When you join the growing BILH team, you're not just taking a job, you’re making a difference in people’s lives.
The Director of Security Governance, Risk & Compliance, leads and manages the Governance Risk and Compliance (GRC) function and is responsible for partnering with the It Security Leader in managing an organization-wide, information risk management program, security compliance program and security awareness campaign. The Director partners with administrative, andJob Description:
Primary Responsibilities:
Leads IT Security Governance, Risk and Compliance program. (essential)
Collaborates with IT Security Leader on building a culture focused on proactive risk management and security best practices. (essential)
Leads IT Security Steering Committee, infusing information security governance procedures that foster resiliency, raise awareness, govern policy and review security related activities. (essential)
Provides clear risk mitigating directives for projects with IT components. (essential)
Responsible for the development, implementation, and execution of BILH-wide information security training and awareness programs. Provides professional and technical training and direction for internal team members as well as
external staff. (essential)
Facilitates and participates in annual internal/external audits using industry standard security methods to help strengthen internal security controls, procedures and policies. (essential)
Investigates security incidents, develop remediation plans, and work with appropriate stakeholders to implement resolutions. (essential)
Serves as a lead advisor on security matters to ensure appropriate levels of security are integrated in process designs and architecture; demonstrates ability to be a respected information security advisor to senior management, as well as to IT Shared Service team. (essential)
Works with IT Security team in the development and acceptance of IT policies and procedures; ensures program standards follow applicable State and Federal regulatory requirements. (essential)
Stays current with all relevant IT security and compliance issues, technologies, and requirements, as well as with emerging best practices in IT program management, planning and governance; Maintains professional and technical knowledge by attending industry workshops, conferences, and participating in personal and professional networks. (essential)
Has the authority to direct and support employees daily work activities. Has the direct responsibility to undertake the following employment actions: hiring, termination, corrective action and performance reviews.
Direct Reports: 2-3
Indirect Reports: None
Required Qualifications:
Bachelor's degree required. Master's degree in Law degree preferred.
More than 10 years related work experience required and 3-5 years supervisory/management experience required
At least 10 years of varied information technology management experience is required, five years of which must be directly related to IT program management and planning as well as computer, information, and network security
assessment, administration, and management.
Experience in the health care industry is essential along with knowledge about program management, information security technology, medical records, patient privacy and confidentiality.
Other key requirements include project planning and project management experience; Advanced technical computer skills as required for technical support specific to functional area and related systems.
Pay Range:
$176,800.00 USD - $205,920.00 USDThe pay range listed for this position is the annual base salary range the organization reasonably and in good faith expects to pay for this position at this time. Actual compensation is determined based on several factors, that may include seniority, education, training, relevant experience, relevant certifications, geography of work location, job responsibilities, or other applicable factors permissible by law.
Anna Jaques Hospital is a 123 bed community hospital serving 17 cities and towns in the Merrimack Valley . The hospital offers a wide range of acute care services to meet the needs of our growing patient population including inpatient and outpatient surgery in fully digitized computerized operating room suites, cardiology including echocardiography and a cardiac cath lab, comprehensive cancer services, orthopedics, nuclear medicine, laboratory, noninvasive vascular lab, joint replacement program and birth center.
Programs include the number one wound center in the nation, a primary stroke service, and Level III Trauma Center . Diagnostic imaging services for patients include MRI, CT, PET, and the PACS digital x-ray system. In addition, we are one of only three healthcare communities to be selected for the pilot Massachusetts e-Health Collaborative. Due to the dedication of our physicians, we are one of the first communities in Massachusetts to implement electronic health records, system-wide, for the safety of our patients.

The hospitals Non Invasive Vascular laboratory was accredited by the Intersocietal Commission for the Accreditation of Vascular Laboratories (ICAVL).
For the second year in a row, the American Association for Respiratory Care awarded the hospital its Quality Respiratory Care Recognition. The hospital had no ventilator acquired pneumonia cases during the last year.
The Wound Healing & Hyperbaric Center is the only such center to receive full accreditation from the Undersea and Hyperbaric Medical Society (UHMS) in Massachusetts .
The hospital is accredited by The Joint Commission, an organization that surveys and rates the performance of hospitals at least every three years. The Joint Commission Dedicated, good employees are one of your strengths. You have a lot to be proud of.