We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.

Job posting has expired

#alert
Back to search results

Consulting Security Controls Engineer

HCA Healthcare
paid time off, 401(k)
United States, Tennessee, Nashville
1 Park Plaza (Show on map)
July 17, 2023

Description

Introduction

Do you have the career opportunities as a(an) Consulting Security Controls Engineer you want with your current employer? We have an exciting opportunity for you to join HCA Healthcare which is part of the nation's leading provider of healthcare services, HCA Healthcare.

Benefits

HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:

  • Comprehensive medical coverage that covers many common services at no cost or for a low copay. Plans include prescription drug and behavioral health coverage as well as telemedicine services and free AirMed medical transportation.
  • Additional options for dental and vision benefits, life and disability coverage, flexible spending accounts, supplemental health protection plans (accident, critical illness, hospital indemnity), auto and home insurance, identity theft protection, legal counseling, long-term care coverage, moving assistance, pet insurance and more.
  • Fertility and family building benefits through Progyny
  • Free counseling services and resources for emotional, physical and financial wellbeing
  • Family support, including adoption assistance, child and elder care resources and consumer discounts
  • 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service)
  • Employee Stock Purchase Plan
  • Retirement readiness and rollover services and preferred banking partnerships
  • Education assistance (tuition, student loan, certification support, dependent scholarships)
  • Colleague recognition program
  • Time Away From Work Program (paid time off, paid family leave, long- and short-term disability coverage and leaves of absence)

Note: Eligibility for benefits may vary by location.

Our teams are a committed, caring group of colleagues. Do you want to work as a Consulting Security Controls Engineer where your passion for creating positive patient interactions are valued? If you are dedicated to caring for the well-being of others, this could be your next opportunity. We want your knowledge and expertise!

Job Summary and Qualifications

Job Summary:

The Security Controls Engineer is a technology and process focused security professional with an emphasis in information security controls, risk assessment, regulatory compliance, and security consultation. Applies information security concepts, knowledge, and skills to support a comprehensive information protection program. The Security Controls Engineer evaluates and monitors the current state of security controls across the organization related to people, process, and technology as well as with 3rd party vendors external to the organization.

General Responsibilities:

  • Collect the top and most pressing IT security risks (regulatory, security of critical enterprise applications and infrastructure, vendors, etc.), analyze, monitor, and derive strategic decisions that balance risk with operation and economic costs of protective measures.
  • Conducts interviews with company senior management and business owners to confirm anticipated business effects resulting from the actual occurrence of any of the identified enterprise security risks.
  • Leverages an inventory of key vendors, applications, processes, and infrastructure items and their impact to the top and most pressing IT security risks. Additionally, maps applications, processes, and infrastructure items to appropriate security risks.
  • Leads activities to identify key controls (policy, procedure, practice, or organizational structure) that if implemented would provide reasonable assurance that security objectives will be achieved and undesired events will be prevented or detected and corrected
  • Leads activities to review, develop, and implement security controls plans, vendor security agreements, and security exceptions to control standards.
  • Leads activities to conduct technical security reviews and assessments of vendors, applications, processes, and IT infrastructure.
  • Leads activities related to the analysis of data collected during security reviews and assessment of vendors, applications, processes, and IT infrastructure in order to determine current state of security risk across the company.
  • Leads activities to develop remediation plans to address issues discovered as result of security reviews and/or assessments of vendors, applications, processes, and IT infrastructure. Works with management to assign remediation responsibilities, actions, and priorities.
  • Leads activities to monitor and track remediation activities to address weaknesses and issues discovered through security reviews or audits of vendors, applications, processes, and IT infrastructure.
  • Leads activities to develop strategies to ensure compliance with security standards as well as regulatory and audit issues.
  • Leads activities to provide periodic reporting including assessment findings and recommendations for improvement to applicable constituencies (e.g., executive management, facility leadership, and governance committee).
  • Identifies security related regulatory requirements (ie. PCI-DSS, SOX, HIPAA), and interacts with internal and external assessors and auditors to ensure ongoing compliance.

Education, Experience and Certifications:

  • Bachelor's Degree - Required
  • 7+ years of experience in relevant work - Required

Other Required Qualifications:

Certifications (preferred, not required):

  • CISSP Certified Information Systems Security Professional
  • GSEC GIAC Security Essentials Certified
  • CISA Certified Information Systems Auditor
  • PCIP PCI Professional Training
  • HCISPP Healthcare Information Security and Privacy Practitioner

Preferred areas of experience:

  • Security Technologies / Methodologies
  • IT Audit/Risk Management
  • Information Security Metrics and Reporting
  • Systems Control Review Process
  • Application/Infrastructure Control Review Process
  • Working knowledge of the COSO and COBIT methodologies
  • Experience with ISO27001, HIPAA, Sarbanes-Oxley, PCI-DSS
  • Experience with IT risk, regulatory, or compliance responsibilities
  • Possession of excellent analytical and interpersonal skills
  • Possession of excellent oral and written communication skills

HCA Healthcare's Information Technology Group (ITG) delivers healthcare IT products and services to HCA Healthcare's portfolio of business and partners, including Parallon, HealthTrust and Sarah Cannon.

For decades, ITG has been a pioneer in the industry, leading the transformation of healthcare into a new era of quality and connectivity. ITG relies on the breadth of the organization and depth of technical expertise to advance and enhance today's healthcare and to enable our physicians and clinicians to provide world-class, innovative care for patients.

ITG employees rally around the noble cause of transforming healthcare through technology and find inspiration in the meaningful work they do-creating a culture that follows our mission statement which begins by saying "above all else we are committed to the care and improvement of human life."

If you want a career in technology and have a heart for healthcare, apply your expertise to a mission that matters.


What qualifications you will need:

Occasional/ Intermittent Travel Required

7 years experience Required Years of Experience

ITG transforms healthcare and gives people healthier tomorrows. We deliver information technology strategy, support, and solutions. ITG improve and enhance patient care and business operations. We deliver services at administrative locations, data centers, and hospitals. The facilities we support are located in 20+ states and the United Kingdom. Our team works to move healthcare forward. We do this by seeking, embracing, developing, and delivering technology for patient care.

HCA Healthcare has been recognized as one of the World's Most Ethical Companies by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.


"Bricks and mortar do not make a hospital. People do." - Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder

If you are looking for an opportunity that provides satisfaction and personal growth, we encourage you to apply for our Consulting Security Controls Engineer opening. We promptly review all applications. Highly qualified candidates will be contacted for interviews. Unlock the possibilities and apply today!

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

(web-54f47976f8-vn8xb)