Skip to main content

Sr Director - Enterprise Cybersecurity Architecture and Cloud Security

Primary Location Pleasanton, CA Worker Location Remote Job Number 1304616 Date posted 09/03/2024
Submit Interest

Navigating the Hiring Process

We're here to support you!

Having trouble with your account or have questions on the hiring process?

Please visit the FAQ page on our website for assistance.

Need help with your computer and browser settings?

Please visit the Technical Information page for assistance or reach out to the web manager at kp-hires@kp.org.

Do you need a reasonable accommodation due to a disability?

A reasonable accommodation is any modification or adjustment that enables you to fully participate in completing the following:

  • Online Submissions
  • Pre-Hire Assessments
  • Interview Process

Please submit your accommodation request and an HR Representative will contact you.

Description:

Upon start, candidate must reside in CA, CO, CT, GA, HI, IL, MD, OR, VA, WA, or District of Columbia.




Technical Summary:


The Senior Director position is a strategic leadership role responsible for shaping and overseeing KP's enterprise's cybersecurity architecture. This individual plays a critical role in ensuring the security and resilience of KP's digital infrastructure, protecting sensitive data, and safeguarding against cyber threats. The Senior Director will lead a team of cybersecurity architects and engineers, driving the design and implementation of innovative security solutions.


Key responsibilities include developing and maintaining the enterprise-wide cybersecurity architecture and cloud strategies, aligning security initiatives with business objectives, assessing risk, and ensuring compliance with industry standards and regulations. This role involves collaborating with cross-functional teams, including IT, legal, compliance, and business units, to integrate security measures into all aspects of KP's global operations.


The ideal candidate will have a strong background in cybersecurity, architecture design, and risk management.  The candidate should possess strong experience in leading large-scale cybersecurity initiatives in complex, global environments. This position requires excellent leadership, communication, and problem-solving skills to effectively manage cybersecurity risks and drive continuous improvement to KP's security posture.




Job Summary:

This senior level managing position oversees the development, implementation and maintenance of assigned ITRM process and/or service portfolio by working collaboratively with leadership to develop the ITRM strategy. This role is responsible for staying current with industry trends, benchmarks, and best practices and providing guidance when difficult decisions need to be made.



Essential Responsibilities:


  • Directs the operations of multiple units and departments by identifying customer and operational needs; analyzing resources, costs, and forecasts and incorporating them into business plans; engaging strategic, cross-functional business units to champion and drive support for business plans and priorities; translating business strategy into actionable business requirements; obtaining and distributing resources; setting standards and measuring progress; anticipating and removing obstacles that impact performance; addressing performance gaps and implementing contingency plans accordingly; ensuring products and/or services meet customer requirements and expectations while aligning with organizational strategies; serving as a subject-matter expert and trusted source to executive leadership; and providing influence and consultation in the development of the larger organizational or business strategy.

  • Models and drives continuous learning and maintains a highly skilled and engaged workforce by aligning cross-functional resource plans with business objectives; overseeing the recruitment, selection, and development of talent; motivating and empowering teams; building organizational capacity and developing high potential employees for growth opportunities and advancement; staying current with industry trends, benchmarks, and best practices; providing guidance and leadership when difficult decisions need to be made; and ensuring performance management guidelines and expectations align with and drive business objectives and results.

  • Effectively communicates technical security findings to non-technical audiences.

  • Leads and assists in the development of project strategies, methodologies, and standard processes for moderately to highly complex IT initiatives across multiple security domains by analyzing business and technology requirements to ensure testability and traceability.

  • Reviews and signs off on project (e.g., testing, requirements documentation, logical models, etc.) scope and approach, and partners with cross-functional IT and business stakeholders to review and approve the overall project approach.

  • Researches and stays abreast of industry trends, emerging threats, best practices, and cutting edge techniques to creatively discover and exploit vulnerabilities, and recommend security solutions for technology systems.

  • Serves as an escalation point on issues, dependencies, and risks related to security testing.

  • Determines if the necessary skills and knowledge required to meet ongoing and changing business demands exists across business or technical domains, and ensures skill and knowledge gaps are closed through talent development and outsourcing as appropriate.

  • Leverages partnerships between security consultants, Program/Project Managers, and other IT planning leaders to drive workforce planning efforts.

  • Approves and directs additional staff augmentation through managed service agreements as needed.

  • Oversees budgets and capital planning across departments and annual business cycle levels as appropriate.

  • Oversees the implementation of and adherence to standardized security tools, templates, and processes to support continuous process improvement across business domains.

  • Recommends and advocates for regional and national process or solution design improvements which align with sustainable best practices, and the strategic and tactical goals of the business.

  • Provides insight and guidance to ensure solutions are aligned with business strategies, operational work flow, established budgets, and vendor service level agreements.

