Skip to main content

This job has expired

Senior IT Control and Risk Analyst

Employer
Adventist HealthCare
Location
Gaithersburg, MD
Closing date
Apr 3, 2019

View more

Industry
Healthcare
Function
Analyst, IT
Hours
Full Time
Career Level
Experienced (Non-Manager)

Job Details

Support Center

If you are a current Adventist HealthCare employee, please click this link to apply through your Workday account. The Senior IT Control and Risk Analyst is responsible for identifying and monitoring information security risks throughout Adventist HealthCare. This will be accomplished through development and completion of audits, projects and monitoring activities to test the effectiveness and efficiency of IT controls and related processes and validate compliance with applicable policies and regulatory requirements.
Work Schedule:


Job Responsibilities


1. Develop and implement an IT Security monitoring program including such activities as”


  • Performing HIPAA and general IS Security Risk Assessments
  • Executing an IT Audit program including detailed tests of controls
  • Establishing a Capacity Maturity Model to assess critical business processes
  • Developing and implementing a balanced score card to monitor and evaluate the effectiveness of the IT Security program
  • Facilitate Control Self Assessments system-wide

2. Validate implementation of information security risk mitigation plans. Provide status updates to Information Services and Organizational Integrity leadership as appropriate.


3. Collaboratively with the Chief Information Security Officer, manage all information security related policies by:


  • Inventorying all information security related policies, periodically reviewing and updating all information security related polices as required
  • Identifying emerging information security related risks and developing policies to help mitigate those risks

4. Act as an IT Security subject matter specialist for IT related projects and committees


5. In collaboration with the Information Services Security team, develop and implement the information security awareness program including development of


annual and periodic training materials, performing phishing simulations and other activities to raise awareness of IT security risks.


6. Maintain a working knowledge of:


  • Applicable federal, state and local laws and regulations including Meaningful Use, HIPAA, NIST, ISO27001, and Payment Card Industry compliance
  • Adventist HealthCare policies and procedures related to the Adventist HealthCare Organizational Integrity Program, Code of Ethics, and other Adventist HealthCare policies and procedures

7. Validate that access control, disaster recovery, business continuity, incident response and risk management needs of Adventist HealthCare are properly addressed



Required Qualifications


1. Ability to work effectively and efficiently, and manage competing priorities with minimal direct supervision


2. Possess and demonstrate an in-depth knowledge of healthcare applications, technology, EHR and experience in health information systems


3. Experience auditing HIPAA, Meaningful Use and PCI related processes and controls


4. Demonstrated Ability to advise others and provide meaningful input on IT related Internal projects


5. Understands IT and general business processes, and applies risk and control concepts as appropriate


6. Demonstrates strong active listening skills


7. Technical expertise in Internal Audit methodology


8. Builds collaborative relationships with entity and department leadership to facilitate improvement to the IT Security environment


9. Communicates effectively, both orally and in writing with all levels of executive management and staff


10. Proactively communicates issues or concerns to the Senior Manager, Audit & Advisory Services and to audit clients


11. Adapts well to new circumstances, information and challenges


12. Ability to flourish in a fast-paced, complex environment


13. Ability and willingness to work in a collaborative, team environment



Education


  • Bachelor's degree in Business, Computer Science, Information Systems/Sciences, Computer Security, Engineering or a related field
  • Master's degree in a business or information security related field preferred.

Experience


  • At least 3 years of IT audit or IT security experience
  • Two years of experience leading projects and working independently, preferably in the healthcare setting

Certifications


  • CISA, CRISC, CISSP, HCISSP or equivalent certification preferred.



Tobacco Statement


Tobacco use is a well-recognized preventable cause of death in the United States and an important public health issue. In order to promote and maintain a healthy work environment, Adventist HealthCare will not hire applicants for employment who either state that they are nicotine users or who test positive for nicotine use.


Adventist HealthCare will withdraw offers of employment to applicants who test positive for Cotinine (nicotine). Those testing positive for cotinine are given the opportunity to re-apply in 90 days, if they can truthfully attest that they have not used any nicotine products in the past ninety (90) days and successfully pass follow-up testing.



Equal Employment Opportunity


Adventist HealthCare is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.


Company

We are a faith-based healthcare organization, based in Montgomery County, Maryland. We are the largest employer in Montgomery County with over 6,000 employees! Our comprehensive approach to caring for our community includes three acute-care hospitals – Shady Grove Medical Center, White Oak Medical Center and Fort Washington Medical Center – as well as two Physical Rehabilitation hospitals, Outpatient centers, Imaging Centers, Urgent Cares, Home Care Services, Employer Health Programs and Physician Networks. We are nationally recognized and honored especially for our Cardiac, OB, Cancer, Stroke, Orthopedic, Rehabilitation and Mental Health services. Our mission is to extend God's care through the ministry of physical, mental and spiritual healing. At its core, our mission expresses who we are, why we exist and the purpose behind what we do. These words are reflective of God’s character as outlined in the Bible and honor the Seventh-day Adventist Church’s long-standing commitment to healing. You will also find that many of the beliefs and standards of conduct at AHC are universal beliefs that are recognized across many faith traditions.

Company info
Website
Location
820 West Diamond Avenue
Suite 600
Gaithersburg
MD
20878
US

Get job alerts

Create a job alert and receive personalized job recommendations straight to your inbox.

Create alert