Stony Brook University logo

IT Security Governance Lead

Stony Brook University

Stony Brook, NYFull-time$87–117K/yrTracked 1mo agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$87–117K/yr
Location
Stony Brook, NY
Schedule
Full-time
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

New York State License Or CertificateBachelor's degree

Job overview

Stony Brook University is hiring an IT Security Governance Lead. The IT Security Governance Lead at Stony Brook Medicine will direct enterprise identity governance, access control, and cloud security strategy, ensuring compliance with HIPAA, NYS, SUNY, and NIST regulations while partnering with technical teams to design and enforce secure authorization models for clinical systems.

Key focus areas include Establish and enforce cloud access governance policies (RBAC/ABAC), Design and oversee authorization models across cloud platforms (OCI and hybrid), and Define and govern access controls for enterprise clinical systems (Oracle Health/Cerner).

Successful candidates bring Bachelor's Degree In Technology and 5+ Years Experience In Identity & Access Management. Important skills include Identity Governance, Access Control, Cloud Security Strategy, Authorization Models, Privileged Access Controls, and Zero Trust Principles. Preferred (not required): Oracle Health, Cerner, HIPAA, and NIST Frameworks.

Skills & qualifications

RequiredNice to have

Skills

Identity GovernanceAccess ControlCloud Security StrategyAuthorization ModelsPrivileged Access ControlsOracle HealthCernerZero Trust PrinciplesLeast PrivilegeHIPAANYS RegulationsSUNY RegulationsNIST FrameworksCloud Access Governance PoliciesRBACABACOCIAccess Certification ReviewsPrivileged Access ManagementPAM/PIMIdentity Risk Signals MonitoringPrivileged Account Activity MonitoringSecure DesignSegregation of DutiesRisk-Based Access DecisionsControl EnforcementAudit ReadinessRegulatory ComplianceConditional AccessMFAAccess ProvisioningIdentity Incident ResponseLogging & MonitoringAuthenticationScalable Governance ModelAzureAWSGCPOracle Cloud InfrastructureEpicClinical Workflows GovernanceSensitive Patient Data GovernanceProvider Roles GovernanceMicrosoft Entra ID GovernanceZero Trust ArchitecturesNIST 800-53NIST 800-207PAM/PIM SolutionsOracle Cloud Infrastructure Access ModelsEnterprise Healthcare Systems SupportEnterprise Healthcare Systems SecurityClinical Workflows Access GovernanceSensitive Patient Data Access GovernanceProvider Roles Access GovernanceNISTIdentity & Access ManagementEnterprise Healthcare/Clinical SystemsPAM/PIM StrategyIndependent Governance Over Privileged AccessIndependent Governance Over Sensitive AccessOracle Health Cerner Access ModelsSecuring Enterprise Healthcare/Clinical SystemsGoverning Access to Clinical WorkflowsGoverning Access to Sensitive Patient DataGoverning Access to Provider RolesAzure AD GovernanceIdentity Governance and AdministrationRBAC ABAC ModelsOracle Health CernerMicrosoft Entra ID Azure AD GovernanceMulti‑Factor AuthenticationHIPAA Security RuleLogging and MonitoringAccess Control PoliciesIdentity Governance & AdministrationPIMMicrosoft Entra IDZero Trust ArchitectureAccess CertificationAccess ReviewsConditional Access & MFAPAMZero TrustNIST Frameworks 800-53 800-207CISSPCISMCRISCCCSP

Qualifications

Bachelor's Degree in Technology5+ Years Identity Access Management ExperienceDirect Experience With Oracle Cloud Infrastructure or Oracle Health Access ModelsExperience Securing Enterprise Healthcare Clinical SystemsPre-Employment Physical ExaminationFour Panel Drug ScreenNew York State License or Certificate

Benefits

Medical Insurance

Full job description

IT Security Governance Lead

Position Summary

Stony Brook Medicine is seeking an IT Governance Lead to drive enterprise identity governance, access control, and cloud security strategy. This senior role is responsible for defining and enforcing authorization models, identity governance frameworks, and privileged access controls across cloud and hybrid environments, including clinical platforms such as Oracle Health (Cerner).

This position serves as the information security authority for “who gets access and why,” ensuring alignment with Zero Trust principles, least privilege, and regulatory requirements (HIPAA, NYS, SUNY, NIST) while partnering with Systems and Engineering teams for operational execution.

Duties of an IT Governance Lead may include the following but are not limited to:

  • Establish and enforce cloud access governance policies (RBAC/ABAC)

  • Design and oversee authorization models across cloud platforms (OCI and hybrid environments)

  • Define and govern access controls for enterprise clinical systems (e.g., Oracle Health / Cerner)

  • Lead access certification reviews and enforce least privilege principles

  • Govern Privileged Access Management (PAM/PIM) strategy and controls

  • Monitor identity risk signals and privileged account activity

  • Align identity governance with HIPAA, NYS, SUNY, and NIST frameworks

  • Partner with Architecture, Cloud, Application, and Clinical IT teams to ensure secure design

  • Enforce segregation of duties (SoD) and access controls

  • Determining who should have access and under what conditions

  • Defining access control policies and governance standards

  • Driving risk-based access decisions and control enforcement

  • Ensuring audit readiness and regulatory compliance, including clinical system access

Collaboration with SBMIT Systems

  • Conditional Access & MFA

  • Defining governance & policy

  • Access Provisioning

  • Defines roles and approval requirements

  • Access Reviews

  • Owns certification process

  • Identity Incident Response

  • Leads investigation and strategy

  • Logging & Monitoring

  • Defines requirements and reviews anomalies

Operations

  • Separation of authentication (Systems) and authorization (InfoSec)

  • Independent governance over privileged and sensitive access, including clinical systems

  • Enforced segregation of duties

  • Scalable governance model supporting cloud and healthcare platforms (OCI/Cerner)

Qualifications

Required Qualifications:

  • Bachelor’s degree in Technology (Computer Science, InfoSec, or related field.

