[SJ-JOB] Director, Information Security, Chicago

[email protected] 18 Nov 2008 00:10:24 -0000
Newsgroups gmane.comp.security.jobs
Message-ID <[email protected]>
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       Director, Information Security
Location:       Chicago, Illinois, United States
Type:           Permanent F/T

Closing Date:   2008-12-07

This is a 3 months Contract - Hire position=0D
=0D
Summary:  Responsible for the overall development, implementation and mai=
ntenance of the security systems used by client. This position will work =
closely with all levels of the organization to ensure the maximum level o=
f security consistent with organizational risk, information access requir=
ements and business strategies. Coordinates with Information Technology (=
IT) Technical Support and IT Applications regarding technical considerati=
ons (user rights/privileges, system access) to ensure proper implementati=
on and provides on-going support of all security operations. Provides sec=
urity related technical consulting on complex organizational projects. Ev=
aluates existing systems and procedures, and makes recommendations for im=
provements as required.=0D
=0D
Principal Duties and Responsibilities:=0D
Assesses security needs and capabilities of the organization. Prepares re=
gular reports to IT management concerning the current state of security m=
easures and makes recommendations for improvement as required. =0D
Develops the overall security program and content. This program will incl=
ude all aspects of information security and information access including =
Internet/Intranet access and risks. Works with existing policies and proc=
edures to identify, recommend and develop revised policies and procedures=
 relating to information security as appropriate. Maintains and revises t=
he overall security program. =0D
Identifies and provides information security awareness training as approp=
riate. Identifies appropriate courses to enhance security capabilities an=
d competencies of the organization. =0D
Works with IT management, risk managers, corporate compliance and in-hous=
e legal counsel to perform and maintain risk assessment concerning system=
 down time, unwarranted system access and general risk levels. Ensures or=
ganization compliance with the security sections of Federal and State reg=
ulations including HIPAA, as well as JCAHO standards. =0D
Works with internal and external auditors to response to needed requests,=
 suggestions and security related findings. =0D
Develops the overall disaster recovery plan and content. Includes all asp=
ects of disaster recovery planning including data center and application =
system recovery and departmental business continuity plans. Works with IT=
 management, IT staff, vendors, regulatory agencies and service providers=
 to develop and maintain cost-effective and appropriate disaster recovery=
 plans and procedures for the organization. =0D
Determines and designs appropriate tests for all aspects of information s=
ecurity and disaster recovery. Activities include attempted "cracking" of=
 system security, review of audit trails, simulations of disaster recover=
y situations and attempted theft of devices. Evaluates system effectivene=
ss and makes change recommendations as necessary. =0D
Keeps current on security administration and disaster recovery issues thr=
ough seminars, publications and self education on an on-going basis. =0D
Conforms to formal departmental methodology standards. =0D
Demonstrates effective behaviors as outlined in the organization-wide cor=
e competencies. =0D
Provides support to the all CLIENT Applications in the development and im=
plementation of security controls for these applications. =0D
Works closely with Application Build Teams to understand the security arc=
hitecture and coordinates the implementation of changes in security once =
approved through the Configuration Management. =0D
Oversees user support issues regarding user access to all applications.  =
=0D
Maintains relationships with clinical and business management to identify=
 and understand security issues related to Client Applications that need =
to be addressed through IT management and technical teams. =0D
Leads, motivates and coaches project team members =0D
Implements and ongoing Scope Change Management Plan; manages scope escala=
tion =0D
Assists the team to problem solve and determine solutions that minimize b=
arriers to the business solution =0D
Proactively manages project issues and risk to minimize variances to the =
plan; manages escalations =0D
Maintains constant communication with the Business Sponsor, Technical Lea=
ds and other team members as well as IT and Business management =0D
Manages the IT Risk and Security team =0D
Identify and manage budget for the team =0D
Identify and manage training objectives for the team =0D
Identify and manage yearly team goals and objectives =0D
Serve as project manager for selected projects =0D
Identify projects that require additional resources and coordinate throug=
h the PMO =0D
Ensure Change Management is carried out for all projects =0D
Ensure maintenance is carried out on all technical systems operated by th=
e team =0D
Provide staff counseling and oversight =0D
Attend departmental manager meetings and provide status updates, as requi=
red =0D
 =0D
=0D



JOB REQUIREMENTS
---------------------------------------------------
Knowledge, Skills and Abilities:=0D
=0D
Requires bachelor's degree in computer science or related technology fiel=
d. =0D
Requires ten years of relevant computer systems experience, preferably in=
 a healthcare setting. =0D
Experience should include at least five years of experience in an informa=
tion security position and three or more years in a customer support role=
 with high customer satisfaction goals. =0D
Thorough understanding of risk analysis, disaster recovery and audit trac=
king. =0D
Thorough knowledge of local area and wide area network architectures (LAN=
/WAN), and in-depth and current knowledge of data processing and programm=
ing concepts. Experience with network design, routing design and open sys=
tem security issues. =0D
Thorough knowledge of formal project management techniques and tools thro=
ugh training and direct experience (MS Project or other project schedulin=
g tools) =0D
Understands sound business concepts and practices for hospital registrati=
on, billing, collections, and receivables management =0D
Command of typical office automation tools (Microsoft Professional Suite,=
 Lotus Notes, e-mail, etc.) as well as vendor/contract management experie=
nce. =0D
Familiarity with current common paradigms for violating system integrity.=
 =0D
7+ years experience as a Project Manager; Project Management Professional=
 (PMP) certification a plus =0D
Must have excellent interpersonal skills to effectively communicate with =
all levels of hospital personnel, vendors and IT personnel. =0D
Must possess the ability to deliver clear, concise communications and pre=
sentations. Must be able to train others quickly and thoroughly on key IT=
 concepts. =0D



CONTACT
---------------------------------------------------
Ashwin Mamidala=0D
(847) 368-0860 x 242=0D
(847) 800-9515 (M)=0D
[email protected]

VIVA USA INC
Ashwin Mamidala
Sr Manager
[email protected]



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs