Senior Security Controls Engineer at HCA Healthcare
Nashville, TN 37203, USA -
Full Time


Start Date

Immediate

Expiry Date

08 Nov, 25

Salary

0.0

Posted On

10 Aug, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Security Controls, Reporting, Interpersonal Skills, Technology, Information Security, Security Metrics, Risk Assessment, Hipaa, Communication Skills, Regulatory Compliance

Industry

Information Technology/IT

Description

INTRODUCTION

Experience the HCA Healthcare difference where colleagues are trusted, valued members of our healthcare team. Grow your career with an organization committed to delivering respectful, compassionate care, and where the unique and intrinsic worth of each individual is recognized. Submit your application for the opportunity below:Senior Security Controls EngineerHCA Healthcare

NOTE: ELIGIBILITY FOR BENEFITS MAY VARY BY LOCATION.

We are seeking a Senior Security Controls Engineer for our team to ensure that we continue to provide all patients with high quality, efficient care. Did you get into our industry for these reasons? We are an amazing team that works hard to support each other and are seeking a phenomenal addition like you who feels patient care is as meaningful as we do. We want you to apply!

JOB SUMMARY AND QUALIFICATIONS

The Security Controls Engineer is a technology and process focused security professional with an emphasis in information security controls, risk assessment, regulatory compliance, and security consultation. Applies information security concepts, knowledge, and skills to support a comprehensive information protection program. The Security Controls Engineer evaluates and monitors the current state of security controls across the organization related to people, process, and technology as well as with 3rd party vendors external to the organization.

RELEVANT WORK EXPERIENCE

  • 5+ years

EDUCATION

  • Bachelor’s Degree Preferred

OTHER/SPECIAL QUALIFICATIONS

Certifications (preferred, not required):

  • CISSP Certified Information Systems Security Professional
  • GSEC GIAC Security Essentials Certified
  • CISA Certified Information Systems Auditor
  • PCIP PCI Professional Training
  • HCISPP Healthcare Information Security and Privacy Practitioner

PREFERRED AREAS OF EXPERIENCE:

  • Security Technologies / Methodologies
  • IT Audit/Risk Management
  • Information Security Metrics and Reporting
  • Systems Control Review Process
  • Application/Infrastructure Control Review Process
  • Working knowledge of the COSO and COBIT methodologies
  • Experience with ISO17799, HIPAA, Sarbanes-Oxley, PCI-DSS
  • Experience with IT risk, regulatory, or compliance responsibilities
  • Possession of excellent analytical and interpersonal skills
  • Possession of excellent oral and written communication skills
Responsibilities
  • Performs the collection of the top and most pressing IT security risks (regulatory, security of critical enterprise applications and infrastructure, vendors, etc.), analyze, monitor, and derive strategic decisions that balance risk with operation and economic costs of protective measures.
  • Performs interviews with company senior management and business owners to confirm anticipated business effects resulting from the actual occurrence of any of the identified enterprise security risks.
  • Leverages inventory of key vendors, applications, processes, and infrastructure items and their impact to the top and most pressing IT security risks. Additionally, maps applications, processes, and infrastructure items to appropriate security risks.
  • Performs activities to identify key controls (policy, procedure, practice, or organizational structure) that if implemented would provide reasonable assurance that security objectives will be achieved and undesired events will be prevented or detected and corrected
  • Performs activities to review, develop, and implement security controls plans, vendor security agreements, and security exceptions to control standards.
  • Performs activities to conduct technical security reviews and assessments of vendors, applications, processes, and IT infrastructure.
  • Performs activities related to the analysis of data collected during security reviews and assessment of vendors, applications, processes, and IT infrastructure in order to determine current state of security risk across the company.
  • Performs activities to develop remediation plans to address issues discovered as result of security reviews and/or assessments of vendors, applications, processes, and IT infrastructure. Works with management to assign remediation responsibilities, actions, and priorities.
  • Performs activities to monitor and track remediation activities to address weaknesses and issues discovered through security reviews or audits of vendors, applications, processes, and IT infrastructure.
  • Performs activities to develop strategies to ensure compliance with security standards as well as regulatory and audit issues.
  • Performs activities to provide periodic reporting including assessment findings and recommendations for improvement to applicable constituencies (e.g., executive management, facility leadership, and governance committee).
  • Identifies security related regulatory requirements (ie. PCI-DSS, SOX, HIPAA), and interacts with internal and external assessors and auditors to ensure ongoing compliance.
Loading...