Director, Information Security Operations

2 months ago


Remote, Oregon, United States Consensus Cloud Solutions Full time

Consensus Cloud Solutions is a publicly traded, leading digital cloud fax and interoperability solutions organization in the United States and globally, focusing on connecting and empowering healthcare providers, payers, care teams, and technology innovators to unify multiple systems that wouldn't otherwise talk to each other. Consensus is a trailblazer in our industry and believes that data transformation will reshape the world of healthcare.

Founded over 25 years ago, Consensus leverages its technology heritage to move from simple digital documents to advanced healthcare standards (HL7/FHIR) for secure data transport, as well as Natural Language Processing (NLP) and Artificial Intelligence (AI) to convert unstructured to structured, analytics-ready data, helping users unveil information that is meaningful and actionable for better patient care.

With more than 11 million users worldwide, Consensus leads the industry in data exchange solutions and we're only getting started With exciting new initiatives on the horizon, we are continuing our strategic expansion and we are looking to add to our diverse team of innovators.

Now is the ideal time to join us in our mission to solve healthcare's biggest challenges, and work collaboratively with a diverse team of like-minded self-starters and partners to accomplish it.

Consensus Cloud Solutions is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive and equitable environment for all employees. We offer many remote and hybrid career opportunities.


How you will impact the organization...

The Director of Information Security Operations at Consensus Cloud Solutions is pivotal in maintaining the organization's security operations and security posture. This role encompasses leading and managing the security operations center, overseeing security monitoring, alerting, and vulnerability management to ensure system, data, and software security, collecting and analyzing security event logs to identify and mitigate risks, and implementing continuous monitoring for real-time threat detection. They are responsible for asset protection monitoring, automating access reviews and approval workflows, monitoring least privilege access, and minimizing attack surfaces to reduce potential entry points for cyber threats. Additionally, they oversee asset management, patch management and protection, support internal and external audits to ensure compliance and lead security incident response to resolve security issues effectively. Maintaining the centralized log collection and monitoring platform is also a top responsibility for this role. Reporting security metrics to management is also vital, providing actionable insights for strategic decisions. This director collaborates with executives and various departments and team leads, including Engineering, Product Management, IT, Network Operations, Project Management, Sales, Marketing, Legal, Internal Audit, HR, and external partners, to uphold and enhance the security framework and compliance standards of Consensus Cloud Solutions.

The value you will deliver...

  • Maintain the organization's global security operations functions, lead and continue to develop the security operations center and security posture, ensuring alignment with regulatory requirements and internal policies across all regions.
  • Manage the vulnerability management program and oversee patch management processes by collaborating with cross-functional teams and system owners who deploy the patches to ensure all software and systems are regularly updated with the latest security patches, reducing vulnerabilities and enhancing system integrity.
  • Conduct vulnerability scanning to systematically identify security weaknesses, assess the severity of risks, and prioritize remediation efforts to mitigate potential threats.
  • Implement continuous monitoring systems to provide real-time detection and response to security incidents, ensuring constant vigilance and quick reaction to emerging threats.
  • Monitor asset protection to secure critical assets from unauthorized access, theft, or damage, employing advanced security measures and monitoring tools.
  • Manage access reviews and approvals by regularly reviewing access controls, ensuring access rights are granted based on the principle of least privilege, and promptly addressing discrepancies.
  • Minimize attack surfaces by identifying and mitigating potential entry points for cyber threats, employing strategies to reduce the organization's risk exposure.
  • Oversee asset management and protection by maintaining an accurate inventory of IT assets, implementing robust security measures throughout their lifecycle, and ensuring secure decommissioning of assets.
  • Support internal and external audits by providing comprehensive documentation, addressing audit findings, and implementing necessary corrective actions to ensure compliance with security policies and regulations.
  • Lead security incident response efforts by developing and maintaining an incident response plan, coordinating investigations, managing communication during incidents, and ensuring effective resolution and post-incident analysis.
  • Monitor and report security metrics to management, developing key performance indicators (KPIs), and providing actionable insights and regular updates to inform strategic security decisions and demonstrate the effectiveness of security measures.
  • Collaborate with executives and various departments, including Engineering, Product Development, IT, Network Operations, Project Management, Sales, Marketing, Legal, Internal Audit, HR, and external partners, to ensure integrated security practices that support the organization's objectives.
  • Uphold and enhance the security framework and compliance standards of Consensus Cloud Solutions, driving continuous improvement and adapting to emerging security threats and regulatory changes to maintain a robust security posture.
  • The role is crucial in overseeing the design and implementation of the organization's information security operations program, including patch management, vulnerability management, continuous monitoring, asset protection management, access reviews, security incident response, and operational security controls. They ensure that security operations are integral to the cloud technology stack.
  • Identifying, selecting, and implementing information security operations tools and technologies that align with the organization's security program is an essential responsibility. This may include vulnerability management platforms, vulnerability scanning tools, patch management tools, security incident response tools, monitoring and alerting tools, cloud-based identity provider platforms, and identity and access management systems.
  • Providing guidance and expertise to software development, cloud infrastructure, and IT teams on designing and implementing secure and compliant solutions is critical. The role helps teams make informed decisions about technology and compliance choices that prioritize security operations and response capabilities.
  • Perform other duties and responsibilities as required, assigned, or requested. Consensus reserves the right to add or change duties at any time.

