Overview
Chief Information Security Officer Jobs in Arlington, VA at KamisPro
Title: Chief Information Security Officer
Company: KamisPro
Location: Arlington, VA
Must be local to DC metro area and able to work on-site 3 days per week. This is a consulting role that will convert to full time employee. Thank you.
Job Title: Chief Information Security Officer (CISO)
Job Description:
Seeking a highly experienced Chief Information Security Officer (CISO) to lead and manage our cybersecurity program. The ideal candidate will have a robust background in IT security with specialized knowledge of the regulatory landscape affecting healthcare organizations.
Key Responsibilities:
Managed Security Services (MSSP/MDR) Orchestration
- Ability to design and operationalize a multi-tier SOC model (e.g., CrowdStrike Falcon Complete + MSSP + internal oversight)
- Experience defining escalation paths, SLAs, and visibility standards across third-party security operators
- Strong understanding of shared responsibility models and how to maintain accountability despite outsourcing
Security Operations Engineering & Runbook Maturity
- Proven capability to build and enforce standardized incident response runbooks integrated with platforms like ServiceNow
- Experience eliminating “email-driven security” in favor of ticket-based, auditable workflows
- Ability to drive measurable KPIs (MTTD, MTTR, containment time) and operational rigor
Identity & Access Governance at Scale (IGA + Clinical Systems)
- Deep experience with identity platforms such as SailPoint, including aggregation timing, role engineering, and transform logic
- Understanding of healthcare-specific identity challenges (e.g., Epic EMP/SER records, provider onboarding/offboarding latency)
- Ability to reduce identity risk through automation and authoritative source alignment (e.g., Workday dependencies)
Epic Security & Clinical Workflow Integration
- Working knowledge of Epic security constructs (Hyperspace roles, templates, SER/EMP relationships)
- Ability to align cybersecurity controls with clinical operations without disrupting patient care
- Experience resolving ownership ambiguity between application, infrastructure, and security teams
Third-Party Risk Management (TPRM) at Scale
- Experience managing large vendor ecosystems (e.g., thousands of accounts, remote access pathways, VPN/IPSec exposure)
- Ability to translate vendor risk into executive-level metrics and enforce standardized onboarding/security controls
- Familiarity with tools like SecurityScorecard and OneTrust, including cost-benefit optimization
Security Architecture (Hybrid Healthcare Environment)
- Strong architectural understanding across:
- Microsoft 365 security stack (Defender, Entra, Purview)
- Network security (Palo Alto, VPN, NAC)
- Endpoint detection and response (CrowdStrike)
- Ability to rationalize tool overlap and drive platform consolidation
Data Protection & eDiscovery Strategy
- Hands-on experience with data classification, retention, and legal hold capabilities (e.g., Microsoft Purview)
- Understanding of healthcare data sensitivity and regulatory implications for PHI
Operational Governance & Service Management Discipline
- Experience implementing structured workflows, including:
- Ticket lifecycle standards (on-hold limits, closure criteria)
- On-call models and escalation protocols
- Ability to enforce accountability across internal teams and vendors
Quantitative Risk & Control Effectiveness Measurement
- Ability to move beyond qualitative assessments to measurable control validation (documentation, implementation, evidence model)
- Experience building executive dashboards (e.g., PowerBI) tied to risk reduction and control performance
Cybersecurity Program Financial Management
- Experience managing large security budgets, including:
- Capital vs. operating expense decisions
- Vendor cost optimization and contract structuring
- Ability to justify investments using risk reduction and operational efficiency metrics
Healthcare-Specific Incident Readiness
- Experience coordinating incident response across clinical, legal, compliance, and executive teams
- Familiarity with downtime procedures and patient safety implications during cyber events
Automation-First Security Mindset
- Demonstrated ability to reduce manual effort through automation across:
- Identity provisioning
- Incident response
- Vendor onboarding
- Strong bias toward scalable, repeatable processes
Executive & Board-Level Communication
- Ability to translate technical risk into business impact (patient safety, operational disruption, financial exposure)
- Experience presenting to boards, audit committees, and insurers (e.g., cyber insurance alignment)
Regulatory Strategy Beyond Compliance
- Ability to operationalize frameworks like NIST CSF 2.0 in parallel with HIPAA/HITRUST
- Experience aligning regulatory requirements with actual security outcomes, not just audit readiness
Qualifications:
- Proven leadership in IT security
- Understanding of HIPAA, HITECH, and HITRUST frameworks, and their application in a healthcare setting.
- Strong knowledge of healthcare IT systems, data protection strategies, and clinical technology integration preferred.
- Relevant certifications such as CISSP, CISM, CISA, or HITRUST Certified CSF Practitioner are highly desirable.
- Excellent communication skills with the ability to present complex issues to executive leadership and cross-functional teams.
- Bachelor’s degree in cybersecurity, information systems, or related field (Master’s preferred).