What are the responsibilities and job description for the Sr. IT Auditor Consultant, Hospital Medical Device IT Controls (BHJOB22048_756) position at ITmPowered?
Sr. IT Auditor Consultant, Hospital Medical Device IT Controls
Read all the information about this opportunity carefully, then use the application button below to send your CV and application.
Be on the frontlines of Technology Risk in the emerging area of Medical Device Cybersecurity! A large national hospital network can have over 350,000 connected medical devices. Many of these interconnected devices (hospital imaging equipment, patient monitoring, IV pumps, blood spinners) and connected hospital facilities devices (elevators, door locks, ID Card readers) are exposed publicly and vulnerable to cyber-attack. To help protect this large IoMT network, our client is implementing a customized set of IT Controls to secure their Medical Devices, Healthcare Technology Management Operations, and Hospital Facilities connect IT devices.
About the Role :
The Sr. IT Auditor Consultant will serve on behalf of the Technology Risk Management organization performing IT Controls Assessments for a set of 20 custom IT controls in this Hospital Medical Device Cybersecurity Program. Plan and perform full lifecycle audits (scope, plan, fieldwork, reporting) assessing Audit IT Controls Design prior to implementation and IT Controls Execution once implemented. Helping the Med Device Cybersecurity team where they have controls gaps and findings and understand how effective IT controls should be implemented.
WHAT YOU’LL ACCOMPLISH
- As a part of the Technology Risk Office, this role will be conducting IT Controls Assessments (IT Audits) of roughly 20 customized Medical Device cybersecurity IT Controls being implemented enterprise-wide.
- Conduct full IT Controls Risk Assessments on each of 20 custom Med Device cybersecurity IT Controls twice :
- First by testing Controls Design (does it make sense) prior to implementation and
- Second testing Controls Execution (is control actually working) once the controls are implemented.
- Spearhead IT Controls Assessments end to end (scoping, planning, fieldwork / controls testing, and reporting).
- Scope and Plan IT Controls Assessment engagements. Lead Kickoff meetings, set expectations and schedule.
- Clearly document IT Controls processes narratives (step 1, 2, 3…) of planned or current IT Control processes.
- Fieldwork – Conduct detailed IT Controls Testing, gather, and document detailed IT Controls test results supported by clear evidentiary artifacts.
- Reporting – Write full IT Controls Assessment (IT Audit) Reports – Assessment Scope, Audit details, controls inspection / testing results, IT Controls Assessment Findings with clearly communicated Risk severity, likelihood, impact, and Controls deficiency Risk Remediation Recommendations and Corrective Action Plans.
- Plan & conduct complex IT Audit Controls Assessments for Hospital Medical Device cybersecurity through full device lifecycle (device procurement, intake, implementation, operations, maintenance, decommissioning).
- Assess IT Risk Controls for Hospital Med Device Cybersecurity Controls across IAM, logical access, password vaulting, network security, logging and monitoring, vulnerability management, change management, etc.
WHAT WE’RE LOOKING FOR
Preferred Experience :
LOGISTICS :
J-18808-Ljbffr