What you will bring to the table...

  • 10+ years experience in Information Security Operations role.
  • 8+ years of experience with SIEM platforms for security incident response monitoring and alerting.
  • 6+ years of experience with Vulnerability Management platforms for scanning web applications and cloud workloads.
  • 6+ years of experience with AWS cloud technologies.
  • 5+ years of experience leading and managing security operations and project management professionals or equivalent experience.
  • In-depth knowledge of security information and event management (SIEM) systems, including configuring, managing, and optimizing SIEM tools for continuous monitoring and real-time threat detection.
  • Proficiency in patch management solutions and processes, ensuring timely and effective deployment of patches across all systems to mitigate vulnerabilities and maintain software security.
  • Expertise in vulnerability scanning tools and methodologies, such as Nessus, Qualys, or OpenVAS, to identify, assess, and prioritize security risks and implement remediation strategies.
  • Experience with asset protection technologies, including data loss prevention (DLP) solutions, encryption methods, and access control systems, to secure critical assets from unauthorized access and threats.
  • Knowledge of access management systems, such as Identity and Access Management (IAM) solutions, to manage and enforce the principle of least privilege, conduct access reviews, and handle approvals.
  • Skills in attack surface management tools and techniques, including using solutions like Attack Surface Analyzer, Securityscorecard, or RiskIQ, to identify and mitigate potential entry points for cyber threats.
  • Competence in asset management systems, such as configuration management databases (CMDB) and IT asset management (ITAM) tools, to track and protect IT assets throughout their lifecycle.
  • Experience in conducting and supporting internal and external security audits, ensuring compliance with frameworks like GDPR, HIPAA, SOC 2, and ISO 27001, and addressing audit findings with appropriate corrective actions.
  • Leadership in developing and implementing incident response plans, including coordinating with incident response teams and using tools like Security Orchestration, Automation, and Response (SOAR) platforms to effectively manage and resolve security incidents.
  • Proficiency in developing and analyzing security metrics, using tools like dashboards and reporting software to monitor security performance, provide actionable insights, and support strategic decision-making.
  • Familiarity with advanced security technologies, such as firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint protection platforms (EPP), and advanced threat protection (ATP) solutions, to protect the organization's IT infrastructure.
  • Technical expertise in encryption and cryptographic techniques, ensuring secure data transmission and storage, and protecting sensitive information from unauthorized access.
  • Knowledge of cloud security technologies and best practices, including securing cloud environments and services, implementing cloud access security brokers (CASB), and ensuring compliance with cloud security standards.
  • Competence in network security technologies, such as virtual private networks (VPNs), secure sockets layer (SSL)/transport layer security (TLS), and network segmentation, to safeguard network communications and infrastructure.
  • Experience with project management tools and methodologies, ensuring effective planning, execution, and oversight of security projects and initiatives aligned with organizational goals.
  • Continuous learning and adaptation to emerging security trends, staying updated with the latest security threats, technologies, and best practices to improve the organization's security posture continually.
  • Ability to integrate security operations with IT practices, using tools like security as code and automated security testing to embed security measures into the system development lifecycle (SDLC).
  • Advanced knowledge of global security operations and compliance requirements, including relevant regulations and standards such as GDPR, HIPAA, SOC 2, SOX, HITRUST, and ISO 27001, to ensure the organization's adherence to legal and regulatory mandates.
  • Expertise in patch management processes, including prioritizing, testing, and deploying patches effectively to maintain software security and reduce vulnerability exposure.
  • Proficiency in conducting vulnerability assessments, with skills in using various vulnerability scanning tools and methodologies to identify, evaluate, and mitigate security risks.
  • Experience in continuous monitoring techniques, employing endpoint and cloud workload protection, patch management tools, and advanced security information and event management (SIEM) tools for real-time threat detection and response.
  • Strong capabilities in asset protection monitoring, utilizing tools and strategies to safeguard critical assets from unauthorized access and potential threats.
  • Knowledge of access control mechanisms and principles, particularly the least privilege principle, to effectively manage access reviews and approvals with cloud-based identity provider solutions.
  • Skills in attack surface management, including identifying, assessing, and reducing potential entry points for cyber threats to minimize the organization's risk exposure.
  • Competence in asset management and protection, ensuring accurate tracking, secure management, and proper decommissioning of IT assets throughout their lifecycle.
  • Ability to support and facilitate internal and external audits, including preparing documentation, addressing audit findings, and implementing corrective actions to ensure compliance with security policies and regulations.
  • Leadership in security incident response, capable of developing, maintaining, and executing incident response plans, coordinating investigations, and managing communication and resolution efforts during incidents.
  • Expertise in monitoring and reporting security metrics, developing key performance indicators (KPIs), and providing actionable insights to management for informed strategic decision-making.
  • Strong collaboration and communication skills, working effectively with executives and various departments, including Engineering, Product Development, IT, Network Operations, Project Management, Sales, Marketing, Legal, Internal Audit, HR, and external partners, to integrate and align security practices with organizational objectives.
  • Strategic thinking and problem-solving abilities, focusing on upholding and enhancing cloud-based products and solutions' security framework and compliance standards such as SaaS and AWS public and gov cloud infrastructure.
  • Project management skills, including planning, executing, and overseeing security projects and initiatives, ensuring timely completion and alignment with the organization's goals.
  • Technical proficiency in cloud-based security technologies and tools, such as virtual firewalls, host-based virtualized intrusion detection/prevention systems (IDS/IPS), encryption solutions, and advanced endpoint security tools, to effectively manage and protect the infrastructure.
  • Adaptability and continuous learning mindset, staying current with emerging security threats, trends, and technologies to improve the organization's security posture continually.

