Information Security Officer

Any city, MS, US, 99999

Gainwell Technologies

Gainwell empowers you through innovative technologies and solutions to deliver better health and human services outcomes.

View all jobs at Gainwell Technologies

Summary

As Information Security Officer (ISO), you will be accountable for all security-related compliance and delivery for the customer(s) assigned. In a typical engagement, you operate as a trusted advisor in the organization, working with senior management and focusing specifically on health care industry regulated security requirements and environments in relation to client business objectives. The ISO helps business leaders understand operational issues and plans next steps from an information security viewpoint. This requires the ability to interact and influence at a managerial level within the account such as with Delivery Leads and the Account General Manager. You will be able to demonstrate industry expertise and understanding of security governance and compliance. Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the National Institute of Standards and Technology (NIST) 800-53 framework are the standard security frameworks that the ISO will be reviewing, maintaining, and helping to assess on each designated account or health care product within Gainwell Technologies and its partners.

Your role in our mission

  • Compliance and security driven
  • Lead security operational governance activities
  • Ensuring delivery excellence in security tooling and business operations (Ensuring avoidance of non-performance / non-compliance leading to contractual penalties).
  • Relationship management with Gainwell Technologies suppliers and the client.
  • Maintain an account security plan for the selected account(s) and products
  • Report and manage security incidents
  • Assist audit preparation, facilitation, and remediation
  • Manage security risks and exceptions
  • Ensure knowledge and implementation of security fundamentals, policies, and standards (regulatory and contractual)
  • Escalate and resolve security issues
  • Coordinate delivery of security metrics and reporting in support of contractual commitment

What we're looking for

  • At least 3 years’ experience working in a risk management, audit, security, or technical delivery role
  • Bachelor or master’s degree in Computer Science, Computer Studies, Information Security (or equivalent combination of education and experience)
  • Experience as a Security consultant, architect and/or engineer
  • Experience with and understanding of the security and auditing regulations
  • Experience with audit and compliance programs, including leading audits and remediation efforts
  • Experience with HIPAA, NIST, and FedRAMP
  • Excellent and effective communication skills
  • Experience in working with security management including information governance and compliance
  • Good understanding of information security industry best practices with hands on experience
  • Experience of security processes and standards, in particular, NIST 800-53, and/or ISO27001
  • Knowledge of security audit processes

What you should expect in this role

  • Functionally reports to the Regional Information Security Manager as part of the Office of the Chief Information Security Officer (OCISO) to coordinate effort, solutions, and promote security practices.
  • Works in conjunction with the Account Delivery Leader (ADL)
  • Partners and collaborates with the information security staff to leverage existing solutions and promote common standards.

 

The deadline to submit applications for this posting is October 14, 2024.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Audits CISO Compliance Computer Science FedRAMP Governance HIPAA ISO 27001 NIST NIST 800-53 Risk management

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.