← Browse all jobs

M

Director of Information Security

Massachusetts Health Connector · United States

FULL TIME

Job Description

Salary: $155,000 - 165,000 per year Requirements:

  • We require a bachelors degree from an accredited college or university and 7–10 years of cybersecurity or information security experience, including leadership responsibilities.
  • We expect demonstrated experience building and operating security capabilities across multiple domains, including identity, endpoint, cloud, and network access controls.
  • Candidates should have experience implementing and operating Zero Trust architectures across identity, devices, networks, and applications.
  • We require experience leading incident response, vulnerability management, and security monitoring programs, as well as managing vendor and third-party security risks.
  • Candidates should have experience in regulated environments handling sensitive information such as PII or PHI, and implementing security programs aligned with NIST frameworks and regulatory requirements.
  • We expect a strong understanding of IT infrastructure and platforms, including networks, operating systems, cloud environments, endpoint management, and identity services.
  • Candidates should understand modern cybersecurity architecture and controls, security operations, data classification, encryption, data loss prevention, and protection of regulated information.
  • We value familiarity with the NIST Cybersecurity Framework and related regulatory standards, along with the ability to explain complex technical risks in terms of organizational impact.
  • Candidates should bring strong collaboration, analytical, problem-solving, organizational, time-management, written communication, and verbal communication skills, as well as leadership and team-development capabilities.
  • Preferred qualifications include a degree in Information Security, Computer Science, Information Systems, Cybersecurity, or a related discipline; experience in public sector, healthcare, or regulated technology; familiarity with ARC-AMPE or CMS security guidance; CISSP, CISM, or equivalent certification; and experience developing security roadmaps or long-term strategies.
  • We require satisfactory proof of eligibility to work in the United States and completion of the Applicant Disclosure Form in connection with the stated 268A requirement.
  • The role requires the ability to commute to our downtown Boston office.
  • A bachelors degree is required; the posting also lists seven years of cybersecurity experience as required, with seven years of incident response and vulnerability management experience preferred.
Responsibilities:
  • We lead and advance our information security and risk management program to protect our systems, infrastructure, and sensitive information from evolving cyber threats.
  • We develop and maintain our Information Security Roadmap, prioritizing capabilities and investments according to organizational needs, technical risk, and regulatory obligations.
  • We oversee core security functions, including Security Operations, Governance, Risk and Compliance, Identity and Access Management, Security Architecture, and Vendor Security Risk Management.
  • We establish and maintain security policies, standards, and governance frameworks aligned with ARC-AMPE, CMS guidance, and the NIST Cybersecurity Framework.
  • We oversee threat detection, vulnerability management, security-event monitoring, and other cybersecurity defense capabilities.
  • We lead incident response, coordinating investigation, containment, remediation, and communications during security events.
  • We implement safeguards for PII, PHI, and other regulated data, including classification and data-protection controls.
  • We guide the development of our security architecture and implement Zero Trust capabilities across identity, devices, networks, and application access.
  • We manage third-party security risk, ensuring vendors, contractors, and partners meet our security and compliance expectations.
  • We partner with Infrastructure and Client Services to implement and operate controls for endpoint management, device configuration, identity platforms, and collaboration technologies.
  • We support disaster recovery, business continuity, and operational resilience planning with technology leadership.
  • We report to leadership on cybersecurity posture, operational security measures, compliance, and remediation activities.
  • We oversee staff development, hiring, performance management, and program administration.
  • We coordinate security initiatives across teams and take on other duties as assigned.
Technologies:
  • Cloud
  • CMS
  • Support
  • Network
  • Security
  • IAM

More:

We are the Commonwealth Health Insurance Connector Authority, an independent public authority operating Massachusettss Affordable Care Act-compliant health insurance marketplace. We provide subsidized and unsubsidized coverage to individuals and small employers, oversee health-reform policy, and conduct public education and outreach. The Director of Information Security reports to our Chief Technology Officer and works with IT and Operations leadership, Infrastructure, Data & Analytics, Legal, Compliance, and internal and external partners. This is a hybrid role based in downtown Boston, with two days in the office and three days working from home; extended days or weekends may occasionally be needed to meet deadlines. The annual salary is $155,000–$165,000. Benefits include dental, health, and vision insurance, an employee assistance program, paid time off, parental leave, and a retirement plan. We are an equal-opportunity employer and value diversity in our workforce.

last updated 40 week of 2026

Details

CompanyMassachusetts Health Connector
LocationUnited States
TypeFULL TIME
Nichegeneral

Similar Jobs

T

Assistant manager

The House Of Shubhashish

M

Property host i guest experience i boutique hospitality

MansionHaus

M

Head - corporate relations

MIT Academy Of Engineering

I

Network & systems administration senior analyst [t500-29329]

Inspire

V

Sap group reporting consultant

VOLTO Consulting