PC
Information Security Specialist
Partners Consulting, Inc.
- 🇺🇸 United States
- Hybrid
- Manager or above
- 11 hours ago
- Regulatory Compliance
- Risk Management
- Change Management
- HIPAA
- NIST
- EHR
- Active Directory
- Unix
- Epic
- ERP
- TCP/IP
- PowerPoint
- Visio
11 hours ago
Location:Philadelphia, PA (hybrid)
Type: Contract
Â
Our direct client is seeking a InfoSec Specialist with demonstrated experience leading security design for new technologies across the full lifecycle, from initial evaluation through implementation. The ideal candidate has technical experience with security logging and security monitoring technology (i.e. security incident and event management technology, managed detection and response technology, etc.), Microsoft technology experience, experience working with Managed Security Service Providers (MSSPs) and Cloud providers, and experience with managing governance over security initiatives, such as security logging governance.
Â
The InfoSec Specialist must be able to work independently and draw upon extensive professional knowledge and experience to make independent judgement regarding analysis, evaluation, development, and implementation of enterprise long-term solutions and operating initiatives. Excellent communication and documentation skills are a must.
Â
The position is primarily remote; however, there is potential to come on site so local candidates highly preferred. Security certifications are preferred but not required.
Â
Key Accountabilities:
- RFP and technology evaluation: Develop or tailor security requirements and questions based on the technology being evaluated; assess vendor responses; identify security considerations and risks; and document clear, actionable recommendations.
- Security architecture and design: Partner closely with the Security Architect to translate approved architecture, standards, and requirements into practical security designs for selected technologies.
- Security engineering and implementation: Engineer security controls and configurations and work collaboratively with technical, application, infrastructure, vendor, and project teams through build, implementation, validation, and transition to operations.
- Security-by-design mindset: Quickly learn unfamiliar healthcare technologies, understand their architecture and data flows, identify the security considerations that matter most, and apply appropriate controls early in the technology lifecycle.
- Communication and collaboration: Demonstrate strong written and verbal communication skills, with the ability to explain technical security requirements and recommendations clearly to both technical and non-technical stakeholders and work effectively across multidisciplinary teams.
Â
- Bachelor's degree in Computer Science, Information Systems, or related field.
- At least twelve (12) years of industry-related experience, including experience in one to two IT disciplines (such as technical architecture, network management, application development, middleware, information analysis, database management, or operations) in a multitier environment.
- At least six (6) years of experience with information security, regulatory compliance and risk management concepts.
- At least three (3) years of experience with Identity and Access Management, user provisioning, Role-Based Access Control, or control self-assessment methodologies and security awareness training.
- Experience with Cloud and/or virtualization technologies.
- Comprehensive knowledge and understanding of Information Security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.
- Knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, and ISO 27000 series).
- Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.
- Good knowledge of basic database query techniques and data mining to analyze data or other related database functionality.
- Knowledge of Microsoft Active Directory, UNIX, and Clinical applications is a plus.
- Experience implementing application-level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience is a plus.
- General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.
- Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, and Project).
- Experience with risk management frameworks.
- Ability to understand and comply with all enterprise and IS departmental information security policies, procedures, and standards.
- Demonstrates specialized and comprehensive knowledge in Information Security management practices, disciplines, regulations, industry standards, related frameworks, project management principles and methodologies, security engineering concepts, security operations model, and industry standards around architecture principles.
- Demonstrates exceptional skills in managing multiple projects and priorities in order to meet strategic goals and timelines.
- Exhibits the ability to plan, manage, and implement highly complex enterprise architecture and security implementations, enhancements, or modifications that require in-depth knowledge across multiple technical areas and business segments.
- Exhibits exceptional understanding of emerging regulatory and healthcare issues in order to develop internal and external checks and controls to ensure proper governance, security and quality of information assets.
- Demonstrates exceptional troubleshooting and collaborative skills required to identify, analyze and resolve complicated security issues.
- Demonstrates advanced proficiency in creating detailed documentation, performing budget planning and oversight, and providing input on infrastructure strategic planning, technology standards, and information security and risk practices.
- Exhibits ability to communicate effectively with clients, colleagues, vendors, and management and the ability to translate complex technical solutions into non-technical requirements documents.
- Performs planning, development, implementation, and delivery of enterprise architecture and engineering principles for new, existing, and future strategic and operational activities.
- Demonstrates the ability to provide technical expertise and consultation to the CIO, CTO, CISO, executive leadership, and other business and clinical leaders.
- At least three (3) years of experience working with matrixed high-performance teams is preferred.
Partner's Consulting is an award-winning IT Consulting and Recruiting firm based in the Philadelphia area. We’ve built personal relationships with our clients over many years and work directly with decision makers on all open positions. Our core values are focused on the highest level of professional dedication to our client's requirements coupled with our desire to partner with highly qualified talent for joint success.
Â
Â
37712024
Information Security Specialist · Partners Consulting, Inc.