Information Security Leader
Remote, US
Agfa HealthCare, is a division of the Agfa-Gevaert Group which is headquartered in Mortsel, Belgium and traded on Euronext Brussels (AGFB).
At Agfa HealthCare, we support healthcare professionals across the globe to transform the delivery of care. Our focus is 100% on providing best-of-suite Imaging IT software solutions that enable secure, effective and sustainable imaging data management.
From product development to implementation, our unified Enterprise Imaging Platform is purpose-built to reduce complexity, improve productivity and deliver clinical value. We use our proven track record as an innovator, our in-depth medical knowledge and our strategic guidance to help healthcare providers achieve their clinical, operational and business strategies.
AGFA HealthCare is seeking an Information Security Leader to define and execute the company’s global cybersecurity vision across all business units and geographies. This role provides enterprise-wide security leadership with primary operational focus on cloud-native and SaaS platforms, while maintaining oversight of legacy on‑premise environments.
The leader is accountable for measurable security outcomes, ensuring the confidentiality, integrity, and availability of healthcare data and systems, strengthening regulatory posture, and reinforcing trust in AGFA HealthCare’s imaging and informatics platforms. This is a hands-on leadership role that combines strategic partnership at the enterprise level with execution-oriented ownership of security operations.
Location:
- Remote: US / Canada
What You'll Do:
- Scaled and resilient security operations capabilities aligned with business growth and risk maturity.
- Material reduction in critical and high-risk security findings through preventive controls and remediation.
- Successful ISO 27001 / ISO 27017 / ISO 27018 HITRUST audit outcomes, with improved audit efficiency year over year.
- Demonstrated adoption of Secure-by-Design and DevSecOps practices across cloud and on-premise products and R&D pipelines.
- Improved executive visibility into cyber risk with actionable, business-oriented reporting.
Strategic Leadership
- Define and execute AGFA HealthCare’s enterprise information security strategy in alignment with business goals, healthcare regulations, and patient safety priorities.
- Act as a trusted advisor to executive leadership and the board on cyber risk posture, emerging threats, and security investment priorities.
- Serve as an executive customer-facing security leader, engaging directly with clients to articulate the company’s security strategy, build trust, address risk and compliance concerns, and support sales efforts by positioning security as a strategic business enabler
- Lead the development and evolution of governance frameworks, policies, and standards supporting HIPAA, FDA 21 CFR Part 11, ISO 27001, ISO 27017, ISO 27018, and SOC 2.
- Embed security by design across products, platforms, imaging workflows, and the full data lifecycle, including third‑party and embedded solutions.
- Partner with Marketing and commercial teams to articulate AGFA HealthCare’s security posture and trust narrative to the market.
- Champion a strong culture of security awareness, education, and accountability across R&D, CloudOps, and customer-facing teams.
Operational Oversight
- Provide leadership and direction for security operations across AGFA HealthCare, including cloud and on‑premise environments.
- Establish, scale, and continuously improve SOC capabilities, ensuring effective detection, response, and recovery aligned with business needs and risk profile.
- Oversee threat intelligence, vulnerability management, and incident response with a focus on automation and continuous improvement.
- Partner with CloudOps and DevOps teams to integrate DevSecOps practices into CI/CD pipelines.
- Optimize and scale security tooling, including AWS-native services and endpoint protection platforms.
Risk, Compliance, and Governance
- Ensure compliance with global security and privacy standards across cloud and on‑premise environments.
- Oversee risk assessments, privacy impact analyses, and security reviews.
- Maintain and evolve the incident response program in partnership with Legal, Privacy, ISP, and Quality and Regulatory teams.
Who You Are:
- 10+ years of progressive experience in cybersecurity with 5+ years leading enterprise security programs or functions; proven leadership in high-growth or highly regulated environments.
- Demonstrated success designing and operating security programs aligned to leading frameworks and sustaining regulatory compliance and audit readiness.
- Expert ability to identify, prioritize, and communicate risk; proven track record translating complex technical concepts into actionable insights and decisions for executive, Board, and technical audiences.
- Strong cross-functional leadership and collaboration skills; experienced at influencing product, engineering, IT, legal, compliance, and operations stakeholders.
- Advanced knowledge across core security domains: endpoint protection, monitoring/telemetry, DLP, IAM/zero trust, vulnerability/patch management, incident response, cloud and infrastructure security, authentication/authorization, and sensitive data protection.
- Experience leading incident response, resiliency programs, and crisis management, including executive and Board-level reporting.
Our Values:
- Own It (I do what I say, full accountability for results, finding solutions and Practice ethical and safe behaviors)
- Play as One (Collaborate for a common goal, diverse perspectives. Listen and communicate with respect, support decision for teams’ benefits)
- Move Forward (Embrace change, explore opportunities to innovate, feedback and improve performance, Proactive steps to resolve issues and continuous progress).
- Drive Value (Bold choices to maximize value creation, customer deliver exceptional value, add value to all stakeholders, use data to generate crucial insights and outcomes).
- Advanced security certifications (CISSP, CISM, CCSP, AWS Certified Security).
- Background in medical imaging or healthcare IT.
- Familiarity with AI/ML security considerations.
What we offer now and in the future:
- Dynamic global organization with a history of innovation and strong product portfolio.
- Challenging environment combined with a supportive management structure.
- Career development and growth.
- Competitive salary and benefit package.
- Friendly work environment surrounded by dedicated and professional colleagues.
Diversity and Inclusion:
At Agfa, our mission at Agfa is to ensure that everyone belongs. We believe that diversity and inclusion of others promotes a greater feeling of belonging and higher levels of engagement. We know that if we work together, we can do amazing things, and that our differences are what make our company, products, and services great.
We offer a rewarding career in a field that impacts lives, the opportunity to work with a talented and committed team of individuals, training and career development programs, and a competitive compensation and benefits package. If you want to be part of this experience, we'll take you there!
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment application process, please contact agfahealthcarehrna@agfa.com.
At Agfa HealthCare, we are passionate about creating an inclusive workplace that promotes diversity of Age, Gender, Gender Identity or expression, Race, Sexual Orientation, Physical Ability, Ethnicity, or any other aspect that makes someone unique. The differences among us are our strengths. We are committed to promoting a diverse, equal and inclusive workplace that fully represents the different cultures, viewpoints and backgrounds of our global organization and the world we live in.
Learn more about Agfa HealthCare and follow us on Instagram.
Job Segment:
Information Security, Compliance, Cloud, Embedded, Cyber Security, Technology, Legal, Security