Director of IT Security
Bergen New Bridge Medical Center · Healthcare · 1,001-5,000 employees
Paramus, NJ · Onsite · full_time
Listed by the employer as “DIRECTOR, IT SECURITY | INFORMATION SERVICES | FULL-TIME DAY SHIFT (25133)”. Title normalized for comparability.
CLI Career Level
Senior Director-equivalent
Moderate confidence
Opportunity Score
63/100
Solid
Moderate confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 17, 2026 · Last verified 3 hours ago · Sourced from LinkedIn — Director of Security (US)
CLI Take
Broader than the title suggests
This role reads Senior Director-equivalent despite being advertised as “DIRECTOR, IT SECURITY | INFORMATION SERVICES | FULL-TIME DAY SHIFT (25133)” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries HIPAA accountability. The reporting line sits below the executive team — the role reports to Information Services leadership. Team size is not disclosed and remains the main open question before pursuing it.
Why this role scores the way it does
63/100 — solid opportunity quality. CLI reads this as a Senior Director-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Information Services leadership. 4 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
Senior Director-equivalent — The employer lists this as “DIRECTOR, IT SECURITY | INFORMATION SERVICES | FULL-TIME DAY SHIFT (25133)”. CLI reads it as Senior Director-equivalent because the role shows 1,001-5,000 employee organization.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Employer profile: 1,001-5,000 employee organization, nonprofit ownership, not applicable, revenue 250m 1b.
- Title and described scope are broadly consistent.
What to probe before applying
- The reporting line sits below the executive team — the role reports to Information Services leadership.
Scoring components · Solid
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
The reporting line sits below the executive team — the role reports to Information Services leadership.
Scope: no enterprise, global or multi-unit remit is described.
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposure: not disclosed.
Title and described scope are broadly consistent.
Employer profile: 1,001-5,000 employee organization, nonprofit ownership, not applicable, revenue 250m 1b.
Team size: not disclosed.
Budget ownership: not disclosed.
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$135,000 – $175,000 base salary, disclosed by employer
The mandate
The Director of IT Security will design and implement the medical center's security architecture and strategy to meet regulatory requirements. The leader is responsible for developing cybersecurity policies, managing incident response, and leading the annual HIPAA Security Risk Assessment process.
Based in the Information Services department at a medical center. The remit covers enterprise-wide security policy, infrastructure, risk assessment, and regulatory compliance.
Scope
- Reports to Information Services leadership
Domains and regulation
- Enterprise Security
- Application Security
- Cloud Security
- Infrastructure Security
- Cyber Defense
- Incident Response
- GRC
- Compliance
- Privacy
- HIPAA
Requirements
Must have
- 8-10 years of experience working in an IT security management role
- 5+ years of experience in a security management role (specifically stated)
- Experience with security policy development, cloud/web application security, and SAAS solutions
- Experience in network penetration testing and application vulnerability assessments
- Bachelor's degree in computer science, Information Management or related field
Preferred / bonus
- Preferred: Familiarity with healthcare industry
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Conducting the annual HIPAA Security Risk Assessment and reporting
- Designing and implementing an IT security architecture and strategy from the ground up
- Coordinating corrective actions for security exposures identified by external auditors
- Establishing an ongoing risk assessment program for both security and privacy matters
Not stated in the posting: Specific reporting line title (e.g., CISO or CIO) not explicitly named; Team size or direct report count not mentioned.
About Bergen New Bridge Medical Center
Bergen New Bridge Medical Center is New Jersey's largest hospital and a clinical affiliate of Rutgers Biomedical and Health Sciences. The facility provides comprehensive services including acute care, behavioral health, substance use disorder treatment, and long-term care to the residents of Bergen County and surrounding areas. For a security leader, this represents a large-scale healthcare environment with complex regulatory requirements and a diverse patient population.
- Industry
- Healthcare
- Headcount
- 1,001-5,000 employees
- Headquarters
- Paramus, NJ
- Founded
- 1916
- Ownership
- Nonprofit
- Funding
- Not applicable
- Revenue
- $250M – $1B
Full company profile for Bergen New Bridge Medical Center →
View original job description
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.