Information Security & Risk Mgmt at Highmark Health is more than just “cyber security”, it’s about ensuring our patients and members are protected and can get the care they need without disruption. We are trusted SMEs with diverse points of view and skills synthesizing security solutions for our enterprise and customers. We are a highly engaged team who values professional development and growth – not just with formalized career development, but with weekly learning opportunities, speaking engagements and leadership involvement in professional organizations. We believe inertia is our prime enemy and relentless incrementalism is our ultimate weapon. That’s why we are innovators, collaborators, solutioners, and tinkerers. Our work is not easy and the challenges only get tougher; if that’s the kind of environment you’re seeking, then we want to talk to you.
This job, as a technical expert in the security domain, sets and monitors role lifecycle management standards, best practices and systems necessary to ensure the protection of the confidentiality of informational assets, which requires strong technical knowledge of information systems, role based access controls (RBAC) and the use of established security control.
Provide Role Based Access Control (RBAC) analysis, design and implementation expertise within the Organization's IAM Infrastructure; collaborating with lean purposed IAM Software Development team to refine and expand the adoption of a semantically logical and comprehensive RBAC framework.
Collaborate with Business Intelligence & Analytics groups; leveraging Tableau data visualization software for role-mining analysis, and dashboarding executive overview reporting.
Collaborate with IT Governance, Risk & Compliance group to expand and improve process certification using industry standard product solutions (Sailpoint, OIG, Dell One).
Document business requirements gathering and documentation for the design and implementation of an RBAC framework.
Provide business analysis support, drafting business requirements documentation for clients, as well as system integrations and operational support for User Access review campaigns.
Other duties as assigned or requested.
3 - 5 years in Information Security and Risk Management with a focus on Role LifeCycle Management
3 - 5 years in Information Technology
3 - 5 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
3 - 5 years in Information Security and Risk Management with a focus on software development companies
Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
In-depth understanding of network security architecture, network and networking protocols
LICENSES AND CERTIFICATIONS
Certified Information Systems Security Professional (CISSP)
Information Technology Infrastructure Library (ITIL)
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, Payment Card Industry (PCI), Health Insurance Portability & Accountability Act (HIPAA), HITECH, COBIT, International Organization for Standardization (ISO) 27001/2, and ITIL
Role Analytics background
Proficient in manipulating and querying databases/SQL
Fluent in scripting, building and running queries
Knowledge of NIST Risk Assessment methodology
Familiarity with secure SDLC best practices
Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
Strong teamwork and inter-personal skills
Adaptable and resilient: able to shift direction while remaining productive. Maintains focus in the face of challenge.
Consultative: skilled listener, prepares recommendations to client problems, adopts a customer first mindset, partner with internal and external project teams to drive results.
Internal Number: J169803
About Highmark Health
Welcome to the Highmark Health organization of leading health care companies and more than 35,000 employees.
We're proud to serve over 50 million Americans in all 50 states and the District of Columbia through our businesses in health insurance, health care delivery, managed vision care, retail eyewear and eye care services, eyewear manufacturing, dental solutions, health risk solutions and innovative technology-based solutions.
We share a deep commitment to improving the health care system, the health of our local communities and the health care experience of those we serve. We invite you to learn more.