IT Security Risk Management Analyst (Remote)
Are you interested in joining a team of experienced healthcare experts and have the ability to shape and transform the healthcare delivery system? At our family of companies, everything we do is to help improve the lives of the nearly 12 million Medicare beneficiaries we serve and 700,000 health care providers who care for them. It is our goal to help create a better health experience for all consumers. Join our winning culture and help transform Medicare for the millions of people who rely on its services.Benefits info:Medical, dental, vision, life and supplemental insurance plans effective the first day of the month following date of hireShort- and long-term disability benefits 401(k) plan with company match and immediate vestingFree telehealth benefitsFree gym membershipsEmployee Incentive PlanEmployee Assistance ProgramRewards and Recognition ProgramsPaid Time Off and Paid Sick Leave What’s My Impact?The IT Security Risk Management Analyst is responsible for integrating industry, government, and business compliance requirements (Defense Information Systems Agency (DISA), National Institute of Standards and Technology (NIST), Health Information Portability and Accountability Act (HIPAA), Federal Information Security Modernization Act (FISMA), Centers for Medicare and Medicaid (CMS), Cybersecurity Framework (CSF), Health and Human Services (HHS) into operational processes and procedures. This role monitors the remediation of non-compliant areas across all the company's lines of business and IT departments including HR, Risk Management, Internal Audit, Legal, Operations, IT, Security and Privacy teams and provides status updates to management, as applicable.What are the Essential Duties & Responsibilities?To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. This list of essential job functions is not exhaustive and may be supplemented as necessary.Primary Duties (90%)Communicate and track remediation plans with vendors, business, and IT partners.Work to ensure that security controls are managed and maintained by business and IT partners in line withInformation Security company policies, standards, federal and state security, and data privacy laws.Develop and maintain information security procedures.Proactively promote security controls and awareness training across IT and business areas.Track Plan of Action and Milestone (POAM) remediation plans with business and IT partners.Participate on IT projects to ensure that security issues are addressed throughout the project life cycle, as needed. Report compliance state for required Statement of Work security deliverables. Maintain Information Security Risk Management and Compliance data repositories.Participate in DISA STIG configuration management compliance reviews.Participate in small IT projects (i.e., less than 100-man hours of work effort), as needed, impacting applications and systems used. to support the company’s mission.Relationships and Collaboration (10%)Manages internal and customer relationships.Works effectively and respectfully with team members.Shares information and performs necessary follow-up to ensure stakeholders are well informed.Performs other duties as the supervisor may, from time to time, deem necessary.What’s Required?High School Diploma or GED4 years’ related work experience IT, Information Security, Cyber Risk Management, ComplianceDemonstrated understanding and knowledge of current control and risk management concepts and industry trends in information risk management, including privacy lawsWorking knowledge of information security risk management and controls frameworks (i.e., NIST; International Organization for Standardization (ISO) 2700; Federal Risk and Authorization Management Program (FedRAMP), Sarbanes Oxley (SOX), CSF, DISA, Center for Internet Security (CIS) Benchmarks)Knowledge of Operating Systems risk issues, specifically around security and privacyKnowledgeable of compliance requirements such as HIPAA, NIST, HHS, National Archives and Records Administration (NARA), FedRAMP and DISAExperience using GRC tools and technologies in support of the assessment/audit process (RSA Archer, Service Now, Logic Manager, Navex, etc.)Demonstrated proficiency in MS Office applications, Microsoft Project, Microsoft VISIO Demonstrated ability to deal effectively with internal and external regulatory agencies/teamsDemonstrated ability to work under stress in emergencies with flexibility to handle high-pressure situationsDemonstrated team-oriented interpersonal skills with the ability to interface with a broad range of IT-business personnelAbility to manage tasks with limited supervision and take ownership of responsibilitiesAbility to learn from mistakes and apply constructive feedback to improve performanceCERTIFICATIONS, LICENSES, REGISTRATIONSPossesses or obtains within 1 year of position placement: CompTIA Security+Possesses or obtains within 2 years of position placement: Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Controls (CRISC)What’s Preferred?Knowledge of CMS security requirements Internal audit experienceGuidewell experienceThe Federal Government and the Centers for Medicare & Medicaid Services (CMS) may require applicants to have lived in the United States for a minimum of three (3) years out of the last five (5) years to be employed with the Company. These years of residence do not have to be consecutive.This opportunity is open to remote work in the following approved states: AL, AK, FL, GA, ID, IN, IO, KS, KY, LA, MS, NE, NC, ND, OH, PA, SC, TN, TX, UT, WV, WI, WY. Specific counties and cities within these states may require further approval. In FL and PA in-office and hybrid work may also be available.We are an Equal Opportunity Employer/Protected Veteran/Disabled