Company :
HM Health Solutions
Job Description :
JOB SUMMARY
This job, as a technical expert in the security domain, sets and monitors role lifecycle management standards, best practices and systems necessary to ensure the protection of the confidentiality of informational assets, which requires strong technical knowledge of information systems, role based access controls (RBAC) and the use of established security control.
ESSENTIAL RESPONSIBILITIES
Provide Role Based Access Control (RBAC) analysis, design and implementation expertise within the Organization’s IAM Infrastructure; collaborating with lean purposed IAM Software Development team to refine and expand the adoption of a semantically logical and comprehensive RBAC framework.
Collaborate with Business Intelligence & Analytics groups; leveraging Tableau data visualization software for role-mining analysis, and dashboarding executive overview reporting.
Collaborate with IT Governance, Risk & Compliance group to expand and improve process certification using industry standard product solutions (Sailpoint, OIG, Dell One).
Document business requirements gathering and documentation for the design and implementation of an RBAC framework.
Provide business analysis support, drafting business requirements documentation for clients, as well as system integrations and operational support for User Access review campaigns.
Other duties as assigned or requested.
EDUCATION
Required
Substitutions
Preferred
EXPERIENCE
Required
3 – 5 years in Information Security and Risk Management with a focus on Role LifeCycle Management
3 – 5 years in Information Technology
3 – 5 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
Preferred
3 – 5 years in Information Security and Risk Management with a focus on software development companies
Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
In-depth understanding of network security architecture, network and networking protocols
LICENSES AND CERTIFICATIONS
Required
Preferred
Certified Information Systems Security Professional (CISSP)
Information Technology Infrastructure Library (ITIL)
Security SKILLS
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, Payment Card Industry (PCI), Health Insurance Portability & Accountability Act (HIPAA), HITECH, COBIT, International Organization for Standardization (ISO) 27001/2, and ITIL
Role Analytics background
Proficient in manipulating and querying databases/SQL
Fluent in scripting, building and running queries
Knowledge of NIST Risk Assessment methodology
Familiarity with secure SDLC best practices
Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
Strong teamwork and inter-personal skills
Adaptable and resilient: able to shift direction while remaining productive. Maintains focus in the face of challenge.
Consultative: skilled listener, prepares recommendations to client problems, adopts a customer first mindset, partner with internal and external project teams to drive results.
Organized/Time Management
Language (Other than English):
None
Travel Requirement:
0% – 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-based
Teaches / trains others regularly
Occasionally
Travel regularly from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement : This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, age, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, age, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.
EEO is The Law
Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled/Sexual Orientation/Gender Identity ( _https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf_ )
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.
For accommodation requests, please contact HR Services Online at [email protected]
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J202413
Job Description Now offering $1,000 in additional bonuses for onsite employees! Paid out in 2 installments: $500 for successful...
Apply For This JobThe position is a part time bookkeeper for an individual real estate developer in Boston, Ma Processing payments, invoices, income...
Apply For This Jobbr{display:none;}.css-58vpdc ul > li{margin-left:0;}.css-58vpdc li{padding:0;}]]> Part time position – full day schedule opportunities! About StratComm, Inc: StratComm, Inc. manages Verbatim...
Apply For This JobWhen you join our team as a Stocker, you’ll be responsible for stocking, organizing new incoming inventory and safely operating...
Apply For This JobJob Description The Food Service Worker will assist the manager with food/meal preparation; maintain cash receipts and meal records. Assist...
Apply For This JobJob Description – $17.00 PER HOUR – During third shift, greets and registers guests, providing prompt and courteous service....
Apply For This Job