Healthcare Information Security Manager (NY HELPS) - FT - Day Shift
Erie County Medical Center Corporation · Buffalo, NY · 7 mo ago
On-siteInformation Technology$52.51–$72.97/hrFull-time
The work involves assisting the Chief Healthcare Information Security Officer (CISO) in managing the Information Security Program at the Erie County Medical Center Corporation (ECMCC).
Does related work as required.
- Manages the Information Security Program procedures, technical systems and workforce training to maintain the confidentiality, integrity, and availability of data within all information systems;
- Captures resources (staff, equipment, vendors, and consultants) across projects, manages the budget for assigned projects), monitors project progress (risks & issues) and adjusts resources and priorities accordingly;
- Drives adoption of secure hardening and configuration practices in the systems security deployment cycle throughout central technology and line of business technical engineering teams;
- Provides subject-matter-expertise in the discipline of Core Platform security to Cybersecurity operation team and others;
- Provides consultancy for secure system design, development, engineering, and operation;
- Provides project management and operational responsibility for administrative coordination and implementation of the organization’s security program;
- Aids in the development of Security Program Policies and enforces policies and procedures;
- Aids in the enforcement of access control needs of the organization;
- Identifies and helps implement continuous process enhancements/improvements to Cybersecurity Operations;
- Aids in managing information security directives as mandated by Federal and State regulations, including but not limited to the Health Insurance Portability and Accountability Act (HIPAA);
- Aids with disaster recovery, business continuity, incident response, and risk management programs;
- As directed by the Healthcare Information Security Director of CISO, performs or works with third-party consultants to perform information risk assessments, security audits, and accreditation surveys, ensuring that information systems are adequately protected and meet HIPAA certification requirements;
- Attends and participates in meetings, seminars, and training sessions.
Full Performance Knowledge, Skills, Abilities and Personal Characteristics:
- Thorough knowledge of state of the art computer security;
- Good knowledge of project management and development;
- Good knowledge of internal computer logic, programs and facilities;
- Good knowledge of technical infrastructure security components and integrated computerized rules-based systems;
- Familiarity with Federal and State privacy and security laws and regulations and industry best practices as they relate to healthcare information security;
- Ability to enforce programs to ensure the security of health information across a widely dispersed workforce with a variety of information mediums;
- Ability to read, interpret and apply technical information;
- Ability to analyze and resolve security problems quickly;
- Ability to supervise others;
- Ability to establish and maintain effective working relationships with a diverse constituency;
- Critical thinking skills;
- Problem solving skills;
- Technical skills;
- Capable of performing the essential functions of the position with or without reasonable accommodation.
Minimum Qualifications:
- Possession of a Master’s Degree* in Health Information Systems, Computer Science/Computer Programming, or related computer technology or healthcare related field and one (1) year of experience in computer or information security** which included experience with federal and state privacy and security laws, regulations and accreditation standards for maintaining information security and confidentiality;
- Possession of a Bachelor’s Degree* in Health Information Systems, Computer Science/Computer Programming, or related computer technology or healthcare related field and three (3) years of experience in computer or information security**, one (1) year of which included experience with federal and state privacy and security laws, regulations and accreditation standards for maintaining information security and confidentiality;
- An equivalent combination of training and experience as defined by the limits of (A) and (B).
Information Security, for the purpose of qualifying applications, is defined as the processes designed and implemented to protect information, systems, and networks against unauthorized access, use or disruption utilizing various forms of technology.