Serious Medicine is what we do. Being extraordinary is who we are. Every colleague plays a key role in upholding this promise to our patients and their families.
Shift:
First Shift (United States of America)Director Information Security and Risk Management
In an era where cyber threats evolve faster than ever, safeguarding patient lives, groundbreaking research, and educational excellence demands visionary leadership. As Director of Information Security & Risk Management at Nebraska Medicine and UNMC, you'll set the enterprise-wide cybersecurity strategy, owning the vision, reliability, and lifecycle of resilient defenses that protect our mission: transforming lives and creating a healthier future through extraordinary patient care, innovative research, and premier education. Lead high-impact teams in delivering secure, scalable solutions while influencing executives to champion innovation, operational excellence, and unbreakable trust in our academic health system.
Details: Director Information Security and Risk Management
Why Work at Nebraska Medicine?
Be part of something extraordinary at Nebraska Medicine!
The Director of Information Security & Risk Management sets the strategic direction for enterprise Cybersecurity & IT Risk across Nebraska Medicine and UNMC. This role oversees multiple teams and functions, ensuring alignment of IT strategy with organizational goals for patient care, education, and research. Owns the vision, reliability, and lifecycle of Cybersecurity & Risk Management, managing portfolios and investments to deliver secure, resilient, and scalable solutions. Acting as an enterprise leader, this position influences senior leadership and executives to drive innovation and operational excellence.
Required Qualifications: Director Information Security and Risk Management
* Minimum of 10 years progressive experience in Information Security & Risk engineering, including large, complex, multi-site environments required.
* Minimum of 5 years leading technical teams with 24x7 operational accountability required.
* Bachelor's degree in computer science, Information Systems, Engineering, or related field required.
* Hands-on expertise with enterprise Cybersecurity, Identity & Access Management, and Risk management required.
* Demonstrated mastery of ITIL processes (incident, change, problem) and service reporting required.
* Strong vendor management and budgeting experience required.
Preferred Qualifications: Director Information Security and Risk Management
* Healthcare delivery organization, & higher education/research experience and familiarity with clinical communications preferred.
* CISSP, CISM, CRISC, ITIL, PMP certifications preferred.
* Proven experience developing and executing enterprise security strategies, including identity and access management, GRC, and security engineering preferred.
* Hands-on leadership of SOC operations, incident response, and threat intelligence programs preferred.
* Risk management and compliance expertise, including HIPAA, NIST CSF, PCI, and other regulatory frameworks preferred.
* Cloud security and zero-trust architecture implementation experience preferred.
* Vendor risk management and third-party security assessments in complex ecosystems preferred.
* Security automation and DevSecOps integration within CI/CD pipelines preferred.
Nebraska Medicine is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, marital status, sex, age, national origin, disability, genetic information, sexual orientation, gender identity and protected veterans' status.
| Date Posted | February 2, 2026 |
|---|---|
| Date Closes | February 17, 2026 |
| Requisition | REQ-34658 |
| Address | Business Service Center |
| Located In | Omaha, NE |
| SOC Category | 11-3021.00 Computer and Information Systems Managers |