What are the responsibilities and job description for the Cybersecurity Consulting Lead position at ECRI Institute?
Job Details Job Location Corporate Headquarters - Plymouth Meeting, PA Remote Type Hybrid Position Type Full Time Education Level Graduate Degree Preferred Travel Percentage 10% Job Shift Day Job Category Health Devices Description
WHY CHOOSE ECRI?
ECRI is an inspiring place to work. We share a common mission to help healthcare organizations make smart, compassionate, and ethical decisions for patients. Consider these additional benefits of joining the ECRI team :
- Industry leadership : We have a long history and proven reputation in patient safety and medical technology research.
- On-the-job-learning : You will have the opportunity to work with specialists across medical science, patient care, healthcare management, and technology.
- Comprehensive healthcare benefits : We offer medical, dental, vision, life insurance, accidental death and dismemberment, and disability coverage.
- Retirement Savings : Our employees can participate in an employer-matching 403(b) Retirement Savings Plan.
- Additional benefits : ECRI offers additional benefits to our employees, including paid time off and holiday pay, paid leave for parents, tuition assistance, employee assistance program, access to LinkedIn Learning, and other voluntary benefit programs (e.g. accident insurance, identify theft insurance, flexible spending accounts).
- Volunteer Program : ECRI Cares, our employee volunteer program, provides a framework for us to work together and make a difference in the lives of others. All employees are provided 16 hours annually of paid time to volunteer at preapproved ECRI Cares charities during normal business hours.
ABOUT ECRI
At ECRI, our passion for safe, effective, and efficient care is ingrained into the fabric of who we are and why we are here. For more than 50 years, the people of ECRI have been unyielding in their work to protect patients from unsafe and ineffective medical technologies and practices. Now, with the acquisition of the Institute for Safe Medication Practices (ISMP), we have created one of the largest healthcare quality and safety entities in the world.
As a non-profit, independent organization, we utilize an unbiased, evidence-based approach to develop guidance, and maintain our principles of integrity and transparent work. Our ethical standards have led us to adopt the industry's strictest conflict-of-interest policies, and they are why tens of thousands of healthcare leaders worldwide rely on ECRI to guide their clinical, operational, and strategic decisions across all sites of care.
The Most Trusted Voice in Healthcare
ECRI is proud to serve the healthcare industry, from providers and insurers to government agencies, and medical associations. Our areas of focus include :
ECRI is the only organization worldwide to conduct independent medical device evaluations, with labs located in North America and Asia Pacific. ECRI is designated an Evidence-based Practice Center by the U.S. Agency for Healthcare Research and Quality and a federally certified Patient Safety Organization by the U.S. Department of Health and Human Services.
At ECRI, our passion for the truth drives us to go further and dig deeper in our pursuit to advance effective, evidence-based healthcare globally.
The success of our organization relies on the kind of creative thinking that can only result from a diverse team of individuals. ECRI is proud to be an employer of choice with an inclusive environment for all employees. As part of this goal and in compliance with various laws and regulations, ECRI provides reasonable accommodation to applicants and employees.
It's what makes ECRI unique, and why we are the most trusted voice in healthcare.
POSITION SUMMARY
To evaluate cybersecurity and interconnectivity of medical devices, provide technical consultation and risk assessment to the healthcare community based on current and future needs and trends, develop and execute risk assessment services, apply broad judgment and experience to multiple Device Safety activities. To participate in diverse ways, such as helping to plan new programs, selecting and training staff, and assisting in managing ongoing internal and external projects. To serve as a key information security expert within the Device Safety team.
ESSENTIAL FUNCTIONS
Reasonable Accommodation Statement :
To accomplish this job successfully, an individual must be able to perform, with or without reasonable accommodation, each essential function satisfactory. Reasonable accommodations may be made to help enable qualified individuals with disabilities to perform the essential functions.
Essential Functions :
General :
Consultation :
Product Evaluation and Guidance :
Community Education :
Administrative :
Additional Responsibilities :
Other duties, as assigned.
Accountability Metrics :
Stay up-to-date with current trends and anticipate future trends in the cybersecurity space.
Meet established deadlines and deliverables for internal and external clients.
Effectively communicate findings with strong written, verbal, and presentation skills.
Qualifications
POSITION QUALIFICATIONS
Experience :
3-5 years of relevant cyber security experience required, with experience in cyber security consulting preferred.
5-7 years' work experience in a clinical setting or in a relevant technical field.
Experience and exemplary knowledge in NIST 800-53, 800-171, HITRUST, SOC2, and / or other equivalent experience and / or regulatory knowledge and understanding.
Strong knowledge of cyber security principles, operations security, cyber threats and vulnerabilities, and knowledge of national regulations, policies, and ethics as they relate to cyber security.
Experience with medical device manufacturer disclosure statements for medical device security preferred.
Ability to communicate very effectively and concisely both orally and in writing.
Must have proven track record of dependable, reliable, and thorough performance and be able to manage changing priorities for multiple simultaneous tasks
Education :
Bachelor's degree required, preferably in computer engineering, information security, or a related field. Master's or doctoral degree preferred, preferably in computer engineering, information security, or a related field.
Computer Skills :
Proficiency with Microsoft Office 365 Suite of Products (e.g., Excel, Word, and PowerPoint)
Certifications and Licenses :
Certified Risk and Information Control (CRIC) or Certified Information Security Systems Professional (CISSP) preferred, or equivalent.
Certified Biomedical Equipment Technician (CBET) and / or Certified Clinical Engineer (CCE) preferred, or equivalent.
POSITION COMPENSATION
The salary range for new employees in this position is $107,776.96 - $122,315.47, based on background, experience, and skills. In addition, new employees in this position are eligible for all of our benefit offerings, including, but not limited to, health and welfare benefits, 403(B) retirement savings, and paid time off (PTO).
PHYSICAL DEMANDS
Table Legend : Not Applicable (N)
Activity is not applicable to this position.
Occasionally (O)
Position requires this activity up to 33% of the time (0 - 2.5 hours a day)
Frequently (F)
Position requires this activity from 34% - 66% of the time (2.5 - 5.25 hours a day)
Constantly (C)
Position requires this activity more than 66% of the time (5.25 hours a day)
Movement : Stand
Walk
Manually Manipulate
Grasp
Reach Outward
Reach Above Shoulder
Speak
Climb
Crawl
Squat or Kneel
Bend
Vision
Lift / Carry : 10 lbs or less
11-20 lbs
21-50 lbs
51-100 lbs
Over 100 lbs
Push / Pull : 12 lbs or less
12-25 lbs
26-40 lbs
41-100 lbs
ADA STATEMENT
ECRI is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity, or veteran status. We value diversity and believe that a diverse workforce enhances our ability to succeed. ECRI complies with applicable federal, state, and local laws governing nondiscrimination in employment and prohibits any form of discrimination or harassment based on these protected characteristics.
EEO STATEMENT
ECRI is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity, or veteran status. We value diversity and believe that a diverse workforce enhances our ability to succeed. ECRI complies with applicable federal, state, and local laws governing nondiscrimination in employment and prohibits any form of discrimination or harassment based on these protected characteristics.
LI-Hybrid
Salary : $107,777 - $122,315