drjobs SCC - IT Security Auditor 3 - Both WEB AND IN PERSON IVS!

SCC - IT Security Auditor 3 - Both WEB AND IN PERSON IVS!

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Richmond - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

SCCs Health Benefit Exchange division is seeking an experienced IT Auditor
ON SITE REQUIRED: Tuesday AND Thursday each week
Parking not provided for contractors

Pls note: The manager will conduct first round interviews on TEAMS and then require the TOP candidate in for a follow up IN PERSON (2nd) interview.

ABOUT THE ROLE

The SCCs Health Benefit Exchange division is seeking an experienced IT auditor to support our transition to a new security standard and strengthen our third-party risk management program. This role will help interpret and implement updated security requirements conduct audits and assessments of both internal processes and external vendors and partners evaluating controls and recommending improvements.

Responsibilities Include:

  • Assess current security controls and processes against new CMS IRS and SCC security standards.

  • Identify gaps and recommend remediation steps to achieve and maintain compliance.

  • Plan lead and execute development and updates to policies procedures and documentation to reflect requirements.

  • Design implement and train on the process for assessing partners and vendors ensuring alignment with security standards.

  • Develop assessment tools workflows and scoring model to evaluate and measure the effectiveness and compliance of vendor and partner security controls.

  • Evaluate the security posture of vendors and partners to ensure information security contractual information sharing and data sharing agreement requirements are met.

  • Test the effectiveness of operational and management controls using interviews document reviews and observation.

  • Analyze assess report and present on audit findings risk exposure and recommendations.

  • Support information security continuous monitoring and incident response programs.

  • Perform related work as required.

Required/Desired Skills Skill Required /Desired Amount of Experience Audit and compliance/information security/information technology experience or combination thereof Required 8 Years Information Security control audit and assessment experience Required 4 Years NIST 800-53 or other security framework Required 4 Years Perform testing analysis reporting and develop remediation plans for compliance with operational and management controls Required 4 Years Develop and update policies procedures and documentation Required 2 Years Healthcare health insurance or ACA Desired 2 Years Industry recognized certification CISA CIA GSNA CISSP or equivalent Desired 2 Years Questions No. Question Question1 Commonwealth of Virginia security policies prohibit the use of offshore IT contractors. Do you attest to the fact that your candidate will physically reside within the US for the duration of the assignment Question2 Please list candidates email address. Question3 In what city and state does your candidate currently reside Local Richmond candidates preferred due to ON SITE requirements. If you put they are in Richmond then please upload a copy of their drivers license to verify their local address. Question4 ON SITE REQUIRED: Tuesday AND Thursday each week. If selected does your candidate agree to this arrangement Question5 Pls make sure to highlight or BOLD (on your candidates resume) their exp with any of the REQUIRED and of DESIRED experience /skills - this helps you (and us) to determine their fit for the role. Question6 Pls note: The manager will conduct first round interviews on TEAMS and then require the TOP candidate come to their office for a follow up IN PERSON (2nd) interview. If selected does your candidate agree to this interview arrangement

Employment Type

Full-time

Company Industry

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.