You will stand out if you also have...

  • Bachelor's degree in computer science, information technology, cybersecurity, or equivalent experience. A master's degree may be preferred.
  • Typically 10 years of experience in cybersecurity and information technology security roles.
  • Previous experience in leadership or managerial positions, such as a team lead or senior security operations analyst.
  • Proven experience in security operations, incident response, and security monitoring for cloud-based products and solutions.
  • Proficiency in various cybersecurity technologies and tools, including attack surface analysis tools, vulnerability scanning tools, penetration testing tools, cloud access security brokers (CASB), and extended or managed detection and response (MDR/XDR) platforms.
  • Hands-on experience with cloud-based patch management, security assessment, and security benchmarking testing tools.
  • Familiarity with security information and event management (SIEM) systems.
  • Experience in deployment of cloud controls for infrastructure, platform, and applications (IaaS/SaaS/PaaS), specifically within AWS.

Additional details...

  • Location requirements: Fully remote within the U.S. (Los Angeles, Las Vegas or Braintree, Massachusetts preferred.)
  • Travel requirements: Up to 10% travel.
  • Physical requirements: Must be able to sit for long periods, as well as, handle long periods of screen time.
  • Technology requirements: Reliable, high speed internet
  • Eligible for sponsorship: No
  • Security clearance: Ability to achieve and maintain a security clearance with the U.S. Government is required

The salary range for this role is up to $175,000 USD. The total compensation package for this position is negotiable and may also include [annual performance bonus, ESPP, enhanced time off packages and benefits.]


We are not accepting agency submissions for this role.

To learn more about us visit



  • Remote, Oregon, United States VidMob Full time

    Vidmob is the creative data company. Its scoring software and analytics have become an essential ingredient in the creative and media decisions of the world's largest marketers and agencies, as they strive to drive business results through improved creative effectiveness. As the leader in creative data, Vidmob's influence lies in its partnerships and...


  • Remote, Oregon, United States Consensus Cloud Solutions Full time

    Consensus Cloud Solutions is a publicly traded, leading digital cloud fax and interoperability solutions organization in the United States and globally, focusing on connecting and empowering healthcare providers, payers, care teams, and technology innovators to unify multiple systems that wouldn't otherwise talk to each other. Consensus is a trailblazer in...


  • Remote, Oregon, United States TEKsystems Full time

    Job OverviewTEKsystems is in search of an Information Security Engineer dedicated to fortifying our network, software, systems, and infrastructure to adhere to the highest security protocols.Contract Duration: 3 Months to Start (potential for extension)Location: 100% RemoteKey Responsibilities:Oversee security policies and technical design throughout project...


  • Remote, Oregon, United States Cayuse LLC Full time

    The exciting world of scientific research is fueled by people with a passion for solving complex problems. At Cayuse, we are committed to our customers' success by empowering organizations to conduct globally connected research that advances their impact on science, discovery and society. We build on that commitment with proven, integrated and easy-to-use...

  • Security Operations

    1 month ago


    Remote, Oregon, United States Voltage Park Full time

    Voltage Park is building an AI Cloud Infrastructure business from the ground up. As part of this effort, we're looking for a Security Operations (SecOps) Analyst. In this role, you will play a pivotal role in ensuring the organization's assets, systems, data, and security posture is robust, that threats are identified and mitigated promptly, and that...

