[SJ-JOB] Director, Information Security, Chicago
[email protected] 18 Nov 2008 00:10:24 -0000
| Newsgroups | gmane.comp.security.jobs |
|---|---|
| Message-ID | <[email protected]> |
--------------------------------------------------- SECURITYFOCUS JOBS - NEW OPPORTUNITY --------------------------------------------------- JOB DESCRIPTION --------------------------------------------------- Position: Director, Information Security Location: Chicago, Illinois, United States Type: Permanent F/T Closing Date: 2008-12-07 This is a 3 months Contract - Hire position=0D =0D Summary: Responsible for the overall development, implementation and mai= ntenance of the security systems used by client. This position will work = closely with all levels of the organization to ensure the maximum level o= f security consistent with organizational risk, information access requir= ements and business strategies. Coordinates with Information Technology (= IT) Technical Support and IT Applications regarding technical considerati= ons (user rights/privileges, system access) to ensure proper implementati= on and provides on-going support of all security operations. Provides sec= urity related technical consulting on complex organizational projects. Ev= aluates existing systems and procedures, and makes recommendations for im= provements as required.=0D =0D Principal Duties and Responsibilities:=0D Assesses security needs and capabilities of the organization. Prepares re= gular reports to IT management concerning the current state of security m= easures and makes recommendations for improvement as required. =0D Develops the overall security program and content. This program will incl= ude all aspects of information security and information access including = Internet/Intranet access and risks. Works with existing policies and proc= edures to identify, recommend and develop revised policies and procedures= relating to information security as appropriate. Maintains and revises t= he overall security program. =0D Identifies and provides information security awareness training as approp= riate. Identifies appropriate courses to enhance security capabilities an= d competencies of the organization. =0D Works with IT management, risk managers, corporate compliance and in-hous= e legal counsel to perform and maintain risk assessment concerning system= down time, unwarranted system access and general risk levels. Ensures or= ganization compliance with the security sections of Federal and State reg= ulations including HIPAA, as well as JCAHO standards. =0D Works with internal and external auditors to response to needed requests,= suggestions and security related findings. =0D Develops the overall disaster recovery plan and content. Includes all asp= ects of disaster recovery planning including data center and application = system recovery and departmental business continuity plans. Works with IT= management, IT staff, vendors, regulatory agencies and service providers= to develop and maintain cost-effective and appropriate disaster recovery= plans and procedures for the organization. =0D Determines and designs appropriate tests for all aspects of information s= ecurity and disaster recovery. Activities include attempted "cracking" of= system security, review of audit trails, simulations of disaster recover= y situations and attempted theft of devices. Evaluates system effectivene= ss and makes change recommendations as necessary. =0D Keeps current on security administration and disaster recovery issues thr= ough seminars, publications and self education on an on-going basis. =0D Conforms to formal departmental methodology standards. =0D Demonstrates effective behaviors as outlined in the organization-wide cor= e competencies. =0D Provides support to the all CLIENT Applications in the development and im= plementation of security controls for these applications. =0D Works closely with Application Build Teams to understand the security arc= hitecture and coordinates the implementation of changes in security once = approved through the Configuration Management. =0D Oversees user support issues regarding user access to all applications. = =0D Maintains relationships with clinical and business management to identify= and understand security issues related to Client Applications that need = to be addressed through IT management and technical teams. =0D Leads, motivates and coaches project team members =0D Implements and ongoing Scope Change Management Plan; manages scope escala= tion =0D Assists the team to problem solve and determine solutions that minimize b= arriers to the business solution =0D Proactively manages project issues and risk to minimize variances to the = plan; manages escalations =0D Maintains constant communication with the Business Sponsor, Technical Lea= ds and other team members as well as IT and Business management =0D Manages the IT Risk and Security team =0D Identify and manage budget for the team =0D Identify and manage training objectives for the team =0D Identify and manage yearly team goals and objectives =0D Serve as project manager for selected projects =0D Identify projects that require additional resources and coordinate throug= h the PMO =0D Ensure Change Management is carried out for all projects =0D Ensure maintenance is carried out on all technical systems operated by th= e team =0D Provide staff counseling and oversight =0D Attend departmental manager meetings and provide status updates, as requi= red =0D =0D =0D JOB REQUIREMENTS --------------------------------------------------- Knowledge, Skills and Abilities:=0D =0D Requires bachelor's degree in computer science or related technology fiel= d. =0D Requires ten years of relevant computer systems experience, preferably in= a healthcare setting. =0D Experience should include at least five years of experience in an informa= tion security position and three or more years in a customer support role= with high customer satisfaction goals. =0D Thorough understanding of risk analysis, disaster recovery and audit trac= king. =0D Thorough knowledge of local area and wide area network architectures (LAN= /WAN), and in-depth and current knowledge of data processing and programm= ing concepts. Experience with network design, routing design and open sys= tem security issues. =0D Thorough knowledge of formal project management techniques and tools thro= ugh training and direct experience (MS Project or other project schedulin= g tools) =0D Understands sound business concepts and practices for hospital registrati= on, billing, collections, and receivables management =0D Command of typical office automation tools (Microsoft Professional Suite,= Lotus Notes, e-mail, etc.) as well as vendor/contract management experie= nce. =0D Familiarity with current common paradigms for violating system integrity.= =0D 7+ years experience as a Project Manager; Project Management Professional= (PMP) certification a plus =0D Must have excellent interpersonal skills to effectively communicate with = all levels of hospital personnel, vendors and IT personnel. =0D Must possess the ability to deliver clear, concise communications and pre= sentations. Must be able to train others quickly and thoroughly on key IT= concepts. =0D CONTACT --------------------------------------------------- Ashwin Mamidala=0D (847) 368-0860 x 242=0D (847) 800-9515 (M)=0D [email protected] VIVA USA INC Ashwin Mamidala Sr Manager [email protected] --------------------------------------------------- SECURITYFOCUS JOBS --------------------------------------------------- SecurityFocus now offers an online interface for searching and managing job opportunities and resumes. http://www.securityfocus.com/jobs