|
How is this team contributing to the vision of Providence?
Cyber Security is committed to appropriately protecting all information relating to its caregivers and affiliates, as well as protecting its confidential business information (including information relating to its caregivers, affiliates, and patients).
What will you be responsible for?
- Identify, develop, and implement necessary enterprise-wide security programs and projects that include budget, resource plans, work-plans, schedules and supporting training and documentation.
- Readily able to translate strategic direction into a concrete action plan with milestones and success criteria.
- Lead proactively to identify projects & collaborate with multiple pillars to enhance standardization, efficiency & maturity of GRC function.
- Manage, coach, mentor, and develop functional team, including identification of training needs and recommending development programs.
- Implement higher-level security requirements and integrate security programs across disciplines.
- Leads end-to-end(E2E) Cybersecurity Internal Audits right from planning to remediation of Observations & Issues.
- Provide and support implementation of IT GRC initiatives globally
- Support in designing GRC frameworks
- Support in achieving KPIs and metric for the GRC processes
- Maintain updated knowledge in the field of GRC to efficiently work on frameworks including NIST CSF, CIS Controls, HIPAA, PCIDSS, ISO27001, GDPR, SOX 404, ITIL, etc.
- Remain current with industry best practices and monitor the legal and regulatory environment for developments.
What would your work week look like?
- Regularly collaborate with business leaders, application, and product owners to evaluate security needs and impacts of security decisions on business processes as well as to communicate risks.
- Drive implementation of framework, policies, standards, and other security requirements.
- Conduct gap analysis and implement Standards Frameworks like ISO 27001, Privacy, GDPR, NIST CSF, HIPAA, PCIDSS, SOX etc.
- Develop and revise Policies, Standards, Processes, and guidelines for the enterprise through change management
- Complete security reviews, attestations requested by regulatory/business partners.
- Responsible for creating Audit Calendar for the organization, performs Internal audits, security risk assessments for HIPAA, PCIDSS, ISO27001, URAC etc
- Perform security reviews, attestations, assessments and serve as a Liaison between various teams and Cybersecurity
- E2E implementation of Integrated control framework program.
- Prioritize work, delegate tasks and effectively address difficult situations.
- Manage expectations and effectively communicate to colleagues, project team members, sponsors, stakeholders, business leaders, as well as internal and external security stakeholders and leaders.
- Promote and raise awareness of Cyber-Security programs and posture, driving change and influencing proper Cyber Security hygiene within the organization.
Who are we looking for?
- 4-year University (Bachelor’s) degree in Computer Science, Information Security, Cyber Security or related field.
- Minimum 8 years of experience in an Information Security/GRC role.
- Minimum 5 years of experience in IT Risk Management Role/GRC role.
- Preferred 3 years of experience in Healthcare, Pharma or Bio-Technology organization.
- Experience with managing a GRC tool support life cycle.
- Strong written and oral communication skills with the ability to explain technical ideas to non-technical individuals at any level.
- Adaptable to shifting priorities, demands, and timelines through analytical and problem-solving capabilities. Able to react to project adjustments and alterations promptly and efficiently.
- Demonstrated experience working independently and in collaboration with cross-functional teams. In addition, has demonstrated experience providing in-depth analysis of complex issues which are then presented to cross-functional teams.
- Ability to effectively prioritize and execute tasks in a high-pressure environment
- Preferred knowledge of Information Security standards (ISO/IEC 27001, 27002, NIST CSF, HIPAA, PCIDSS, HITRUST, CIS Controls)
|