Healthcare Technology IT Security Lead
Guidehouse
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
Healthcare Technology IT Security Lead
Guidehouse’s Health IT Solutions team collaborates with clients to significantly enhance their technology outcomes through IT strategies, improved IT operations, and the adoption of new technology initiatives. Leveraging a deep understanding of health system IT operational best practices supported by data, Guidehouse drives IT operational improvement and technology adoption across various departments and service lines within client organizations.
The Healthcare Technology IT Security Lead will be responsible for overseeing the design, implementation, validation, and ongoing sustainment of comprehensive cybersecurity and data protection strategies for an extensive Public Health System’s Oracle Health EHR implementation. This critical role ensures that all infrastructure, applications, integrations, and data flows adhere to or surpass state and federal security standards, including HIPAA, NIST 800-53, and specific State cybersecurity policies. The IT Security Lead will engage closely with technical partners, key stakeholders, and third-party vendors to maintain secure, compliant, and resilient operations across diverse state and correctional health environments.
Key Responsibilities
- Security Architecture and Governance
- Lead the development of a hybrid cloud security architecture utilizing Oracle Cloud Infrastructure (OCI) and State-managed data centers.
- Implement zero-trust architecture principles, including least-privilege access, multi-factor authentication (MFA), and role-based access controls (RBAC).
- Ensure all security controls align with service agreements, NIST 800-53, and CIS benchmarks.
- Establish robust governance models for change control, incident response, and disaster recovery (DR) planning.
- Serve as the primary liaison to the Executive Steering Committee and state cybersecurity teams.
- Risk Management and Compliance
- Conduct structured risk assessments across technical, contractual, staffing, and hosting domains.
- Develop and maintain a comprehensive risk register with mitigation strategies based on governance, monitoring, and contract safeguards.
- Lead vulnerability scanning, penetration testing, and firewall reviews across all environments.
- Ensure stringent compliance with HIPAA, 42 CFR Part 2, FISMA, and other applicable regulations.
- Oversee the implementation of continuous monitoring, patching, and SOC (Security Operations Center) coordination.
- Identity and Access Management (IAM)
- Design and implement IAM protocols across Oracle Health Millennium, RevElate, and integrated systems.
- Manage user provisioning, de-provisioning, and access audits across all care settings.
- Validate integration with Oracle IAM and state identity providers for seamless SSO and MFA.
- Disaster Recovery and Business Continuity
- Define and validate Service Level Agreements (SLAs) for uptime, performance, Recovery Time Objectives/Recovery Point Objectives (RTO/RPO), and incident response.
- Coordinate DR testing with Oracle Health and state infrastructure teams.
- Develop and maintain playbooks for failover, downtime procedures, and recovery operations.
- Ensure that DR protocols are integrated into training and operational handoffs.
- Data Protection and Integration Security
- Oversee secure ingestion and normalization of multi-source data (clinical, claims, operational) using Oracle Health Data Intelligence (HDI).
- Validate HL7/FHIR interface security, including encryption, authentication, and audit logging.
- Implement secure APIs and data exchange frameworks for interoperability with federal and state systems.
- Operational Support and Sustainment
- Provide 24/7 monitoring, quarterly health checks, and proactive performance tuning.
- Lead continuous modernization efforts leveraging OCI’s roadmap (AI, automation, new security services).
- Ensure alignment with ITIL service management practices and state governance.
What You Will Need
- Bachelors degree
- Minimum 5 years of experience in IT security leadership within healthcare or public sector environments.
- Proven success in securing large-scale EHR implementations, preferably Oracle Health Millennium and RevElate.
- Deep understanding of HIPAA, NIST, FISMA, and state-specific cybersecurity frameworks.
- Experience with IAM, SOC operations, vulnerability management, and DR planning.
- Familiarity with HL7/FHIR, OCI, and secure data integration practices.
- Excellent communication, stakeholder engagement, and documentation skills.
What Would Be Nice To Have
- Certifications such as CISSP, CISM, CISA, or equivalent.
- Experience with federal/state EHR implementations.
- Familiarity with Oracle Health’s security architecture and OCI observability tools.
- Experience managing security in multi-entity, multi-specialty environments.
Compensation & Benefits
The annual salary range for this position is $130,000.00-$216,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits Include:
- Medical, Rx, Dental & Vision Insurance
- Personal and Family Sick Time & Company Paid Holidays
- Position may be eligible for a discretionary variable incentive bonus
- Parental Leave and Adoption Assistance
- 401(k) Retirement Plan
- Basic Life & Supplemental Life
- Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
- Short-Term & Long-Term Disability
- Student Loan PayDown
- Tuition Reimbursement, Personal Development & Learning Opportunities
- Skills Development & Certifications
- Employee Referral Program
- Corporate Sponsored Events & Community Outreach
- Emergency Back-Up Childcare Program
- Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
Key skills/competency
- Cybersecurity Strategy
- Healthcare IT Security
- Oracle Health EHR
- HIPAA Compliance
- NIST 800-53
- Risk Management
- Identity and Access Management (IAM)
- Disaster Recovery Planning
- Data Protection
- Oracle Cloud Infrastructure (OCI)
How to Get Hired at Guidehouse
- Research Guidehouse's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor, focusing on their Health IT Solutions team.
- Tailor your resume: Customize your application to highlight extensive experience in healthcare IT security leadership, EHR implementations, and compliance frameworks like HIPAA and NIST 800-53.
- Showcase relevant experience: Emphasize your proven track record in securing large-scale Oracle Health Millennium and RevElate EHR systems, risk management, and zero-trust architecture.
- Prepare for technical questions: Be ready to discuss your expertise in IAM, SOC operations, vulnerability management, DR planning, HL7/FHIR security, and Oracle Cloud Infrastructure (OCI).
- Demonstrate consulting acumen: Highlight strong communication, stakeholder engagement, and documentation skills, crucial for success in Guidehouse's client-facing consulting environment.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background