  • 5 years of experience in Identity & Access Management (IAM), or Identity Governance such as:

  • Identity Governance & Administration (IGA)

  • RBAC / ABAC models

  • PAM/PIM solutions

  • Cloud platforms (OCI, Azure, AWS, or GCP)

Preferred Qualifications:

  • Direct experience with Oracle Cloud Infrastructure (OCI) and Oracle Health (Cerner) access models

  • Experience supporting or securing enterprise healthcare/clinical systems (e.g., Oracle Health / Cerner, Epic, or similar)

  • Experience governing access to clinical workflows, sensitive patient data, and provider roles

  • Familiarity with Microsoft Entra ID / Azure AD governance

  • Experience with Zero Trust architectures and conditional access

  • Relevant certifications (CISSP, CISM, CRISC, CCSP)

  • Understanding :

  • HIPAA Security Rule

  • NIST frameworks (800-53, 800-207)

Special Notes : Resume/CV should be included with the online application.

Posting Overview : This position will remain posted until filled or for a maximum of 90 days. An initial review of all applicants will occur two weeks from the posting date. Candidates are advised on the application that for full consideration, applications must be received before the initial review date (which is within two weeks of the posting date).

If within the initial review no candidate was selected to fill the position posted, additional applications will be considered for the posted position; however, the posting will close once a finalist is identified, and at minimal, two weeks after the initial posting date. Please note, that if no candidate were identified and hired within 90 days from initial posting, the posting would close for review, and possibly reposted at a later date.

______________________________________________________________________________________________________________________________________

  • Stony Brook Medicine is a smoke free environment. Smoking is strictly prohibited anywhere on campus, including parking lots and outdoor areas on the premises.

  • All Hospital positions may be subject to changes in pass days and shifts as necessary.

  • This position may require the wearing of respiratory protection, which may prohibit the wearing of facial hair.

  • This function/position may be designated as “essential.” This means that when the Hospital is faced with an institutional emergency, employees in such positions may be required to remain at their work location or to report to work to protect, recover, and continue operations at Stony Brook Medicine, Stony Brook University Hospital and related facilities.

Prior to start date, the selected candidate must meet the following requirements:

  • Successfully complete pre-employment physical examination and obtain medical clearance from Stony Brook Medicine's Employee Health Services
    • Complete electronic reference check with a minimum of three (3) professional references.
  • Successfully complete a 4 panel drug screen
    • Meet Regulatory Requirements for pre-employment screenings.
  • Provide a copy of any required New York State license(s)/certificate(s).

Failure to comply with any of the above requirements could result in a delayed start date and/or revocation of the employment offer.

*The hiring department will be responsible for any fee incurred for examination .

_____________________________________________________________________________________________________________________________________­­­

Stony Brook University is committed to excellence in diversity and the creation of an inclusive learning, and working environment. All qualified applicants will receive consideration for employment without regard to race, color, national origin, religion, sex, pregnancy, familial status, sexual orientation, gender identity or expression, age, disability, genetic information, veteran status and all other protected classes under federal or state laws.

If you need a disability-related accommodation, please call the University Office of Equity and Access at (631)632-6280.

In accordance with the Title II Crime Awareness and Security Act a copy of our crime statistics can be viewed here .

Stony Brook University Hospital, consistent with our shared core values and our intent to achieve excellence, remains dedicated to supporting healthier and more resilient communities, both locally and globally.

Anticipated Pay Range:

The starting salary range (or hiring range) for this position is - $87019 - $117116 / year.

The above salary range represents SBUH’s good faith and reasonable estimate of the range of possible compensation at the time of posting. The specific salary offer will be based on the candidate’s validated years of comparable experience. Any efforts to inflate or misrepresent experience are grounds for disqualification from the application process or termination of employment if hired.

Some positions offer annual supplemental pay such as:

  • Location pay for UUP full-time positions ($4000)

Your total compensation goes beyond the number in your paycheck. SBUH provides generous leave, health plans, and state pension that add to your bottom line.

Visit our WHY WORK HERE page to learn about the total rewards we offer.

Job Number: 2602498

Official Job Title: : Senior Programmer/Analyst

Job Field : Information Technology

Primary Location : US-NY-Stony Brook

Department/Hiring Area: : Information Security

Schedule : Full-time

Shift : Day Shift Shift Hours: : M-F 9-5 Pass Days: : Sat, Sun, Variable

Posting Start Date : Jul 27, 2026

Posting End Date : Oct 25, 2026, 10:59:00 PM

Salary: : 87019 - 117116

Salary Grade: : SL4

SBU Area: : Stony Brook University Hospital

Req ID: 2602498

You've read the whole posting — now see how you match it.

IT Security Governance Lead at Stony Brook University | Olive Jobs