Reports To: Sr. Vice President, IT Engineering
Position Purpose: This position is responsible for supporting teams within the Infosec and IT Governance & Compliance department including their administrative responsibilities, supporting audit functions such as gathering documentation for auditors, and working with various internal departments to secure and defend Everise infrastructure.
Principle Accountabilities:
- Work with stakeholders to identify, design, rollout security service components & procedures ability to assess the business viability of new security adoption requirements
- Ability to conceptualize and develop security solutions to address customer's security challenges working with various cloud security solution providers and security & risk teams
- Managing security operations to ensure implemented security technologies & controls are effective and adequate to protect the company
- Manage the arrangement and oversee the implementation of a robust security monitoring program
- Conducting Identifying root causes and remediating of cybersecurity incidents.
- Providing advisory on security threats and vulnerabilities. This includes performing vulnerability scans and analyzing the results of the scans
- Overseeing the development and execution of corporate security awareness and training programs. This includes getting the buy-in of senior business stakeholders, which includes securing funding for IT security programs
- Enhancing early detection capability - Driving lessons learned activities after incidence closure to identify potential gaps in security control
Attributes & Attitude
- Dynamic and dependable
- Demonstratable written and oral communication skills
- Ability to work under pressure
- Integrity and drive
- Energetic and Enthusiastic
- Comfortable and even thrives in a fast-paced environment
Qualifications
- At least 12-14 years of experience in Risk, Compliance & Security domain and should have a proven track record of managing a practice and teams. Education will be considered in lieu of experience.
- Experience in working as part of a large cross-cultural team
- Must have exposure to data security, application security, infrastructure security & risk compliance domains
- Experience with IT audit activities
- Knowledge of PCI, SOC2 reporting and HITRUST framework preferred.
- Be proactive in achieving results and does not wait for assignments.
- Experience with US healthcare regulations a plus
- Excellent computer skills
- Ability to multitask.
- Ability to work well in a fast paced, team-oriented environment.
- Impeccable attention to details
- Project management skills a plus
- Ability to work independently and manage tasks with minimal supervision