Director of Information Security
Massachusetts Health Connector · United States
Job Description
Salary: $155,000 - 165,000 per year Requirements:
- We require a bachelors degree from an accredited college or university and 7–10 years of cybersecurity or information security experience, including leadership responsibilities.
- We expect demonstrated experience building and operating security capabilities across multiple domains, including identity, endpoint, cloud, and network access controls.
- Candidates should have experience implementing and operating Zero Trust architectures across identity, devices, networks, and applications.
- We require experience leading incident response, vulnerability management, and security monitoring programs, as well as managing vendor and third-party security risks.
- Candidates should have experience in regulated environments handling sensitive information such as PII or PHI, and implementing security programs aligned with NIST frameworks and regulatory requirements.
- We expect a strong understanding of IT infrastructure and platforms, including networks, operating systems, cloud environments, endpoint management, and identity services.
- Candidates should understand modern cybersecurity architecture and controls, security operations, data classification, encryption, data loss prevention, and protection of regulated information.
- We value familiarity with the NIST Cybersecurity Framework and related regulatory standards, along with the ability to explain complex technical risks in terms of organizational impact.
- Candidates should bring strong collaboration, analytical, problem-solving, organizational, time-management, written communication, and verbal communication skills, as well as leadership and team-development capabilities.
- Preferred qualifications include a degree in Information Security, Computer Science, Information Systems, Cybersecurity, or a related discipline; experience in public sector, healthcare, or regulated technology; familiarity with ARC-AMPE or CMS security guidance; CISSP, CISM, or equivalent certification; and experience developing security roadmaps or long-term strategies.
- We require satisfactory proof of eligibility to work in the United States and completion of the Applicant Disclosure Form in connection with the stated 268A requirement.
- The role requires the ability to commute to our downtown Boston office.
- A bachelors degree is required; the posting also lists seven years of cybersecurity experience as required, with seven years of incident response and vulnerability management experience preferred.
- We lead and advance our information security and risk management program to protect our systems, infrastructure, and sensitive information from evolving cyber threats.
- We develop and maintain our Information Security Roadmap, prioritizing capabilities and investments according to organizational needs, technical risk, and regulatory obligations.
- We oversee core security functions, including Security Operations, Governance, Risk and Compliance, Identity and Access Management, Security Architecture, and Vendor Security Risk Management.
- We establish and maintain security policies, standards, and governance frameworks aligned with ARC-AMPE, CMS guidance, and the NIST Cybersecurity Framework.
- We oversee threat detection, vulnerability management, security-event monitoring, and other cybersecurity defense capabilities.
- We lead incident response, coordinating investigation, containment, remediation, and communications during security events.
- We implement safeguards for PII, PHI, and other regulated data, including classification and data-protection controls.
- We guide the development of our security architecture and implement Zero Trust capabilities across identity, devices, networks, and application access.
- We manage third-party security risk, ensuring vendors, contractors, and partners meet our security and compliance expectations.
- We partner with Infrastructure and Client Services to implement and operate controls for endpoint management, device configuration, identity platforms, and collaboration technologies.
- We support disaster recovery, business continuity, and operational resilience planning with technology leadership.
- We report to leadership on cybersecurity posture, operational security measures, compliance, and remediation activities.
- We oversee staff development, hiring, performance management, and program administration.
- We coordinate security initiatives across teams and take on other duties as assigned.
- Cloud
- CMS
- Support
- Network
- Security
- IAM
More:
We are the Commonwealth Health Insurance Connector Authority, an independent public authority operating Massachusettss Affordable Care Act-compliant health insurance marketplace. We provide subsidized and unsubsidized coverage to individuals and small employers, oversee health-reform policy, and conduct public education and outreach. The Director of Information Security reports to our Chief Technology Officer and works with IT and Operations leadership, Infrastructure, Data & Analytics, Legal, Compliance, and internal and external partners. This is a hybrid role based in downtown Boston, with two days in the office and three days working from home; extended days or weekends may occasionally be needed to meet deadlines. The annual salary is $155,000–$165,000. Benefits include dental, health, and vision insurance, an employee assistance program, paid time off, parental leave, and a retirement plan. We are an equal-opportunity employer and value diversity in our workforce.
last updated 40 week of 2026
Details
| Company | Massachusetts Health Connector |
| Location | United States |
| Type | FULL TIME |
| Niche | general |
