Cybersecurity Manager
Confluence Health Chelan County, Washington, United States
Hospitals and Health Care · 1,001-5,000 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Cybersecurity Manager provides leadership for cybersecurity operations, identity management, and network security engineering within a regulated healthcare environment. This role translates security strategy into daily operations, manages staff development, and serves as the primary escalation point for security incidents.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and at least 6 years of progressive experience in cybersecurity or related disciplines. Additionally, the role requires 2 or more years of formal leadership experience and at least two professional security certifications.
Benefits
Full description
Salary Range
$55.87 - $96.87 Overview
Located in the heart of Washington, we enjoy open skies, snow-capped mountains, and the lakes and rivers of the high desert. We are the proud home of orchards, farms, and small communities. Confluence Health actively supports the communities we serve and their quality of life through our community support program and through our individual efforts as involved community members.
Full Time Employees of Confluence Health receive a wide range of benefits in addition to compensation.
- Medical, Dental & Vision Insurance
- Flexible Spending Accounts & Health Saving Accounts
- Paid Time Off
- Generous Retirement Plans
- Life Insurance
- Long-Term Disability
- Gym Membership Discount
- Tuition Reimbursement
- Employee Assistance Program
- Adoption Assistance
- Shift Differential
For more information on our Benefits & Perks, click here!
Summary
The Cybersecurity Manager provides people leadership and operational management for the organization’s cybersecurity operations, identity/access, and network security engineering functions in a regulated healthcare environment. Reporting to the Information Security Officer, Director, this role converts security strategy, risk priorities, policies, and regulatory expectations into coordinated daily operations, measurable service outcomes, resilient technical practices, and staff development. The manager oversees workload, staffing, service delivery, incident coordination, technology operations, project execution, documentation, metrics, vendor performance, and cross-functional collaboration. The position serves as the primary management escalation point for assigned teams while preserving the Information Security Officer’s accountability for enterprise security governance, risk acceptance, regulatory oversight, executive reporting, and strategic direction.
Position Reports To: Information Security Officer, Director
Essential Functions
- Directly supervises assigned staff across cybersecurity, security operations/identity, and network security engineering. Establishes clear expectations, assigns work, reviews results, provides regular coaching and feedback, supports career development, manages performance, and promotes cross-training and succession readiness.
- Translates priorities established by the Information Security Officer into team plans, service objectives, assignments, schedules, and measurable outcomes. Balances operational support, incidents, projects, maintenance, compliance activities, and technical debt using risk and business impact.
- Oversees daily security monitoring, alert triage, investigation, containment, remediation, recovery coordination, vulnerability management, and operational use of security platforms. Ensures activity is timely, documented, repeatable, and escalated according to approved procedures.
- Oversees operational identity and access workflows, including account lifecycle support, authentication controls, privileged access processes, access reviews, exception handling, and audit evidence. Partners with application, HR, Compliance, Privacy, and IT teams to improve access governance and reduce inappropriate access risk.
- Oversees secure operation and lifecycle management of enterprise network and network security services, including WAN/LAN, wireless, firewalls, segmentation, secure remote access, network access control, load balancing, monitoring, and connectivity dependencies. Ensures resiliency, change discipline, documentation, and effective escalation during outages or security events.
- Serves as the management escalation point for cybersecurity incidents, identity-related events, network disruptions, and high-impact operational issues. Coordinates technical resources, communications, evidence preservation, remediation, recovery, root-cause follow-up, and after-action improvements. Promptly escalates material risk and required decisions to the Information Security Officer.
- Maintains effective intake, prioritization, escalation, and closure practices for incidents, requests, problems, and recurring work. Reviews queues, dashboards, documentation, service quality, aging items, and customer-impacting trends; addresses barriers and drives corrective actions.
- Ensures assigned security and network platforms are maintained, monitored, documented, supported, and operated in accordance with approved architecture, change management, access, backup, recovery, and configuration standards. Coordinates lifecycle plans, capacity needs, upgrades, and operational readiness.
- Leads or supports security and network initiatives, implementation planning, resource coordination, testing, operational acceptance, documentation, and transition to support. Ensures changes follow organizational change controls and that operational risks, dependencies, and rollback considerations are identified.
- Develops and maintains meaningful team metrics, service dashboards, risk and remediation tracking, initiative status, trend analysis, and management summaries. Uses results to improve performance, resource planning, reliability, control effectiveness, and executive visibility through the Information Security Officer.
