Assist in conducting cybersecurity compliance reviews and tracking compliance gaps to remediation.
Assist in development/reviewof cybersecurity policies and procedures.
Consult with workforce members on regulatory and policy requirements.
Assist in conducting cybersecurity control compliance reviews for international travelers.
Act as cybersecurity compliance representative on cross-functional work teams.
Assist with project/organizational risk assessments.
Develop, implement and monitor security compliance work plans for the organization.
Develop/improve processes for evaluating/documenting security compliance.
Assist in responding to third party audits (payers, research partners, vendors, etc.).
Assist in responding to internal audits (assist in managing and completing Management Action Plans (MAPs)).
Assist in developing cybersecurity training initiatives.
Prepare regular reports for executive review.
Maintain an in-depth knowledge of privacy/security-related regulatory frameworks such as HIPAA, GDPRand provide timely information regarding important regulatory changes to operational leaders.
PREFERRED QUALIFICATIONS:
Bachelors degree in related field or equivalent experience.
Experience writing/editing policies and procedures.
Experience managing compliance documentation, including but not limited to committee charters, confidentiality agreements and annual attestations.
Excellent organizational, analytical, and time management skills.
Effective interpersonal, writing, and communications skills required.
Experience with US and international privacy / security-related regulatory frameworks (HIPAA/HITECH, GDPR, etc).
Ability to work independently with minimal supervision.
Experienced with business process development / improvement.
Ability to manage multiple competing priorities within the context of a complex, multi-faceted organization.
At least 3 years experience in cybersecurity.
Information Security Related Professional Qualification (e.g., CISSP, CISA, Security+, CEH, GSEC, etc.)
TECHNICAL CAPABILITIES:
PROGRAM MANAGEMENT (INTERMEDIATE):Planning, organizing, and managing resources to bring about the successful completion of specific program goals and objectives.
RISK AND COMPLIANCE ASSESSMENTS (INTERMEDIATE): Ensuring compliance with established foreign and domestic laws and regulations and VUMC institutional policies and procedures and recommending any necessary changes. This activity will include the independent review and examination of IT systems, architectures, data flows, etc., and the documentation and reporting of such assessments in support of VUMC programs.
PEER LEADERSHIP (INTERMEDIATE):The ability to show leadership and influence people of equal rank in an effort to accomplish team goals.
QUALITY MANAGEMENT (INTERMEDIATE):Developing a systematic process of checking to see whether a process or service is meeting specific requirements.
NETWORKING (INTERMEDIATE):Build relationships through industry contacts, professional organizations and individuals.
PROCESS IMPROVEMENT (INTERMEDIATE):Identifies, analyzes and improves upon existing business processes for optimization and to meet standards of quality.
About the Department:
Vanderbilt Health - VUMC Enterprise Cybersecurity (VEC)
VEC provides information security service solutions for securing all administrative, clinical and research operations for all of Vanderbilt Health, the largest non-government employer in Middle Tennessee.
Vanderbilt Health is always growing, with our current environment of 7 hospitals, nearly 40K staff, over 40K workstations, over 160K network connections, and numerous data centers and cloud environments, securing our health system is truly a challenge!
To meet the challenge, VEC is led by 2 Vice Presidents and is structured with many dedicated teams, including: Active Vulnerability Assessment, Business Information Security Office, Business Resilience Services, Identity and Directory Services, Policy and Compliance, Security and Architecture Assurance, Security Engineer Services, Security Operations Center, and Threat Detection and Response.
VEC also employs state-of-the-art technology and partners with the many IT and operational teams across the enterprise to ensure a partnered, cohesive, and comprehensive approach to information security.
At our growing health system, we support each other and encourage excellence among all who are part of our workforce. High-achieving employees stay at Vanderbilt Health for professional growth, appreciation of benefits, and a sense of community and purpose.