What are the responsibilities and job description for the Cyber Security Analyst (Full-time/On-site) position at Humboldt Park Health?
Position Summary:
Manages the overall implementation, tracking, monitoring, auditing and reporting on user system activity, security and usage related to Humboldt Park Health’s computerized systems, including the EMR and attached systems and those systems having Personal Health Information (PHI). Remains current with evolving regulations (including HIPAA) related to system and data security, in order to assist Humboldt Park Health management in developing, maintaining, recommending, and operationalizing data security policies and procedures related to system security and data confidentiality. Manages systems, interfaces, and develops reports where needed related to data security and monitoring systems.
Assists Compliance and HIPAA Officers in the creation and implementation of policies and procedures related to record retention, disaster recovery and business continuity. Audits and approves user system profiles and access rights in conjunction with the Information Technology Services team. Assists management in the documentation, education and training of staff. Maintains current knowledge related to local, state, and federal regulatory requirements related to IT data security, financial systems and HIPAA security. Assists management in the gap analysis and execution of the long-term HIPAA security action plans to maintain Meaningful Use, HITECH, DNV, and other compliance agency regulatory
Essential Duties and Responsibilities:
- Monitors, audits and recommends changes to overall access to controlled areas and information systems that process or handle highly confidential and sensitive data.
- Assists in the creation, ongoing maintenance and implementation of data security and HIPAA security auditing, monitoring, and reporting policies and procedures, including the establishment of corporate user security access profiles.
- Assists in the creation and maintenance of disaster recovery and business continuity policies, procedures and action plans.
- Assists in the overall approval process of system change management implementations to ensure data and confidential security and accesses are maintained to ensure regulatory compliance.
- Monitors, audit reports, and enacts corrective action on data/system usage, including tables/catalogs/dictionaries, for appropriateness and need basis for fulfilling business needs while ensuring the confidentiality of the data and patient information.
- Creates and maintains educational materials and performs ongoing education and training related to data compliance and HIPAA security issues for staff and the community.
- Implements and maintains systems utilized in the auditing, monitoring, and reporting of data and HIPAA security and confidentiality usage and breaches.
- Uses data encryption, firewalls, and other appropriate security tools and applications to conceal and protect transfers of confidential digital information.
- Determine frequency to update virus protection systems by monitoring current reports of computer viruses; facilitates or performs needed updates.
- Develop a security plan for best standards and practices for the company.
- Conduct frequent testing of simulated cyber-attacks to look for vulnerabilities in the computer systems and take care of these before an outside cyber-attack.
- Make recommendations on security advancements to best protect the company’s systems.
- Conduct or coordinate vulnerability scans, and penetration tests on campus systems, document findings, and recommend risk mitigation strategies.
- Collaborates with the executive team, leadership and customers to solve problems and improve business operations through process re-engineering, to meet or exceed data security and HIPAA security regulatory requirements.
- Provides leadership and direction to Humboldt Park Health management and staff, as it relates to data and HIPAA security measures, controls, and corrective action processes to ensure a caring approach with the utmost confidentiality, integrity, and respect.
Qualifications:
- 3 5 years of experience
- Experience with Proofpoint, Varonis and Nessus is highly desired
- Associates degree or related experience. Bachelor’s degree is preferred
- Preferred certifications in – CompTia Network , CompTia Security , CompTia Cybersecurity Analyst, Certified Ethical Hacker (CEH), Certified in Risk and Information Systems Control (CRISC), Certified information Systems Auditor (CISA)