Post Job Free
Sign in

Cybersecurity IT

Location:
Clarksville, TN
Posted:
August 28, 2026

Contact this candidate

Resume:

Joseph Orlando

DIRECTOR, INFORMATION SECURITY & CYBER RISK

Healthcare Cybersecurity Governance, Risk & Compliance Cyber Resilience

EXECUTIVE PROFILE

Healthcare-focused cybersecurity and technology executive with 20+ years of leadership across regulated healthcare, enterprise security, cloud, SaaS, consulting, and technology organizations. Proven record developing and maturing security programs spanning governance, enterprise risk, HIPAA/NIST-aligned controls, vulnerability management, incident response, third-party risk, business continuity, cloud security, identity, and executive reporting. Trusted advisor to executives and Boards who translates technical and regulatory risk into practical business priorities, remediation plans, investment decisions, and measurable risk reduction. Experienced leading cross-functional teams and significant technology portfolios, including $28M+ budgets.

ROLE-ALIGNED EXPERTISE

Cybersecurity Governance & Strategy • Enterprise Cyber Risk Management • HIPAA Security & Healthcare Compliance • NIST CSF / NIST 800-53 • Vulnerability Management & Remediation • Incident Response & Cyber Resilience • Third-Party / Vendor Risk • Executive & Board Reporting • Risk Registers, KRIs & Dashboards • Security Awareness • Cloud Security • Microsoft Azure & Microsoft 365 • IAM / Zero Trust • SIEM / Security Operations • Business Continuity & Disaster Recovery • AI Governance & Emerging Technology Risk • Audit Readiness • Privacy / GRC • Stakeholder & Program Leadership

PROFESSIONAL EXPERIENCE

STERIS Director, Product Cybersecurity / IT Security Leader 2025–Present

• Lead cybersecurity strategy, governance, secure-by-design initiatives, vulnerability management, PSIRT, AI governance, and executive cyber-risk reporting for healthcare and regulated technology environments.

• Develop and execute multi-year cybersecurity roadmaps aligned with business priorities, customer requirements, regulatory obligations, and enterprise risk reduction.

• Partner across engineering, product, IT, infrastructure, compliance, and leadership to identify, assess, prioritize, and remediate cyber risks and strengthen operational resilience.

• Strengthen vulnerability governance, SBOM practices, remediation prioritization, and lifecycle security integration, contributing to approximately 30%+ vulnerability reduction and faster remediation cycles.

• Support security and compliance readiness aligned with HIPAA, NIST, ISO 27001, SOC 2, FDA cybersecurity guidance, CMMC, FedRAMP, and GovRAMP.

• Translate complex security issues into executive roadmaps, KPIs, risk summaries, business cases, and investment recommendations; evaluate AI and emerging-technology risks in regulated environments.

Kern Health Systems Director, IT / Cybersecurity 2022–2025

• Directed cybersecurity and technology operations for a regulated healthcare organization, including SIEM/security monitoring, incident response, vulnerability management, cloud security, IAM, disaster recovery, and business continuity.

• Led enterprise risk management and security governance practices, including risk registers, remediation planning, KRIs, heat maps, executive dashboards, and Board-ready reporting.

• Directed third-party risk management, vendor cybersecurity assessments, technology evaluations, and cloud modernization initiatives while managing a $28M+ technology and cybersecurity budget.

• Led Microsoft Azure and Microsoft 365 modernization, identity and Zero Trust initiatives, security architecture, and enterprise control improvements supporting HIPAA-regulated operations.

• Coordinated cross-functional security and resilience initiatives across IT, operations, business leadership, vendors, and strategic partners, aligning investment decisions to operational and regulatory risk.

The Torchlite Group Managing Partner / Executive-in-Residence 2004–2022

• Served as interim/vCISO and trusted advisor to healthcare, technology, government, growth-stage, and private-equity organizations, leading cybersecurity, GRC, privacy, cloud, and enterprise-risk transformations.

• Advised Boards, CEOs, CIOs, and executive teams on cybersecurity strategy, governance, risk prioritization, M&A/security diligence, vendor governance, cloud transformation, and operating-model maturity.

• Translated regulatory, business, and technical requirements into practical roadmaps, security programs, policies, investment priorities, and remediation plans across regulated environments.

• Led multidisciplinary teams and complex programs spanning security, infrastructure, architecture, operations, compliance, vendors, and business stakeholders.

PricewaterhouseCoopers UK Senior Director, Strategic Technologies 2001–2004

• Led strategic technology, cybersecurity, privacy, governance, and transformation initiatives for global enterprise clients; advised senior executives on cyber resilience, enterprise architecture, and technology risk.

Motorola Corporation Director / VP, Strategic Markets 1998–2000

• Led strategic technology and market initiatives, cross-functional teams, executive relationships, partnerships, and commercialization programs connecting emerging technologies to enterprise customer requirements.

IBM Global Services Director 1996–1998

• Led major enterprise technology and program initiatives, including PMO and data-warehousing programs for large clients; contributed to the global launch of IBM ViaVoice, reaching more than 2 million users in its first 18 months.

SELECTED LEADERSHIP IMPACT

• Led global and cross-functional teams of 25–50+ across security, technology, engineering, operations, compliance, product, and business functions.

• Managed or influenced portfolios and budgets exceeding $28M while balancing cyber-risk reduction, regulatory requirements, modernization, operational resilience, and business priorities.

• Built executive-level cyber dashboards, risk heat maps, KRIs, roadmaps, and Board-ready materials to make security risk understandable and actionable.

• Deep experience in healthcare and trust-sensitive environments, including HIPAA, NIST, FDA cybersecurity guidance, ISO 27001, SOC 2, privacy, cloud, and third-party risk.

TECHNOLOGIES & FRAMEWORKS

Microsoft Azure • Microsoft 365 • Microsoft Defender • SIEM • IAM • Zero Trust • Cloud Security • Vulnerability Management • Incident Response • Business Continuity / Disaster Recovery • Third-Party Risk Management • Secure SDLC • SAST / DAST / SCA • SBOM / PSIRT • NIST CSF • NIST 800-53 / 800-171 • HIPAA • ISO 27001 • SOC 2 • FDA Cybersecurity Guidance • CMMC • FedRAMP / GovRAMP • GDPR

EDUCATION & CERTIFICATION

Bachelor of Arts, Business Administration — Stetson University

Scrum Master Certified

***@*********.*** 352-***-****

Clarksville, TN linkedin.com/in/jgorlando



Contact this candidate