Match score not available

Business Information Security Officer (Remote)

Remote: 
Full Remote
Experience: 
Expert & Leadership (>10 years)
Work from: 
Iowa (USA), United States

Offer summary

Qualifications:

Bachelor's degree required, Minimum one industry certification required, 10+ years of professional experience, Experience in healthcare preferred.

Key responsabilities:

  • Provide oversight of CIP Policies and Standards
  • Consult on security process governance based on risk appetite
Conexess Group logo
Conexess Group Information Technology & Services SME https://www.conexess.com/
51 - 200 Employees
See more Conexess Group offers

Job description

Our History:
From our start in 2009, Conexess has established itself in 3 markets, employing nearly 200+ individuals nation-wide. Operating in over 15 states, our client base ranges from Fortune 500/1000 companies to mid-small range companies. For the majority of the mid-small range companies, we are exclusively used due to our outstanding staffing track record.
 
Who We Are:
Conexess is a full-service staffing firm offering contract, contract-to hire, and direct placements. We have a wide range of recruiting capabilities extending from help desk technicians to CIOs. We are also capable of offering project-based work.
 
Conexess Group is aiding a large healthcare client in their search for a
Business Information Security Officer in a remote capacity. This is a long-term opportunity with a competitive compensation package.

***This position includes fiduciary duty or access to financial systems***

 
Responsibilities:
  • The Business Information Security Officer (BISO) performs a First Line of Defense role within the Information Protection organization, providing oversight of all CIP Policies & Standards within the assigned business unit. 
  • The primary interface between Information Protection and the assigned business unit and is focused on improving operational efficiency, driving accountability and ownership, and reducing risk to an acceptable level by: 
  • Enhancing visibility for key risk areas to maximize risk reduction
  • Consulting on key security process governance based on risk appetite
  • Supporting deeper integration of Information Protection Shared Services
  • Driving security value around local and global initiatives
 
Primary Focus Areas:
  • Application Vulnerability Assessment
  • Audit Interface
  • Continuity of Business
  • Data Transfer Authorization
  • Data Leakage Prevention
  • Desktop Controls
  • Electronic Transportable Media
  • End User Computing
  • Identity & Access Management
  • Information Security Risk Assessment
  • Issues Management
  • Key Risk Indicators
  • Legal / Regulatory Requirements
  • Policy & Procedures
  • Phishing
  • Risk Control Self-Assessment
  • Secure Software Development Lifecycle
  • Security Incident Response Team
  • Training & Awareness
  • Third Party Information Security Assessment
 
 
Qualifications:
  • A bachelor’s degree, a minimum of one industry certification (CISA, CISSP, CISM, CRISC, CDPSE, CGEIT), and experience in a regulated industry is required.
  • Experience in a Health Services related industry is preferred.
  • 10+ years of professional experience in the areas of Information Security, Technology Risk, Operational Risk, and Data Protection.
  • Industry certifications such as CISA, CISSP, CISM, CRISC, CDPSE, CGEIT.
  • Familiarity and experience with Legal / Regulatory frameworks such as FIO, GDPR, HIPAA, HITRUST, and SOX.
  • Familiarity and experience with Industry frameworks such as COBIT, ISO, NIST, PCI, SCF, SOC1, and SOC2.
  • A strong communicator with great analytical / presentation skills.
  • An emotionally intelligent individual with the ability to build productive partnerships between technology, business leaders, and external partners.
  • Agility in dealing with a fast paced, constantly changing business environment and areas of ambiguity.
  #LI-DB1
#LI-Remote

Required profile

Experience

Level of experience: Expert & Leadership (>10 years)
Industry :
Information Technology & Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Emotional Intelligence
  • Communication
  • Analytical Skills

Information Security Analyst Related jobs