Senior Information Security Analyst
Chippenham Hospital - mechanicsville, VA
Apply NowJob Description
Description Introduction Do you want to join an organization that invests in you as a(an) Senior Zone FISO? At , you come first. HCA Healthcare has committed up to $300 million in programs to support our incredible team members over the course of three years. Benefits HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include: Comprehensive medical coverage that covers many common services at no cost or for a low copay. Plans include prescription drug and behavioral health coverage as well as free telemedicine services and free AirMed medical transportation. Additional options for dental and vision benefits, life and disability coverage, flexible spending accounts, supplemental health protection plans (accident, critical illness, hospital indemnity), auto and home insurance, identity theft protection, legal counseling, long-term care coverage, moving assistance, pet insurance and more. Free counseling services and resources for emotional, physical and financial wellbeing 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service) Employee Stock Purchase Plan with 10% off HCA Healthcare stock Family support through fertility and family building benefits with Progyny and adoption assistance. Referral services for child, elder and pet care, home and auto repair, event planning and more Consumer discounts through Abenity and Consumer Discounts Retirement readiness, rollover assistance services and preferred banking partnerships Education assistance (tuition, student loan, certification support, dependent scholarships) Colleague recognition program Time Away From Work Program (paid time off, paid family leave, long- and short-term disability coverage and leaves of absence) Employee Health Assistance Fund that offers free employee-only coverage to full-time and part-time colleagues based on income. Learn more about Employee Benefits Note: Eligibility for benefits may vary by location. You contribute to our success. Every role has an impact on our patients lives and you have the opportunity to make a difference. We are looking for a dedicated Senior Zone FISO like you to be a part of our team. Job Summary and Qualifications The Senior Zone FISO is responsible for leading, driving, and, in some cases, implementing Information Protection & Security (IPS) activities. He or she serves as a liaison between local leadership and IPS leadership. Senior Zone FISO operate under minimal supervision from the Division Director of Information Security Assurance (DISA) and may mentor less-experienced Facility Security Program Managers. Under minimal supervision from the DISA, Facility Security Program Managers are responsible for leading the ongoing maturation of the IPS Program, including: driving consistency and visibility of IPS risk management activities; working with business owners to protect patients and prevent data loss; and rounding with leadership to reduce or eliminate risky behaviors. This role is responsible for helping workforce members appropriately comply with the companys IPS requirements. Senior Zone FISOs act as a SME for other ZFISOs across the IPS Field Operations program, providing guidance and best practices to less-experienced team members. This role requires extensive focus on building and expanding relationships with key stakeholders such as local leadership; workforce members; physicians; IT teams; business owners; vendors; and other people and entities who support IPS objectives and activities. Major Responsibilities: Risk Management Coordinate and perform risk assessments using corporate-provided tools and templates. Drive and manage execution of corrective action plans to address deficiencies identified during risk assessments. Ensure the designated committee (e.g., Security Committee, Ethics & Compliance Committee) receives, documents, tracks, investigates, and sponsors remediation of security control deficiencies, suspected IPS incidents, and complaints. Provide education and guidance to ensure these committees make informed, risk-based decisions necessary to balance business needs and security objectives. Represent IPS needs in strategic planning, budgeting, and work prioritization processes. Drive ongoing compliance with IPS policies, standards, and operational procedures. Work with leaders to submit and approve exceptions to IPS standards. Lead audit response activities to address IPS issues identified by Internal Audit or external auditors (e.g., CMS HIPAA Security audits). Issues Tracking and Resolution Support, coordinate, and manage incident response and investigation activities. Investigate information leaving the organization with appropriate leadership (i.e. Manager, ECO, HR, Legal) Coordinate with HR Director, Facility Privacy Official and Ethics & Compliance Officer to ensure that sanctions related to IPS issues are applied appropriately and consistently. Perform follow-up education and consultation with workforce members with risky behaviors and/or behaviors that violate Company policies and standards. Execution Round to build and strengthen relationships with workforce members at all levels and educate staff on how to reduce or eliminate risky behaviors. Facilitate, and lead where appropriate, proactive IPS communication and awareness activities including coordinating with HR and training departments to ensure that periodic workforce training includes company-required IPS content. Assist with and manage the review and approval of user requests for high-risk access. Assist the Division IPS Director in driving key elements in the enterprise and division IS programs to ensure that required processes are adopted and maintained. Lead and coordinate implementation and adoption of technology and processes changes. Vendor Systems Security Collaborates with system business owners to ensure vendor contracts are in place for department IT systems and services. Work with appropriate business leadership and supply chain to help ensure specific systems, services, and devices receive proper assessments and remediation before implementation. Work with appropriate business, IT, supply chain, and corporate IPS stakeholders to help ensure specific systems, services, and devices receive proper security assessments and remediation. Work with system business owners and vendors to document system vulnerabilities and document mitigation controls or remediation actions. Ensure vendor systems use approved connectivity, remote management and monitoring. Knowledge, Skills, Abilities, Behaviors: Significant experience in developing and assessing technical and process-based controls, managing risk assessments/investigations, and working with organization management to integrate controls into the scope of existing business practices. Required Experience in management and/or operations in a number of healthcare business or IT functional areas. Required Experience in some combination of audit, risk management, information security, privacy, and information technology. Required Experience with information security regulations (HIPAA Privacy/Security, Sarbanes-Oxley IT controls, Payment Card Industry (PCI)) and applying these to identify appropriate controls necessary to maintain compliance Required Demonstrated experience in building and maintaining positive team relationships at all levels of the facility, market, and corporate levels. Required Possesses confident leadership skills: decisiveness, assertiveness, with the ability to achieve results quickly. Required Demonstrates a high degree of initiative, dependability, and the ability to work with minimal supervision. Required Possesses a sense of responsibility and accountability someone who takes ownership and initiative. Required Creative thinker, always looking for a better way to deliver value; not stopped or discouraged by adversity. Required Demonstrates respect for diversity of experience, characteristics, viewpoints, and opinions. Required Maintains professional demeanor, appearance, and positive attitude. Required Education & Experience: Bachelor's degree and 5+ years of experience in a relevant field Required or High School Graduate/Equivalent and 10+ years of experience in a relevant field Required Master's degree Preferred Licenses, Certifications, & Training: CISSP, CISA, HCISPP, CHC, CHPC, CHSP, CISM or other relevant certifications in information security or privacy Travel: The job may require up to 15% travel. HCA Healthcare (Corporate) , based in Nashville, Tennessee, supports a variety of corporate roles from business operations to administrative positions. Like our colleagues in any HCA Healthcare hospital, our corporate campus employees enjoy unparalleled resources and opportunities to reach their potential as healthcare leaders and innovators. From market rate compensation to continuing education and career advancement opportunities , every person has a solid foundation for success. Nashville is also home to our Executive Development Program , where exceptional employees are groomed to take on CNO- and COO-level roles in our hospitals. This selective program focuses on ethics, leadership and the financial and clinical knowledge required of professionals at this level of the industry. HCA Healthcare has been recognized as one of the World's Most Ethical Companies by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses. "Good people beget good people."- Dr. Thomas Frist, Sr. HCA Healthcare Co-Founder We are a family 270,000 dedicated professionals! Our Talent Acquisition team is reviewing applications for our Senior Zone FISO opening. Qualified candidates will be contacted for interviews. Submit your resume today to join our community of caring! We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Created: 2024-10-31