Description

Assess current security controls and processes against new CMS, IRS, and SCC security standards.

Identify gaps and recommend remediation steps to achieve and maintain compliance.

Plan, lead, and execute development and updates to policies, procedures, and documentation to reflect requirements.

Design, implement, and train on the process for assessing partners and vendors, ensuring alignment with security standards.

Develop assessment tools, workflows, and scoring model to evaluate and measure the effectiveness and compliance of vendor and partner security controls.

Evaluate the security posture of vendors and partners to ensure information security contractual, information sharing, and data sharing agreement requirements are met.

Test the effectiveness of operational and management controls using interviews, document reviews, and observation.

Analyze, assess, report, and present on audit findings, risk exposure, and recommendations.

Support information security continuous monitoring and incident response programs.

Perform related work as required.

 

Required/Desired Skills

 

SkillRequired /DesiredAmountof Experience
Audit and compliance/information security/information technology experience or combination thereofRequired8Years
Information Security control audit and assessment experienceRequired4Years
NIST 800-53 or other security frameworkRequired4Years
Perform testing, analysis, reporting, and develop remediation plans for compliance with operational and management controlsRequired4Years
Develop and update policies, procedures, and documentationRequired2Years
Healthcare, health insurance, or ACADesired2Years
Industry recognized certification – CISA, CIA, GSNA, CISSP, or equivalent   

Assess current security controls and processes against new CMS, IRS, and SCC security standards.

Identify gaps and recommend remediation steps to achieve and maintain compliance.

Plan, lead, and execute development and updates to policies, procedures, and documentation to reflect requirements.

Design, implement, and train on the process for assessing partners and vendors, ensuring alignment with security standards.

Develop assessment tools, workflows, and scoring model to evaluate and measure the effectiveness and compliance of vendor and partner security controls.

Evaluate the security posture of vendors and partners to ensure information security contractual, information sharing, and data sharing agreement requirements are met.

Test the effectiveness of operational and management controls using interviews, document reviews, and observation.

Analyze, assess, report, and present on audit findings, risk exposure, and recommendations.

Support information security continuous monitoring and incident response programs.

Perform related work as required.

 

Required/Desired Skills

 

SkillRequired /DesiredAmountof Experience
Audit and compliance/information security/information technology experience or combination thereofRequired8Years
Information Security control audit and assessment experienceRequired4Years
NIST 800-53 or other security frameworkRequired4Years
Perform testing, analysis, reporting, and develop remediation plans for compliance with operational and management controlsRequired4Years
Develop and update policies, procedures, and documentationRequired2Years
Healthcare, health insurance, or ACADesired2Years
Industry recognized certification – CISA, CIA, GSNA, CISSP, or equivalent   

Education

Any Gradute