What are the responsibilities and job description for the Security Specialist- Mid Level (HYBRID) position at Serigor Inc?
Job Title: Security Specialist- Mid Level (HYBRID)
Location: Raleigh, NC
Duration: 12 Months
Job Description:
The Candidate will be allowed to work remotely but will need to be onsite at short notice. There is a mandatory three-week training onsite at the beginning of the engagement. Once all staff return to site the candidate will need to work onsite full time.
The Client HIEA Compliance Officer will ensure that operations follow all relevant state and federal requirements for securely transacting health information via the HIE Network, The client HealthConnex. The Compliance Officer will be familiar with risk management, comfortable leading internal risk assessments, and possess knowledge of HIPAA and NIST privacy and security requirements for health information networks. This position will work closely with the NC HIEA leadership team, the client legal counsel, and client Privacy Team, and the client Security and Risk Management Team to ensure continual improvement of the client HIEA’s security and risk profile.
Responsibilities:
Skill
Required / Desired
Amount
of Experience
Knowledge of privacy laws (state and federal such as HIPAA (preferred), PCI, CJIS); proven risk management experience.
Required
3
Years
Experience in creation of risk management strategies and policy development to handle data breaches and other incidents.
Required
3
Years
Knowledge of NIST controls and experience with completing/conducting assessments; written and verbal communication.
Required
3
Years
Strong conflict management skills in order to work with senior management to ensure security and data protection rules and regulations are in place.
Required
3
Years
Knowledge of cybersecurity and privacy principles
Required
3
Years
Ability to determine whether a security incident violates a privacy principle or legal standard requiring specific legal action.
Required
3
Years
Ability to work across departments and business units to implement organization’s privacy principles and programs.
Required
3
Years
Ability to develop, update, and/or maintain standard operating procedures (SOPs).
Required
3
Years
Ability to develop clear directions and instructional materials.
Required
3
Years
Location: Raleigh, NC
Duration: 12 Months
Job Description:
The Candidate will be allowed to work remotely but will need to be onsite at short notice. There is a mandatory three-week training onsite at the beginning of the engagement. Once all staff return to site the candidate will need to work onsite full time.
The Client HIEA Compliance Officer will ensure that operations follow all relevant state and federal requirements for securely transacting health information via the HIE Network, The client HealthConnex. The Compliance Officer will be familiar with risk management, comfortable leading internal risk assessments, and possess knowledge of HIPAA and NIST privacy and security requirements for health information networks. This position will work closely with the NC HIEA leadership team, the client legal counsel, and client Privacy Team, and the client Security and Risk Management Team to ensure continual improvement of the client HIEA’s security and risk profile.
Responsibilities:
- Assist with the development and implementation of a compliance program for the client HIEA that includes preparation for HITRUST certification
- Create sound internal controls and monitor adherence to them
- Draft and revise policies
- Proactively audit processes, practices and documents to identify weaknesses
- Evaluate activities to assess compliance risk
- Collaborate with external auditors and the client Security Team when needed
- Set plans to manage a crisis or compliance violation
- Educate and train employees on regulations and industry practices
- Address employee concerns or questions on compliance
- Keep abreast of industry standards and business goals
- Proven experience as a Compliance Officer
- Experience in risk management
- Knowledge of HIPAA and NIST requirements
- Familiarity with industry practices and professional standards
- Excellent communication skills
- Integrity And professional ethics
- Attention To detail
Skill
Required / Desired
Amount
of Experience
Knowledge of privacy laws (state and federal such as HIPAA (preferred), PCI, CJIS); proven risk management experience.
Required
3
Years
Experience in creation of risk management strategies and policy development to handle data breaches and other incidents.
Required
3
Years
Knowledge of NIST controls and experience with completing/conducting assessments; written and verbal communication.
Required
3
Years
Strong conflict management skills in order to work with senior management to ensure security and data protection rules and regulations are in place.
Required
3
Years
Knowledge of cybersecurity and privacy principles
Required
3
Years
Ability to determine whether a security incident violates a privacy principle or legal standard requiring specific legal action.
Required
3
Years
Ability to work across departments and business units to implement organization’s privacy principles and programs.
Required
3
Years
Ability to develop, update, and/or maintain standard operating procedures (SOPs).
Required
3
Years
Ability to develop clear directions and instructional materials.
Required
3
Years