Jason Torres
Associate Director, Security Threat & Incident Management @ Memorial Sloan Kettering Cancer Center
About
An accomplished Cybersecurity and Risk Management Leader that specializes in building and managing robust security programs with a budget exceeding $15M, prioritizing risk management and data security. Strategic vision and relationship building is evident through co-founding an international cybersecurity conference and establishing initiatives like the Cybersecurity Governance Committee and Third-Party Risk Management Program. Recognized as a finalist for Non-Clinical Manager of the Year in 2022 directly to excelling at fostering cross-functional collaboration and leading high-performing teams most recently of 2 managers, 12 analysts/engineers, and 2 architects. Drives a culture of success through principled leadership, building trust, empowering individuals and establishing a sense of shared commitment through technical expertise and a deep understanding of business priorities to drive success.
United States
Greater Chicago Area
Hospital & Health Care
Business Relationship Management, Budget Management, IT Strategy, Security Operations, Payment Card Industry Data Security Standard (PCI DSS), Identity and Access Management (IAM), Information Security Management, Internal Controls, Internal Audit, Process Engineering, Business Process Improvement, Healthcare, Risk Assessment, IT Audit, CISA, HIPAA, Project Planning, Project Management, Auditing, Hospital Operations
Experience

Associate Director, Security Threat & Incident Management
Remote
Provide strategic security oversight: Lead the STIM team and advise executive leadership on security threats, incidents, and vulnerabilities, ensuring informed decision-making. Manage enterprise security tools: Oversee deployment and management of key security technologies, including endpoint threat protection, vulnerability scanning, SIEM, and EDR solutions. Drive incident response and investigation: Ensure prompt and effective response to security incidents, oversee incident investigations (including digital forensics), and maintain incident response procedures and playbooks. Develop security policies and training: Assist in crafting and enforcing security policies, standards, and compliance measures while coordinating security awareness and training programs. Monitor threat intelligence and third-party operations: Manage threat intelligence processes and supervise the third-party Security Operations Center, ensuring proactive identification of threats and efficient triage of security alerts.

Cybersecurity Director – GRC, IAM, Administration
Chicago, Illinois, United States
+ Governance • Partner with key stakeholders across privacy, legal and technology to support the expansion efforts of the Rush brand through assessment and remediation of GRC related issues • Understand the enterprise strategy and integration of security into RUSH business strategies and processes while ensuring that the results are documented and actionable, with clear ties to the NIST CSF framework and accountability to the ERM Program and Rush Cybersecurity Governance Committee + Risk • Drive the security risk management process to ensure consistency of approach and regular tracking and reporting of high risks • Drive the vendor risk management process by working closely with legal and procurement; Monitor the effectiveness of the security risk management and third party management functions + Compliance • Provide leadership and guidance to departments across Rush impacted by regulatory compliance (HIPAA, PCI, etc) • Provide oversight to information security incident response planning and investigation of breaches + Administration • Provide enterprise-wide leadership and direction in all areas of information security, risk management, regulatory compliance and security programs • Align the security team scope, budget, and staffing to the company level strategy, emerging technologies, and threat landscape + Medical Device Security • Conduct risk assessments in order to characterize the potential risk of the device and system at various stages of its lifecycle • Operate programs needed to manage cybersecurity risk of new and existing devices including vulnerability handling and incident response + Identity & Access Management • Participate in projects and initiatives with Rush business stakeholders/service owners to provide consensus-based enterprise IAM solutions that are scalable and adaptable • Lead the ongoing operations and enhancements of IAM solutions and service level metrics through ServiceNow

Cybersecurity Manager GRC
Chicago
+ Responsible for developing, implementing and maintaining the security systems used by Rush University Medical Center (RUMC) + Work closely with the CISO in collaboration with corporate compliance, internal and external auditors to ensure the maximum level of information security + Supervises security analysts and engineers to ensure proper implementation and support of security infrastructure and operational workflows and provides oversight of all security operations + Assesses security needs and capabilities of the organization through regular reporting to IT management but also Medical Center and University management concerning the current state of security measures and makes recommendations for improvement as required + Develop and enhance the overall security program and content including policies and procedures + Build up the capabilities of the information security awareness training to increase competencies of the organization as a whole + Works with IT management, risk managers, corporate compliance and in-house legal counsel to perform and maintain risk assessment concerning system down time, unwarranted system access and general risk levels + Works with internal and external auditors to response to needed requests and security related findings + Provides support in the development and implementation of security controls for clinical and finance applications + Works closely with cross functional IT teams to understand the security architecture and coordinates the implementation of changes in security once approved through the configuration management + Oversees user support issues regarding user access to all applications + Maintains relationships with clinical and business management to identify and understand security issues related to Rush Applications that need to be addressed through IT management and technical teams

IT Audit Manager
Chicago, Illinois, United States
- Develop, execute and continuously innovate Rush’s IT Audit function through multiple audits focusing on general operations, application and security control reviews. - Create annual and long-term IT Audit plans through risk assessment meetings with management - Built strong trust-based relationships with varying levels of Medical Center personnel to be a resource for mitigating risks identified and review process improvements. - Proactively assist management in the development of action plans that adequately address issues, present audit reports to Rush management and conduct follow-up audits to ensure implementation of management action plans. - Manage and train Internal Audit staff and interns to develop their knowledge of Medical Center operations, providing feedback on performance and mentoring them in their career paths. - Manage and provided effective IT audit and consulting support to external and internal stakeholders as required. - Perform non-IT reviews over hospital operations, financial reporting and healthcare revenue cycles. Key Accomplishments - Assisted in the development of IT focused risk initiatives related to the Rush ERM process. - Through collaboration with the Information Services Management Team, assessed the overall maturity scale of the Rush Information Services department against the newest COBIT 5 framework and communicated through specific deliverables. This included categorizing IT operational effectiveness, evaluating application and data flow risks and determining priority IT focus areas through collaborative agreement with the Information Services Management Team - Performed Rush’s first PCI assessment to evaluate our data security standards and aid in obtaining higher coverage for Rush’s cyber liability policy. Performing internally saved Rush $40-50k. - Initiated the first ever IT Security assessment of Rush using SANS CIS Critical Security Controls

Staff/Senior Auditor
Chicago, Illinois, United States
Responsible for creation and execution of audit plans to identify potential risks and areas of improvement. This included preparation and presentation of audit reports to all levels of management including the Board. Developed and maintained relationships with clients to ensure timely and accurate closure of control recommendations.

Associate Pastor - Millennial Ministry
Chesterton United Methodist Church
Chesterton, IN
Part time local pastor responsible for creating a sustainable ministry for the 21-40 year old crowd
Jason Torres's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



