What are the responsibilities and job description for the Information Technology Specialist – (ISSO) position at Tohono O'odham Nation Healthcare?
PLEASE NOTE - This position may require temporarily relocation to other TONHC Facilities : Sells Hospital, Santa Rosa Health Center, San Simon Health Center, and San Xavier Health Center.
Position Summary :
The incumbent carries out vital projects that are central to the mission of securing the infrastructure and RPMS for the Tohono O'odham Nation. The work involves complying with, monitoring compliance with, and facilitating compliance with TON HC Hospital, HHS and I.H.S. security policies and the Tohono O'odham Nation.
This position supports high profile and high cost investments and projects that affect medical care and business practices within the TON HC. This position is under the supervision of the TON HC Hospital Chief Information Officer, Department of Information & Technology who provides general assignments and responsibilities in terms of broadly defined objectives, functions, or missions.
Essential Duties and Responsibilities :
- Planning, coordinating, training, supporting, upgrading, maintaining and implementing information security for the infrastructure and RPMS.
- Responsible for coordinating information security requirements with TON HC Hospital, facilities, and I.H.S. ISSOs to ensure RPMS and infrastructure is adequately secured and meets all federal information security legislation, directives, policies, and procedures as well as security industry best practices.
- Provides technical and policy related support and coordination to the TON HC Hospital IT security program that affects TON HC Hospital health care organizations.
- Provides security policy and procedures implementation and maintains required infrastructure and RPMS documentation such as a system security plan, continuity of operations (COOP), emergency management plan (EMP) and Plan of Action and Milestones (POA&M).
- Participates in conducting security evaluations, testing, reviews, audits of processes such as risks and self-assessments, vulnerability scans and penetration tests, COOP / EMP testing and other security oriented processes.
- Plays an integral role in the certification and accreditation (C&A) process for RPMS including conducting reviews such as Security Control Testing and Evaluation (ST&Es), tracking progress, defining POA&Ms, preparing reports and guidance for various levels within the agency utilizing applicable regulation, law, policy, procedure, directives and guidance.
- Performs security duties related to the Federal Information Security Management Act (FISMA) and any federal directives or guidance as it becomes relevant. Conducts reviews of security logs, performs log analysis, and provides suggestions for improvement and mitigation of findings.
- Reviews, develops, tests, and recommends standard security configurations for the infrastructure and RPMS.
- Assists with internal and external system audits, incident response, and COOP and disaster recovery efforts as required.
- Coordinates with the Network Operations and Security Center (NOSC) personnel to ensure the infrastructure and RPMS is adequately secure.
- Coordinates with standards, configuration, and change management committees to ensure infrastructure and RPMS information security issues are properly addressed.
- Ensures consistency of implementation of security controls throughout the agency as well as determining if security controls are operating as intended creating a balance between business needs and security requirements.
- Reviews security software currently on the market which can be integrated with the infrastructure and RPMS, as appropriate.
- Assures software security is maintained, including the use and selection of software protection devices, which prevent unauthorized access to system programs or data.
- Routinely accesses information security advisories (US-CERT for example), and other Security Bulletin Boards, Web sites, etc. Reviews and evaluates all new information and obtains documents required to ensure adequate security for the infrastructure and RPMS.
- Recommends changes to security policies or procedures based upon findings. Keeps current of state-of-the-art information security equipment / software and applicable legislation, directives, policies, and procedures.
- Contributes to Enterprise Architecture Management, Software and System Acquisition Management and Investment Control management.
- Ensures the security of infrastructure and RPMS while balancing the needs of system end-users in multiple lines of business throughout the TON HC Hospital Health care systems.
- Responds to infrastructure and RPMS security related priorities set by the I.H.S. Office of Information & Technology, I.H.S. Information Systems Advisory Committee and TON HC Hospital CIO.
- Collaborates with staff of the Office of Information & Technology to ensure that infrastructure and RPMS adapts and conforms to evolving industry standards, legislative and regulatory mandates for system security and privacy. Identifies areas of noncompliance and recommends remediation plans as needed.
- Contributes to a team effort.
- Performs other job related duties as assigned.
Knowledge, Skills, and Abilities :
Minimum Qualifications :
Licenses, Certifications, Special Requirements :
Salary : $85,979 - $107,376