EPITEC→
IT Securtity Risk Specialist at EPITEC in Southfield, MI
Skills
Job Description
Company Description
.
Job Description
This position will be responsible for completing Vendor Assessments for the Vendor Risk Management team. This role will primarily focus on the following specific areas of responsibility: -Day-to-day management of Information Security risk identification, mitigation and acceptance processes in coordination with security operations and maintaining program requirements language -Execution of training, education and awareness of all users, managers and board members regarding Information Security vendor requirements and expectations -Operational risk planning, mitigation and remediation to address Information Security deficiencies -Identifying new vendor engagements and renewal of existing vendor assessments. Coordinating distribution and completion of vendor assessment questionnaire -Reviewing on-site assessment reports, examining risks and controls associated with all aspects of the vendor -Drafting preliminary findings reports -Conducting preliminary results meeting with BCBSM and its subsidiaries stakeholders and management staff -Receiving and review vendor response-action plan, if necessary -Communicates the results of assessment and-or projects in a clear and concise manner to all levels of management -Designs and operate key operational and executive metrics, reports and dashboards
Qualifications
5+ years of Vendor Risk Management in the Healthcare space
- Strong knowledge of HIPAA and other applicable Healthcare laws
- Strong understanding of the development and operation of a Risk Management program
Additional Information
Extensive experience building and managing a diverse and inclusive team environment with strong commitment to respect, equality and teaming.
- Strong understanding of IT Audit/Information Security control review and remediation plans
- Strong understanding of Information Security and the relationship between threat, vulnerability and information
- Good understanding of risk-based decision-making (i.e. risk analysis, mitigation, resolution, acceptance, etc.)
- Possess a good understanding of appropriate leading-edge governance-enabling technologies.
- Possess a good understanding of regulatory and best practice frameworks in the information security context (HITRUST, HIPAA, HITECH, ISO, etc)
- Strong written and verbal communication skills