Primary Purpose:Identify & manage company IT & IS-related needs, act as a liaison, and provide oversight of 3rd-party IT Support vendors. Responsible for the ongoing management and development of information security policies, procedures, and technical systems. Perform supervisory duties such as coaching, training, motivation, disciplinary actions, and performance reviews of assigned departmental staff in order to ensure accurate and timely completion of all departmental assigned duties.
Principal Duties and Responsibilities (* = essential functions):- Provide leadership and oversight for Information Technology, Services, Systems, and staff. *
- Conduct audits of policies, processes, and staff, implementing plans of improvement. *
- Responsible for implementing, managing, and enforcing information security directives as mandated by HIPAA, government regulation, or contract. *
- Ensure IT Service management, incident response, and change management processes are consistently implemented and monitored both internally and by the IT Support vendor. *
- Ensure that the organization's access control, disaster recovery, business continuity, security incident response, and risk management needs are properly addressed and implemented. *
- Perform and respond to ongoing information risk assessments and audits in conjunction with the Compliance Officer to ensure that information systems are adequately protected and meet HIPAA and other regulatory certification requirements. *
- Work with vendors, outside consultants, and other third parties to improve information security within the organization. *
- Identify, implement, and support technology to support business operations. *
- Plans, directs, and implements procedures that will ensure accurate and efficient configuration and use of systems to support the company. *
- Monitors and trains staff to ensure compliance with Company policies and procedures.
- Takes initiative and is innovative in solving or recommending ways to solve issues.
- Researches and monitors ongoing industry developments and identifies potential new technologies.
- Maintains confidentiality in all endeavors.
- Will assist with other projects and duties as assigned.
Job Specifications (KSAs):- Bachelor's Degree from an accredited college or university in the field of Business Administration, Management Information Systems, Computer Sciences, or a related field is required.
- Five or more years of practical work experience in a Healthcare environment.
- Experienced in the management of both physical and logical information security systems.
- Strong technical skills (application and operating system hardening, vulnerability assessments, security audits, TCP/IP, intrusion detection systems, firewalls, etc.)
- Demonstrated experience with cybersecurity, regulatory compliance, HIPAA, HITRUST, and project management.
- Must possess a high degree of integrity and trust along with the ability to work independently
- Excellent documentation skills
- Ability to weigh business risks and enforce appropriate information security measures
- In-depth knowledge of HIPAA Security Rule and other government technology law
- Plans, directs, and implements procedures to ensure accurate and efficient configuration and use of systems to support the company.
- Must have strong management, organization, communication, and decision-making skills