  • Director, FED Sales

    1 month ago


    Remote, Oregon, United States Orca Security Full time

    Location: North East- DC/VAABOUT USDive right in. Swim with our pod. At Orca, in the right environment and with the right team, talent has no boundaries. This team spirit, together with our drive to always aim high, has quickly earned us unicorn status and turned us into a global cloud security innovation leader. So if you're ready to join an amazing team of...


  • Remote, Oregon, United States Column Software Full time

    Column is looking to hire a full-time Director of Operations to join the company's leadership team. The Director of Operations will report directly to our CEO, Jake Seaton, and should be excited about building a growth stage company and taking Column to its next stage. The Director of Operations will be responsible for the day-to-day management of the...


  • Remote, Oregon, United States Millennium Information Services Full time

    Company Overview: Millennium Information Services stands as a premier national provider of property inspection solutions and advanced process management services tailored for property and casualty insurance firms.Position Overview: We are currently seeking a dedicated individual to enhance our Field Inspection Management division. This role is ideal for...


  • Remote, Oregon, United States Millennium Information Services Full time

    Company Overview: Millennium Information Services is a prominent national provider specializing in property inspection services and advanced process management solutions tailored for property and casualty insurance firms.Position Overview: We are currently seeking to enhance our Field Inspection Management division with a remarkable opportunity for...


  • Remote, Oregon, United States Accurate Background Full time

    Reporting to the Chief Revenue Officer, the Revenue Operations Director plays a critical role in supporting the revenue team by integrating non-customer-facing activities across sales, marketing, customer service, and finance to drive growth through operational efficiency and ensure accountability to revenue. This position requires a blend of technical and...


  • Remote, Oregon, United States Level Access Full time

    Working with the Director of Information Security, the Senior Security Engineer role at Level Access will be responsible for helping Level Access scale its goal of being the most secure company in digital accessibility. Primary responsibilities include: leading the multi-framework compliance program; designing and implementing an appropriately-sized...


  • Remote, Oregon, United States Millennium Information Services Full time

    Company Overview: Millennium Information Services is a prominent national provider specializing in property inspection services and advanced process management solutions tailored for property and casualty insurance firms.Position Overview: We are seeking a qualified individual to enhance our Field Inspection Management team. This role is ideal for candidates...


  • Remote, Oregon, United States Millennium Information Services Full time

    Company Overview: Millennium Information Services is a prominent national provider specializing in property inspection services and advanced process management solutions tailored for property and casualty insurance firms.Position Overview: We are currently seeking a qualified individual to enhance our Field Inspection Management team. This role is ideal for...


  • Remote, Oregon, United States Millennium Information Services Full time

    Company Overview: Millennium Information Services is a premier national provider of property inspection solutions and advanced process management services tailored for property and casualty insurance firms.Position Overview: We are seeking a qualified individual to enhance our Field Inspection Management division. This role is designed for candidates with a...


  • Remote, Oregon, United States Millennium Information Services Full time

    Company Overview: Millennium Information Services is a prominent national provider specializing in property inspection services and advanced process management solutions tailored for property and casualty insurance firms.Position Overview: We are currently seeking a dedicated individual to enhance our Field Inspection Management team. This role is suitable...


  • Remote, Oregon, United States Radiology Partners Full time

    About the RoleRadiology Partners is seeking a highly skilled and experienced Senior Director of Operations Strategy to join our team. As a key member of our operations leadership team, you will be responsible for driving strategic initiatives and improving operational processes across the organization.Key ResponsibilitiesDevelop and Implement Strategic...


  • Remote, Oregon, United States Podium Full time

    At Podium, our mission is to help local businesses win. Our lead conversion platform, powered by AI and integrations, helps local businesses convert leads faster, communicate easier, and make more sales. Every day, thousands of local businesses utilize our review management, communication, marketing, and payments products. Our work and focus on helping local...


  • Remote, Oregon, United States Wiz Full time

    Come join the company that is reinventing cloud security and empowering businesses to thrive in the cloud. As the fastest-growing startup ever, Wiz is on a mission to help organizations secure cloud environments that will accelerate their businesses. Trusted by security teams all over the world, we have a proven track record of success and a culture that...


  • Remote, Oregon, United States Life Technologies (Thermo Fisher Scientific) Full time

    Work ScheduleStandard (Mon-Fri)Environmental ConditionsOffice Job Description At Thermo Fisher Scientific, you'll discover meaningful work that makes a positive impact on a global scale. Join our colleagues in bringing our Mission to life - enabling our customers to make the world healthier, cleaner and safer. We provide our teams with the resources needed...


  • Remote, Oregon, United States Everly Health Full time

    Reporting to the VP of Compliance & Risk, the Data Protection Programs Director is integral to the development, maintenance, and enhancement of Everly Health's data protection program as it evolves with the business. Incumbent will be responsible for advising multiple levels of the organization on laws, regulations, and industry best practices concerning...