Direct-to-Consumer Ecommerce busine... Show more

 • Promoted

Director, Project Delivery (CAPEX Project Lead)

LonzaBend, OR, United States
Full-time

Director, Project Delivery (CAPEX Project Lead).Relocation assistance is available for eligible candidates and their families, if needed.Note on Travel/Location: This role will be based full-time a... Show more

 • Promoted

Shift Manager

Five GuysBend, OR, United States
Full-time

This is the job description content.It has been cleaned up to focus on the core information, removing all unnecessary tags, links, and metadata.The formatting has been adjusted to ensure consistenc... Show more

 • Promoted

Director, Quality Engineering & Computer System Assurance

Sern BioScienceBend, OR, United States
Full-time

Director, Quality Engineering & Computer System Assurance (CSA).Sern BioScience seeks a Director, Quality Engineering & Computer System Assurance (CSA) to oversee and provide strategic and operatio... Show more

 • Promoted

Project Manager

HireTalentBend, OR, United States
Full-time

IT Infrastructure Senior IT PM.Location: Bend OR, US Duration: 24 Months Brief Description of Project / Assignment:.The role is responsible for planning, overseeing and leading the delivery of IT ... Show more

 • Promoted

Transportation Security Officer (TSO) - PT or FT

TSARedmond, OR, United States
Full-time

Come join the TSA to serve in a high-stakes environment to safeguard the American way of life.No matter what your background or level of education, TSA has opportunities for a wide range of new can... Show more

 • Promoted

Chief Financial Officer

MONTEVISTA HOMESBend, OR, United States
Full-time

Under the general direction of the President, the Chief Financial Officer (CFO) is accountable for the financial strategy, financial health, and long-term economic sustainability of MonteVista Home... Show more

 • Promoted

CFO

TruelineBend, OR, United States
Full-time

Trueline is seeking a Chief Financial Officer (CFO) to join a growing residential homebuilder with a strong reputation for quality, operational excellence, and long-term success.This executive lead... Show more

 • Promoted

Director of Lodge Restaurants

CoralTree HospitalityBend, OR, United States
Full-time

The Director of Lodge Restaurants will provide oversight and management to The Lodge Kitchen, Owl's Nest, Merchant Trader Caf, and Starbucks.They will manage the training of all staff to ensure exc... Show more

 • Promoted

Site Director

HireIQ Solutions, IncRedmond, OR, United States
Full-time

Location: Central Oregon (Redmond area) On-site.Compensation: $175,000$215,000 DOE, 30% Annual Bonus Eligibility, 40% Long-Term Incentive Plan.Benefits: Comprehensive benefits package including me... Show more

 • Promoted

Safety and Training Analyst

City of Bend, ORBend, OR, United States
Full-time

The City of Bend is accepting applications for one (1) regular, full-time Safety and Training Analyst for the Public Works Department.This is a COBEA represented, overtime-eligible position.The Cit... Show more

 • Promoted

Project Manager

Katalyst Healthcares & Life SciencesBend, OR, United States
Full-time

IT Infrastructure Project Manager.The role is responsible for planning, overseeing and leading the delivery of IT and OT Infrastructure Projects in an international environment and with a scope rea... Show more

 • Promoted

Manager Infection Prevention and Caregiver Health

St. Charles Health SystemRedmond, OR, United States
Full-time

Manager Infection Prevention and Caregiver Health.Reports To Position: Director of Quality Management.Department: Quality Management.Pay range: $122,012 - $189,134 annually, based on experience.Thi... Show more

 • Promoted

Burgerville Assistant Manager Oregon NON-EXEMPT *Bend

BurgervilleBend, OR, United States
Full-time

At Burgerville, our Assistant Managers are essential leaders who help create outstanding guest experiences, develop strong teams, and support restaurant performance.This role partners closely with ... Show more

 • Promoted

Consumer Insights Analyst

Earn HausBend, Oregon, United States
Part-time

We're currently seeking motivated individuals to participate in online surveys and paid gaming opportunities for well-known national brands.If you're looking for a flexible way to earn extra cash f... Show more

 • Promoted

Site Director at Sage Elementary

Kindercare EducationRedmond, OR, United States
Full-time

Where first steps, new friendships, and confident learners are born.At KinderCare Learning Companies, we offer a variety of early education and child care options for families.Whether it's KinderCa... Show more

 • Promoted

Assistant Manager - OR

Hassan & Sons, Inc.Bend, OR, United States
Full-time

The Assistant Manager supports the Store Manager with all tasks related to a site's operation.Perform select duties and responsibilities of the Store Manager in their absence, for example, submitti... Show more

 • Promoted

Unarmed Security Officer (Bend Clinic)

Servexo USABend, OR, United States
Part-time

Company Overview Servexo USA delivers comprehensive security solutions through highly-trained personnel, advanced technology, and state-of-the-art equipment.We specialize in serving sectors such as... Show more

 • Promoted

Area Director

Fellowship of Christian AthletesBend, OR, United States
Full-time

The Director is responsible for growing the ministry by praying, staffing, and funding the area through the Advancement Lanes: Ministry, Board, Donor, Talent and International.The Director works in... Show more