Sr IT Security Analyst (Remote)
Are you interested in joining a team of experienced healthcare experts and have the ability to shape and transform the healthcare delivery system? At our family of companies, everything we do is to help improve the lives of the nearly 12 million Medicare beneficiaries we serve and 700,000 health care providers who care for them. It is our goal to help create a better health experience for all consumers. Join our winning culture and help transform Medicare for the millions of people who rely on its services.Benefits info:Medical, dental, vision, life and supplemental insurance plans effective the first day of the month following date of hireShort- and long-term disability benefits 401(k) plan with company match and immediate vestingFree telehealth benefitsFree gym membershipsEmployee Incentive PlanEmployee Assistance ProgramRewards and Recognition ProgramsPaid Time Off and Paid Sick Leave What’s My Impact?The Senior IT Security Analyst performs security assessments and provides consultative guidance on the development of information security strategies and programs. Supports audit assessments and defines processes and standards to ensure that security configurations are maintained, and other applicable security requirements are in place. Leads efforts, oversees work results, provides formal training, and serves as a technical resource for Information Security team members. Handle reported Security Incidents and take action to report to CMS within 1 Hour.What Will I Do?To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. This list of essential job functions is not exhaustive and may be supplemented as necessary.Primary Duties (80%)Validates that technical and operational information security controls are incorporated into new IT systems by participating in all business planning groups and reviewing all new systems/installations and major changes. Participates in initiatives to identify, select and implement technical controls. Works with IT leadership to develop strategies and plans to enforce security requirements and address identified risks. Analyzes, proposes, and implements solutions concerning residual risk, vulnerabilities, and other security exposures. Develops information security processes, policies, and procedures. Advises on service level agreements and works to ensure that security controls are managed and maintained. Develops and maintains documentation for security systems, procedures, and security diagrams. Serves as a liaison and lead on audit-related initiatives managing relationships, collection of data, progression tracking, assessment, and remedial activities.Advises IT Security and other IT teams on normal and exception-based processing of security authorization requests.Researches, evaluates and recommends information security related hardware and software including development of businesses cases for security investments. Proactively identifies company-wide program opportunities and works to implement solutions. Guides the direction of the overall information security program. Serves as a liaison with IT and business area partners to identify, understand, document, and advise on security requirements, impacts and risks. Participates on IT projects to ensure that security issues are addressed throughout the project life cycle.Assists and supports the development of security architecture.Investigate and evaluates detected and reported Privacy incidents for corrective action and resolutions; and work with companies to mitigate risks and exposures. Relationships and Collaboration (20%)Interacts and manages relationships with IT business partners, with CMS, data centers, internal customers, and other business partners to maximize business effectiveness and meet contractual obligations for system processing.Manages internal and customer relationships, ensures staff understands the customer needs and manages to those needs while balancing performance expectations.Provides constructive feedback and proactively addresses conflict.Works effectively and respectfully with all levels of management. Influences, interacts, and communicates collaboratively.Shares information and performs necessary follow-up to ensure stakeholders are well informed. Provides thought leadership.Performs other duties as the supervisor may, from time to time, deem necessary.What’s Required?High School diploma or GED.5 years related work experience or equivalent combination of transferrable work experience or education. Knowledge of information security principles, including risk assessment and management, threat and vulnerability management, incident response and access management. Knowledge of network infrastructure, including routers, switches, firewalls and associated network protocols and concepts.Strong technical knowledge of current systems, software, protocols, and standards.In-depth knowledge of operating systems and security applications.Working knowledge of basic network protocols and tools.Critical thinking skills to evaluate alternative and present solutions that are consistent with business objectives and strategy.Proven leadership abilities including effective knowledge sharing, conflict resolution, facilitation of open discussions, fairness and displaying appropriate levels of assertiveness.Strong customer focus with the ability to manage customer expectation and experience and build long-term relationships.Strong team-oriented interpersonal skills with the ability to interface with a wide range of people and roles including IT vendors and IT business personnel.Ability to work under stress in emergencies with flexibility to handle multiple high-pressure situations simultaneously.Ability to adapt in a rapidly changing environment.Ability to communicate highly technical information clearly and articulately for all levels and audiences.Ability to manage tasks independently and take ownership of responsibilities.Ability to learn from mistakes and apply constructive feedback to improve performance.Possesses or obtains within 1 year of position placement: CompTIA Security+Possesses or obtains within 2 years of position placement: Certified Information Systems Security Professional (CISSP)What’s Preferred? Experience using the following technologies:Endpoint Detection and Response tools such as Carbon Black (highly desired), McAfee, SymantecData Logging and Analytics tools such as SplunkThreat and Vulnerability detection tools such as TenableRelated technology or cyber security specialist certificationsAA or Bachelor’s degree in related fieldThe Federal Government and the Centers for Medicare & Medicaid Services (CMS) may require applicants to have lived in the United States for a minimum of three (3) years out of the last five (5) years to be employed with the Company. These years of residence do not have to be consecutive.This opportunity is open to remote work in the following approved states: AL, AK, FL, GA, ID, IN, IO, KS, KY, LA, MS, NE, NC, ND, OH, PA, SC, TN, TX, UT, WV, WI, WY. Specific counties and cities within these states may require further approval. In FL and PA in-office and hybrid work may also be available.We are an Equal Opportunity Employer/Protected Veteran/Disabled