hirq
← All jobs

Epitec Inc.

IT Securtity Risk Specialist

Southfield, MI, us · On-site · Full-time

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

CybersecurityRisk ManagementHIPAACommunication
.   This position will be responsible for completing Vendor Assessments for the Vendor Risk Management team. This role will primarily focus on the following specific areas of responsibility: -Day-to-day management of Information Security risk identification, mitigation and acceptance processes in coordination with security operations and maintaining program requirements language -Execution of training, education and awareness of all users, managers and board members regarding Information Security vendor requirements and expectations -Operational risk planning, mitigation and remediation to address Information Security deficiencies -Identifying new vendor engagements and renewal of existing vendor assessments. Coordinating distribution and completion of vendor assessment questionnaire -Reviewing on-site assessment reports, examining risks and controls associated with all aspects of the vendor -Drafting preliminary findings reports -Conducting preliminary results meeting with BCBSM and its subsidiaries stakeholders and management staff -Receiving and review vendor response-action plan, if necessary -Communicates the results of assessment and-or projects in a clear and concise manner to all levels of management -Designs and operate key operational and executive metrics, reports and dashboards  5+ years of Vendor Risk Management in the Healthcare space - Strong knowledge of HIPAA and other applicable Healthcare laws - Strong understanding of the development and operation of a Risk Management program Extensive experience building and managing a diverse and inclusive team environment with strong commitment to respect, equality and teaming. - Strong understanding of IT Audit/Information Security control review and remediation plans - Strong understanding of Information Security and the relationship between threat, vulnerability and information - Good understanding of risk-based decision-making (i.e. risk analysis, mitigation, resolution, acceptance, etc.) - Possess a good understanding of appropriate leading-edge governance-enabling technologies. - Possess a good understanding of regulatory and best practice frameworks in the information security context (HITRUST, HIPAA, HITECH, ISO, etc) - Strong written and verbal communication skills