- Implements and monitors operational practices supporting HIPAA Security Rule requirements, organizational policies, audit commitments, contractual security requirements, DNV-related expectations, and other applicable obligations. Coordinates evidence collection, remediation tracking, access/process reviews, and audit readiness without assuming the designated HIPAA Security Officer function.
- Manages day-to-day vendor relationships, support performance, licensing, renewals, quotes, and assigned contracts. Assists the Information Security Officer with capital and operating budget development, forecasting, prioritization, and business justification.
- Builds effective working relationships with IT, Clinical Applications, Privacy, Compliance, Legal, Human Resources, Project Management, business leaders, and vendors. Communicates operational risk, service impacts, priorities, and decisions in clear business and technical terms.
- Ensures procedures, runbooks, standards, inventories, architecture references, escalation paths, and knowledge articles are current, usable, and consistently followed. Recommends policy and control improvements to the Information Security Officer.
- Maintains current knowledge of cybersecurity threats, healthcare security requirements, identity and access practices, network security, and leadership methods. Participates in after-hours support or on-call escalation as assigned.
- Performs other duties as assigned.
Demonstrate standards of behavior and adhere to the Code of Conduct in all aspects of job performance at all times.
Qualifications
Required:
- Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or an equivalent combination of education and relevant experience.
- 6 years of progressive experience in cybersecurity, information security, identity/access security, network security, or related enterprise technology disciplines and 2 or more years of formal leadership, supervision, or management experience within technical or security teams.
- Two or more certifications such as CISSP, CISM, Security+, CCNP Security, GIAC, CRISC, or a role-aligned cloud, identity, network, or vendor certification.
Required:
- Experience in healthcare or another highly regulated environment.
- Experience with Microsoft security technologies, SIEM/SOAR, endpoint security, vulnerability/exposure management, firewalls, network access control, privileged access management, identity governance, cloud security, and secure remote access.
Physical/Sensory Demands
O = Occasional, represents 1 to 25% or up to 30 minutes in a 2 hour workday.
F = Frequent, represents 26 to 50% or up to 1 hour of a 2 hour workday.
C = Continuous, represents 51% to 100% or up to 2 hours of a 2 hour workday.
Physical/Sensory Demands For This Position:
- Walking - F
- Sitting/Standing - F
- Reaching: Shoulder Height - O
- Reaching: Above shoulder height - O
- Reaching: Below shoulder height - O
- Climbing - O
- Pulling/Pushing: 25 pounds or less - O
- Pulling/Pushing: 25 pounds to 50 pounds - O
- Pulling/Pushing: Over 50 pounds - O
- Lifting: 25 pounds or less - O
- Lifting: 25 pounds to 50 pounds - O
- Lifting: Over 50 pounds - O
- Carrying: 25 pounds or less - O
- Carrying: 25 pounds to 50 pounds - O
- Carrying: Over 50 pounds - O
- Crawling/Kneeling - O
- Bending/Stooping/Crouching - O
- Twisting/Turning - O
- Repetitive Movement - F
Working Conditions:
- Works with substantial independence and discretion in a fast-paced healthcare technology environment. May require flexible hours, participation in an after-hours escalation rotation, and response to cybersecurity incidents, technology outages, planned maintenance, or urgent operational needs. The position regularly handles confidential, security-sensitive, and potentially regulated information and must follow organizational privacy, security, records, and acceptable-use requirements.
Job Classification:
- FLSA: Exempt
- Hourly/Salary: Salary
Physical Exposures For This Position:
- Unprotected Heights - No
- Heat - No
- Cold - No
- Mechanical Hazards - No
- Hazardous Substances - No
- Blood Borne Pathogens Exposure Potential - No
- Lighting - Yes
- Noise - Yes
- Ionizing/Non-Ionizing Radiation - No
- Infectious Diseases - No
Similar roles
-
Cryptography Cybersecurity Expert
Inetum Lisbon, Portugal
-
IT Security Engineer
JYSK Aarhus, Central Denmark Region, Denmark
-
Cybersecurity Specialist (5+y)
Bridge 351 Lisbon, Portugal
-
Cybersecurity Co-Founder / Head of Sales (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany
-
Product Security Engineer (m./f./div.)
Keenfinity Ovar, Portugal
-
M04 - IT Security Engineer
FPT Asia Pacific Pte Ltd Singapore, Singapore