Manager, Security Risk Assessments at CVS Health
Annapolis, MD 21401, USA -
Full Time


Start Date

Immediate

Expiry Date

02 Aug, 25

Salary

203940.0

Posted On

02 May, 25

Experience

4 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Qualys, Cissp, Critical Thinking, Nist, Architecture, Infrastructure, Cloud, Operating Systems, Communication Skills, Archer, Vulnerability, Information Technology, Security Risk, Regulations, Hitrust, Security

Industry

Information Technology/IT

Description

At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.
As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

POSITION SUMMARY

This role conducts thorough security risk assessments for new technologies before deployment and technologies post-deployment in the production environment. Identifies, assesses, analyzes security risks, scrutinizes potential vulnerabilities, and provides risk mitigation strategies to ensure compliance and adherence to information security standards for a seamless and secure integration. This role will require the colleague to engage project managers, project management team members including developers, architects, infrastructure engineers, and EIS stakeholders as applicable. This role should be able to describe technical issues to business partners or senior leaders in risk terms that are clear and understandable while still having some subject matter expertise. This role should be able to lead small teams, mentor junior team members, oversee third party contractors, and respond to critical requests.

REQUIRED QUALIFICATIONS

  • 5+ years of information security experience
  • 4+ years working knowledge of common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA/HITECH, HITRUST and PCI-DSS
  • 4+ years working knowledge of Information Technology including concepts like Cloud, access management, architecture, infrastructure, operating systems, application/software development, and endpoint security

PREFERRED QUALIFICATIONS

  • Industry related certification such as CISSP, CISM, CRISC, etc.
  • Ability to comprehend implications of security risk (inherent risk, residual risks), compensating controls, etc.
  • Solid written and verbal communication skills
  • Ability to demonstrate critical thinking and knowledge of risk management basic processes, tools, and techniques
  • Experience operating in applications including Archer, Qualys, Checkmarx, and Prisma
  • Solid knowledge of Information Security policies and procedures
  • Solid knowledge of regulatory (including Audit frameworks) standards, including but not limited to NIST 800-53, SOX, SOC1/SOC2 Type II audits, HIPPA/HITECH, HITRUST, and PCI-DSS
  • Knowledge of current security threat and vulnerability trends
  • Understanding of cloud Security best practices and frameworks

EDUCATION

  • Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience)
Responsibilities

Please refer the Job description for details

Loading...