IT Securtity Risk Specialist

  • Full-time

Company Description

.

 

Job Description

This position will be responsible for completing Vendor Assessments for the Vendor Risk Management team.
This role will primarily focus on the following specific areas of responsibility:
-Day-to-day management of Information Security risk identification, mitigation and acceptance processes in coordination with security operations and maintaining program requirements language
-Execution of training, education and awareness of all users, managers and board members regarding Information Security vendor requirements and expectations
-Operational risk planning, mitigation and remediation to address Information Security deficiencies
-Identifying new vendor engagements and renewal of existing vendor assessments. Coordinating distribution and completion of vendor assessment questionnaire
-Reviewing on-site assessment reports, examining risks and controls associated with all aspects of the vendor
-Drafting preliminary findings reports
-Conducting preliminary results meeting with BCBSM and its subsidiaries stakeholders and management staff
-Receiving and review vendor response-action plan, if necessary
-Communicates the results of assessment and-or projects in a clear and concise manner to all levels of management
-Designs and operate key operational and executive metrics, reports and dashboards

Qualifications

 5+ years of Vendor Risk Management in the Healthcare space
- Strong knowledge of HIPAA and other applicable Healthcare laws
- Strong understanding of the development and operation of a Risk Management program

Additional Information

 Extensive experience building and managing a diverse and inclusive team environment with strong commitment to respect, equality and teaming.
- Strong understanding of IT Audit/Information Security control review and remediation plans
- Strong understanding of Information Security and the relationship between threat, vulnerability and information
- Good understanding of risk-based decision-making (i.e. risk analysis, mitigation, resolution, acceptance, etc.)
- Possess a good understanding of appropriate leading-edge governance-enabling technologies.
- Possess a good understanding of regulatory and best practice frameworks in the information security context (HITRUST, HIPAA, HITECH, ISO, etc)
- Strong written and verbal communication skills