We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Vice President, Information Security & Risk

Thresholds
medical insurance, dental insurance, vision insurance, sick time, 403(b), retirement plan
United States, Illinois, Chicago
4101 North Ravenswood Avenue (Show on map)
Aug 07, 2026
Description

The Vice President (VP), Information Security & Risk is responsible for leading the execution and continuous improvement of the Thresholds information security and risk management program. The scope of the program is the protection of Thresholds' information and technology assets as well as Thresholds' digital data in the cloud. The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and compliant manner; provides strong technical leadership; and serves as a trusted advisor to the Chief Information Officer and agency leaders in addition to serving as the agency's designated security official.

ESSENTIAL DUTIES & RESPONSIBILITIES:

Security Operations and Execution



  • Manages the day-to-day information security operations, including security posture and event monitoring, threat and vulnerability identification, policy violation, access control and attack surface monitoring, monitoring the effectiveness of email and URL filtering, and incident response activities.
  • Manages the remediation of security issues, policy violation, ineffective rules for access control, attack surface reduction, and email/URL filtering as well as the creation and maintenance of standard operating procedures for security operations.
  • Develops and maintains dashboard(s) of security operations KPI's for Information Technology (IT/ITS) management review.


Application, Cloud, Digital, Infrastructure and Platform Security



  • Supports secure implementation and operation of applications, cloud services, infrastructure, and platforms (cloud, digital, end-user, and server).
  • Partners with Information Technology Services (ITS) and digital teams to incorporate needed security controls into the design, development, and deployment of Thresholds applications, cloud services, infrastructure, and platforms.
  • Performs and/or coordinates risk reviews of application and digital systems, and their underlying configurations.


Data Security and Privacy



  • Manages the IT Risk Management Program using Thresholds' risk management tool to record and assess identified risks, assign a risk owner, track risk treatment progress in the risk register, and provide risk management reporting to ITS leadership.
  • Leads enterprise, regulatory, service provider, and project IT risk assessments.
  • Supports internal and external audits, regulatory reviews, and customer or partner security inquiries.


Policy, Awareness & Documentation



  • Owns development and enforcement of the Information Security & Risk Management Program's policies, standards, and procedures, as well as the agency's Acceptable Use Policies.
  • Leads or oversees security awareness and training programs for the agency and the ITS staff.
  • Maintains and improves the Incident Response Playbook.


Collaboration and Continuous Improvement



  • Serves as a trusted advisor to business units and project teams on matters related to AI security, application security, information security, network security, AI risk, IT risk, regulatory compliance, emerging threats, social engineering, data classification; promoting security as a mission enabler for Thresholds.
  • Promotes a strong, practical security/risk culture that balances protection with usability and business needs.
  • Influences decisions by clearly articulating risk, tradeoffs, and recommendations.


Program Leadership and Strategy Execution



  • Embeds security by design principles into system implementations, vendor selection, and operational processes.
  • Translates security strategy into actionable roadmaps, initiatives, and measurable outcomes.
  • Stays current on evolving AI and cyber threats, data protection practices, and regulatory requirements.


Vulnerability and Threat Management



  • Manages the Vulnerability Management Program using Thresholds' vulnerability management tools to identify and assess vulnerabilities, assigns a vulnerability treatment owner, tracks vulnerability treatment progress in the vulnerability register, and provides vulnerability management reporting to IT leadership.
  • Reviews threat intelligence to identify potential negative impacting issues and proactively performs remedial actions to block or avoid the threat(s).
  • Provides threat action summaries to ITS leadership.


Team Leadership and Development



  • Directly manages, mentors, and develops security staff; setting performance goals and supporting career growth.
  • Provides technical guidance and decision support to security team members and cross-functional partners.
  • Helps shape workforce planning, resource allocation, and budget inputs for security initiatives.



EDUCATION:



  • Accredited bachelor's degree in information security, Computer Science, Information Systems, or a related field (or equivalent experience) required.



EXPERIENCE:

Required



  • Minimum of seven (7) Years of progressive experience in information security, cybersecurity, data protection, or IT risk management.
  • Minimum of three (3) Years of experience leading teams or major security/risk management programs.
  • Hands-on experience with security operations, incident response, risk assessments, or compliance activities.
  • Working knowledge of security and risk frameworks (e.g., NIST, ISO 27001, CIS Controls), AI security and risk management best practices, regulatory requirements (e.g., HIPAA, PCI DSS), Microsoft security and risk management tools, identify and access management, network access controls, data loss prevention, and SIEM systems.
  • Demonstrated ability to explain security risk and control matter to non-technical audiences.



Preferred



  • Experience supporting cloud environments, SaaS platforms, or digital transformation initiatives.
  • Experience in a mid-sized, non-profit and/or regulated organization.
  • Familiarity with data analytics, and reporting tools.
  • Familiarity with computer forensic techniques.
  • Demonstrated experience partnering with leaders/senior leaders and influencing outcomes.



SKILLS/CERTIFICATIONS



  • Security certifications (e.g. CISSP, CISM, Security+, CCSP)
  • Microsoft certified
  • Demonstrated and effective analytical and problem-solving skills
  • Strong analytical and problem-solving skills
  • Practical, risk-based approach to security
  • Clear interpersonal and communication skills, both written and oral
  • Policy writing
  • Scripting languages, preferably PowerShell
  • Collaboration and relationship management
  • Attention to detail and follow-through
  • High integrity and discretion
  • Demonstrated project management and people management skills
  • Strategic execution and program ownership
  • Demonstrated effective cross-functional collaboration



What Sets Thresholds Apart:



  • Competitive pay - Salary Range: $155,000.00 - 175,000.00 annually
  • Generous PTO (9 federal holidays, 8 days of sick leave, 15-22 days personal and vacation)
  • Dental insurance, vision insurance,choice of 3 medical insurance plans
  • 403(b) retirement plan with 3% employer match
  • Robust employee assistance program (EAP)



Thresholds is a mission-driven agency with a deep commitment to fostering an environment where all feel valued and respected, a place where every employee can be themselves, thrive, and support the agency's mission. Click here to learn more.

One of the oldest and largest community mental health organizations in Illinois, we pride ourselves in being a Chicago Tribune Top Workplace and one of Chicago's 101 Best & Brightest Companies to Work For, several years in a row.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Applied = 0

(web-77cf7d65c7-jdxdg)