  • Develops trends and high level themes related to lessons learned, and communicates this feedback to stakeholders, leadership, and the larger information security community.

  • Collaborates with cross-functional IT teams to gain buy-in and approval of test plans, and tracks quality metrics across testing phases (e.g., SIT, Performance, UAT, Automation, Production, Validation).

  • Ensures KPIs are defined, up-to-date, and aligned to higher level organizational KPIs.

  • Drives the development of cyber security intellectual capital by leading process or procedure improvements, consulting on brown bag training sessions, and leading the development of new training documents.

  • Directs information sharing and integration procedures across cyber security to ensure the exchange of threat intelligence and cyber security vulnerability assessment data.

  • Provides insight and influence to executive management and business leaders on how to remediate issues identified through security testing processes.

  • Reviews, evaluates, and prioritizes value gaps and opportunities for process enhancements or efficiencies.

  • Establishes a network of partnerships with technology risk teams and business stakeholders to respond to and remediate identified issues, and ensure the best approach for improving security posture.

Minimum Qualifications:


  • Minimum four (4) years informal leadership experience with or without direct reports.

  • Minimum six (6) years managing operating budgets and/or project financials.

  • Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum twelve (12) years experience in IT or a related field, including Minimum six (6) years in information security. Additional equivalent work experience may be substituted for the degree requirement.


Additional Requirements:

Preferred Qualifications:
  • Two (2) years experience performing vulnerability assessments of IT technologies.
  • Four (4) years experience overseeing projects or programs requiring the integration of cross-functional technology and/or business solutions.
  • Six (6) years of work experience in a role requiring interaction with executive leadership (e.g., Vice President level and above)
  • Two (2) years experience in IT incident management, including the development and/or deployment of remediation plans.
  • Two (2) years experience in cyber security threat response and investigation.
  • Two (2) years experience in risk management, governance, or compliance.
  • Two (2) years experience in business continuity, crisis management, or disaster recovery.
Primary Location: California,Pleasanton,Pleasanton Tech Cntr Building A Additional Locations:

KP-IT @ West Annex - Parsons, 74 N. Pasadena Ave., Pasadena,California, 91124
KPIT - Dole Annex, 680 Iwilei Rd. Ste. 600, Honolulu,Hawaii, 96817
Nicolai Service Center, 2850 NW Nicolai Ave., Portland,Oregon, 97210
Northwest DC Medical Offices, 2301 M St. NW, Washington,Dist of Columbia, 20037
Service West Inc. - Alexandria, 6304-G Gravel Ave., Alexandria,Virginia, 22310
Qwest Chicago Cybercity, 350 E. Cermak Rd., Chicago,Illinois, 60616
Greenwood Plaza IT, 6560 Greenwood Plaza Blvd., Greenwood Village,Colorado, 80111
Pershing Point Plaza IT, 1375 Peachtree St. NE, Atlanta,Georgia, 30309
New Carrollton Administration, 4000 Garden City Dr., Hyattsville,Maryland, 20785
Renton Administration - Rainier, 2715 Naches Ave. SW, Renton,Washington, 98057
Connecticut Remote Workers Location, 210 Capitol Ave, Hartford,Connecticut, 06106
Scheduled Weekly Hours: 40 Shift: Day Workdays: Mon, Tue, Wed, Thu, Fri Working Hours Start: 08:00 AM Working Hours End: 05:00 PM Job Schedule: Full-time Job Type: Standard Worker Location: Remote Employee Status: Regular Employee Group/Union Affiliation: NUE-IT-01|NUE|Non Union Employee Job Level: Director/Senior Director Specialty: IS Strategy Department: KPIT ADMIN - CYBER STRATEGY - 9601 Pay Range: $211800 - $274010 / year The ranges posted above reflect the location in the job posting. The salary range may vary if you reside in a different location or state than the location posted. Travel: No Remote: Work location is the remote workplace (from home) within KP authorized states. Worker location must align with Kaiser Permanente's Authorized States policy. At Kaiser Permanente, equity, inclusion and diversity are inextricably linked to our mission, and we aim to make it a part of everything we do. We know that having a diverse and inclusive workforce makes Kaiser Permanente a better place to receive health care, a more supportive partner in our communities we serve, and a more fulfilling place to work. Working at Kaiser Permanente means that you agree to and abide by our commitment to equity and our expectation that we all work together to create an inclusive work environment focused on a sense of belonging and wellbeing.

Kaiser Permanente is an equal opportunity employer committed to a diverse and inclusive workforce. Applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy), age, sexual orientation, national origin, marital status, parental status, ancestry, disability, gender identity, veteran status, genetic information, other distinguishing characteristics of diversity and inclusion, or any other protected status. Submit Interest