Information Security Officer - Healthcare OperationsHouston, Texas onsite work required. Candidates available to move immediately will be considered. This is an expected 6-month client contract-to-hire position.Description of Duties/Essential Functions:Develop and implement Client specific Cyber security Master Plan aligned with the COH Cyber security Master Plan to address the confidentiality, integrity and availability of Client’s systems, data and informationDirects an ongoing, proactive risk assessment program for all new and existing Client’s systems and remains familiar with Client’s goals and business processes so effective controls can be put in place for those areas presenting the greatest information security riskResponsible for communicating risks and recommendations to mitigate risks to the COH CIO, CISO and HHD senior leadership team in cost/benefit terms so decisions can be made to ensure the security of information systems and information entrusted to Client.Oversees all ongoing activities related to the development, implementation and maintenance of Client’s information security policies and procedures by ensuring these policies and procedures encompass the overall security of protected health information (PHI) and electronic protected health information (ePHI) bot at rest and in motionAssists Client’s divisions, programs and Client’s Privacy Officer with efforts to ensure Health Insurance Portability and Accountability Act (HIPAA) compliance aEnsures Client’s vulnerabilities are managed and mitigated per COH Cyber Division policyAssists with the development of Client specific, role-based information security awareness training programs, and works with COH Cyber Division, Client’s divisions and programs to present to staff as appropriateWorks with COH CISO to ensure proper protections, technical and physical controls are in place to protect the confidentiality, integrity, and available of Client’s systems, data and information.Assists with the development and implementation of an HHD business continuity/disaster recovery plan to offset the impact caused by intentional and unintentional acts Evaluates security incidents and determines what response, if any, is needed and coordinates with COH CISO and COH Cyber Division on proper responses when sensitive data or information are compromisedAssists the COH CISO with Client’s insider threat investigationsRemains competent and current through self-directed professional reading, developing professional contacts with colleagues, attending professional development courses, attending training, conferences, and/or courses as directed by COH CISO, and obtaining certifications relevant to job dutiesRequirements:B.A.
or B.S. degree in Management and Information Systems (MIS), Computer Science, Engineering or a closely related field.Certified Information Systems Security Professional (CISSP) required; Certified Information Security Manager (CISM) and HealthCare Information Security and Privacy Practitioner (HCISPP) security certifications preferred.At least 5 years of experience developing and implementing cybersecurity plans and controls in a healthcare-focused organization. Strong understanding of the department’s core business functions and business strategy.Broad working knowledge of health care operations and their related data/software/hardware requirements including, but not limited to, hospitals, clinics, medical offices, and their information technology needsComprehensive understanding of the compliance and legal requirements for information confidentiality and integrity especially as it relates to patient information in a healthcare environment (electronic health/medical records (EHR/EMR), HIPAA, HITECH, etc.)Experience evaluating and managing cyber risk and working within industry-standard frameworks (e.g.
NIST Cybersecurity Framework, CIS Top 20, NIST 800-XX, etc.).Knowledge and experience with Windows, Active Directory, group policy, DNS, encryption, patch management, anti-virus, system configuration managementKnowledge and experience with LAN, WAN, VPN, routers, firewalls, servers, IDS/IPS, SIEM and DLPSolid expertise in formal/structured IT security risk assessment methodology, including understanding the implementation challenges and advantages across all levels of hardware platforms and software applicationsExperience with a wide variety of operating systems: Windows Server, Windows 10, Windows 7, Linux etc.Knowledgeable of Cyber Kill Chain and Diamond Model of Intrusion Analysis modelsKnowledge of SIEM, IDS, anti-virus/anti-malware and firewall technologiesSolid knowledge and understanding of networking and TCP/IPWell-developed interpersonal skills. Ability to get along with diverse personalities; tactful, mature and flexibleAbility to establish creditability and be decisive but also to recognize and support theorganization’s preference and priorities.Ability to maintain the highest standard of confidentiality is required with zero toleranceHigh energy level, comfortable performing multifaceted projects in conjunction with normalactivities.Results oriented with the ability to balance other business considerationsAbility to speak and present information effectively to groups of varying sizesProven experience working in a rapidly changing, high intensity environmentAvid, proactive learner and ability to work well in a team-based environmentStrong interpersonal and writing skills
Information Security Officer - Healthcare Operations in houston at Unknown Company
- Typical pay
- $34,060–$39,520
For context, most security guards earn between $34,060–$39,520 a year according to Bureau of Labor Statistics wage data. What this particular role pays is set by the employer — check the description above.
This position is listed as contract and onsite.