As a notforprofit organization Partners HealthCare is committed to supporting patient care research teaching and service to the community by leading innovation across our system. Founded by Brigham and Womens Hospital and Massachusetts General Hospital Partners HealthCare supports a complete continuum of care including community and specialty hospitals a managed care organization a physician network community health centers home care and other healthrelated entities. Several of our hospitals are teaching affiliates of Harvard Medical School and our system is a national leader in biomedical research.
Were focused on a peoplefirst culture for our systems patients and our professional family. Thats why we provide our employees with more ways to achieve their potential. Partners HealthCare is committed to aligning our employees personal aspirations with projects that match their capabilities and creating a culture that empowers our managers to become trusted mentors. We support each member of our team to own their personal developmentand we recognize success at every step.
Our employees use the Partners HealthCare values to govern decisions actions and behaviors. These values guide how we get our work done: Patients Affordability Accountability & Service Commitment Decisiveness Innovation & Thoughtful Risk; and how we treat each other: Diversity & Inclusion Integrity & Respect Learning Continuous Improvement & Personal Growth Teamwork & Collaboration.
General Overview/Summary
With guidance from the Information Security Risk Manager assists with the Partners HealthCare enterprisewide information security risk assessment program through active engagement with business owners including information gathering risk analysis and reporting.
Principal Duties and Responsibilities
Coordinates and performs information system and thirdparty risk assessments following a NISTbased methodology.
Works closely with IS management business owners endusers and developers to implement risk identification and mitigation strategies and solutions that comply with IS security policies and standards.
Assists with the implementation of GRC technologies including the implementation of automated risk assessment practices.
Will assist in the development of report templates creating formal risk assessment process documents and also delivering formal risk assessments reports to all levels of the business.
Coordinates with other functional units in the Partners HealthCare Information Security and Privacy Department in relation to application security testing and vulnerability management.
Maintains current knowledge of applicable federal and state privacy laws and accreditation standards and monitor advancements in information privacy and security technologies to ensure adaptation and compliance.
Maintains awareness of new technologies and related opportunities for impact on system or application security.
Conduct information security research in keeping abreast of latest security issues and keeps abreast of testing tools techniques and process improvements in support of security event detection and analysis.
Uses the Partners HealthCare values to govern decisions actions and behaviors. These values guide how we get our work done: Patients Affordability Accountability & Service Commitment Decisiveness Innovation & Thoughtful Risk; and how we treat each other: Diversity & Inclusion Integrity & Respect Learning Continuous Improvement & Personal Growth Teamwork & Collaboration.
Performs other duties as assigned.
Partners HealthCare is an Equal Opportunity Employer & by embracing diverse skills perspectives and ideas we choose to lead. All qualified applicants will receive consideration for employment without regard to race color religious creed national origin sex age gender identity disability sexual orientation military service genetic information and/or other status protected under law.
Bachelors degree in a technical field or equivalent combination of education and experience.
Minimum of 2 years related experience including: 12 years information system security in a health care environment preferred including solid background with various technology areas including networking distributed applications systems software firewalls and database management.
Strong technical background; understanding of security architecture networking and system security controls
12 years of project management experience using established methodologies and tools
Knowledge of HIPAA HITECH and the NIST 80053/30 and FIPS series publications
Skills/Abilities/Competencies Required
Ability to exhibit critical and systems thinking
Ability to apply analyze interpret and present data and findings which represent work performed for operations and strategic decisionmaking
Energetic positive and has a can do attitude
Understand the work environment and competing priorities in conjunction with developing and meeting defined goals and objectives
Function as both an individual contributor and team player within Health Information Systems and the Partners Healthcare organization at large and have an ability to be versatile adaptable and work within a complex multisite environment.
Provide quality customer service and serve as an exemplary representative of Partners Information Security Office.
Understand the flow of data through a complex architecture (networking systems and database)
Strong PC skills including Microsoft Office Suite
Good project management and process improvement implementation skills
Good written and verbal communication skills