Information Access Management Security Systems Analyst
Company: Highmark Health
Location: Lansing
Posted on: January 23, 2023
|
|
Job Description:
**Company :**Highmark Health**Job Description :****JOB
SUMMARY**Information Security & Risk Mgmt at Highmark Health is
more than just "cyber security", it's about ensuring our patients
and members are protected and can get the care they need without
disruption. We are trusted SMEs with diverse points of view and
skills synthesizing security solutions for our enterprise and
customers. We are a highly engaged team who values professional
development and growth - not just with formalized career
development, but with weekly learning opportunities, speaking
engagements and leadership involvement in professional
organizations. We believe inertia is our prime enemy and relentless
incrementalism is our ultimate weapon. That's why we are
innovators, collaborators, solutioners, and tinkerers. Our work is
not easy and the challenges only get tougher; if that's the kind of
environment you're seeking, then we want to talk to you.This job,
as a technical expert in the security domain, sets and monitors
role lifecycle management standards, best practices and systems
necessary to ensure the protection of the confidentiality of
informational assets, which requires strong technical knowledge of
information systems, role based access controls (RBAC) and the use
of established security control.**ESSENTIAL RESPONSIBILITIES**+
Provide Role Based Access Control (RBAC) analysis, design and
implementation expertise within the Organization's IAM
Infrastructure; collaborating with lean purposed IAM Software
Development team to refine and expand the adoption of a
semantically logical and comprehensive RBAC framework.+ Collaborate
with Business Intelligence & Analytics groups; leveraging Tableau
data visualization software for role-mining analysis, and
dashboarding executive overview reporting.+ Collaborate with IT
Governance, Risk & Compliance group to expand and improve process
certification using industry standard product solutions (Sailpoint,
OIG, Dell One).+ Document business requirements gathering and
documentation for the design and implementation of an RBAC
framework.+ Provide business analysis support, drafting business
requirements documentation for clients, as well as system
integrations and operational support for User Access review
campaigns.+ Other duties as assigned or
requested.**EDUCATION****Required**+ Bachelor's Degree in
Information Security, Information Systems, Information Assurance,
Computer Science or related field**Substitutions**+ 6 years of
Information Security, Governance, Risk and/or Compliance,
Information Technology or Business Analysis**Preferred**+ Master's
Degree in Computer Science, Information Security or related
field**EXPERIENCE****Required**+ 3 - 5 years in Information
Security and Risk Management with a focus on Role LifeCycle
Management+ 3 - 5 years in Information Technology+ 3 - 5 years
developing, communicating and presenting Information Security and
Risk Management concepts to varying audiences**Preferred**+ 3 - 5
years in Information Security and Risk Management with a focus on
software development companies+ Experience working within an
information security function using the HITRUST Common Security
Framework (HITRUST CSF), or the NIST 800-83 cyber security
framework+ In-depth understanding of network security architecture,
network and networking protocols**LICENSES AND
CERTIFICATIONS****Required**+ None**Preferred**+ Certified
Information Systems Security Professional (CISSP)+ Information
Technology Infrastructure Library (ITIL)+ Security **SKILLS**+
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework,
Payment Card Industry (PCI), Health Insurance Portability &
Accountability Act (HIPAA), HITECH, COBIT, International
Organization for Standardization (ISO) 27001/2, and ITIL+ Role
Analytics background+ Proficient in manipulating and querying
databases/SQL+ Fluent in scripting, building and running queries+
Knowledge of NIST Risk Assessment methodology+ Familiarity with
secure SDLC best practices+ Knowledge of Microsoft Apps and Suites,
Windows server, SharePoint, etc.+ Strong teamwork and
inter-personal skills+ Adaptable and resilient: able to shift
direction while remaining productive. Maintains focus in the face
of challenge.+ Consultative: skilled listener, prepares
recommendations to client problems, adopts a customer first
mindset, partner with internal and external project teams to drive
results.+ Organized/Time Management**Languages (Other than
English)**None**Travel Requirement**0% - 25%**PHYSICAL, MENTAL
DEMANDS and WORKING CONDITIONS****Position
Type**Office-BasedTeaches/Trains others
regularlyOccasionallyTravels regularly from the office to various
work sites or from site-to-siteOccasionallyWorks primarily
out-of-the office selling products/services (Sales employees)Does
Not ApplyPhysical Work Site RequiredYesLifting: up to 10 poundsDoes
Not ApplyLifting: 10 to 25 poundsDoes Not ApplyLifting: 25 to 50
poundsDoes Not ApplyDisclaimer: The job description has been
designed to indicate the general nature and essential duties and
responsibilities of work performed by employees within this job
title. It may not contain a comprehensive inventory of all duties,
responsibilities, and qualifications required of employees to do
this job.Compliance Requirement: This position adheres to the
ethical and legal standards and behavioral expectations as set
forth in the code of business conduct and company policies.As a
component of job responsibilities, employees may have access to
covered information, cardholder data, or other confidential
customer information that must be protected at all times. In
connection with this, all employees must comply with both the
Health Insurance Portability Accountability Act of 1996 (HIPAA) as
described in the Notice of Privacy Practices and Privacy Policies
and Procedures as well as all data security guidelines established
within the Company's Handbook of Privacy Policies and Practices and
Information Security Policy. Furthermore, it is every employee's
responsibility to comply with the company's Code of Business
Conduct. This includes but is not limited to adherence to
applicable federal and state laws, rules, and regulations as well
as company policies and training requirements.Highmark Health and
its affiliates prohibit discrimination against qualified
individuals based on their status as protected veterans or
individuals with disabilities, and prohibit discrimination against
all individuals based on their race, color, religion, sex, national
origin, sexual orientation/gender identity or any other category
protected by applicable federal, state or local law. Highmark
Health and its affiliates take affirmative action to employ and
advance in employment individuals without regard to race, color,
religion, sex, national origin, sexual orientation/gender identity,
protected veteran status or disability.EEO is The LawEqual
Opportunity Employer
Minorities/Women/ProtectedVeterans/Disabled/Sexual
Orientation/Gender Identity (
http://www1.eeoc.gov/employers/upload/eeoc\_self\_print\_poster.pdf
)We endeavor to make this site accessible to any and all users. If
you would like to contact us regarding the accessibility of our
website or need assistance completing the application process,
please contact number below.For accommodation requests, please
contact HR Services Online at
HRServices@highmarkhealth.orgCalifornia Consumer Privacy Act
Employees, Contractors, and Applicants NoticeReq ID: J169803
Keywords: Highmark Health, Lansing , Information Access Management Security Systems Analyst, Executive , Lansing, Michigan
Click
here to apply!
|