Information Security Analyst

An enterprising practice management firm developing cutting edge software to simplify the processes clinicians use to coordinate and develop their practices. In pursuit of becoming the industry’s most widely used product, they have earned a reputation as the top-ranking software in the practice management space. They are looking for an information security analyst who will implement innovative information security controls that mitigate the organization’s risk, empower innovation and show continued dedication to security for both our customers and their clients. Required Skills Experience 5+ years experience in information security compliance 2+ years experience supporting compliance programs within the technology space 5+ years experience in security controls across all security domains such as access management, encryption methods, vulnerability management, network security, etc. Project management skills Experience of data security frameworks and regulatory standards, including PCI, HITRUST, HIPAA and NIST CSF Experience with developing security and compliance reporting for a variety of audiences, including executive management Demonstrated leadership skills with experience working effectively across various levels Experience developing and submitting audit and compliance reports to governing bodies, legal entities, andor external authorities Experienced in processes for assessing and designing internal controls for large scale organizations Experience assessing security risk for large scale organizations. Specific experience in cloud services organizations Certifications in one or more of the following areas preferred CISSP, CISA, CISM, CRISC, GISO, GCIH, CIPP What You Will Be Doing Daily Responsibilities Understand technical implementation details necessary to identify and assess security risks and recommend mitigating controls Participate in the development and oversight of required corrective action plans relating to security compliance issues Support business relationships with the internal and external security auditors and regulators Identify, research and evaluate new compliance requirements and ensure they are incorporated into the organization’s security policy framework Support the communication of policies, procedures, and plans to internal stakeholders regarding security and compliance best practices around applicable laws, regulations and controls Support the identification, validation and remediation of information technology controls Be responsible for Data Security Standards (HITRUST and PCI), regulations governing personally identifiable information (PII) and other applicable regulatory compliance frameworks Partner with internal teams to ensure successful security programs that align with compliance requirements Understand the security needs of internal and external stakeholders around external business partners and maintain a process that meets stakeholder needs Manage daily activities and functions of the external business partner management program Coordinate and drive business partner security assessment activities for both inbound and outbound relationships Lead assessments of business partner security risk, develop mitigation plans, and work with internal stakeholders to assign monitoring responsibility. Prepare and complete annual risk assessments and assist with regulatory and accreditation audit preparation as needed Support business partner selection on significant sourcing decisions and reassess security risk for business partners prior to contract renewal The Offer Competitive Salary Up to 130year, DOE You will receive the following benefits Medical Insurance Health Savings Account (HSA) 401(k) Paid Sick Time Leave Pre-tax Commuter Benefit Applicants must be currently authorized to work in the United States on a full-time basis now and in the future.

Related Post