Director of Information Security Assurance Job at HCA Healthcare, Charleston, SC

ZFBUVlUwS3JuaGZMeU9XMHJTajRTa0RDc1E9PQ==
  • HCA Healthcare
  • Charleston, SC

Job Description

**Description** This position is incentive eligible. **Introduction** Do you have the career opportunities as a Director of Information Security Assurance you want with your current employer? We have an exciting opportunity for you to join HCA Healthcare which is part of the nation's leading provider of healthcare services, HCA Healthcare. **Benefits** HCA Healthcare offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include: + Comprehensive medical coverage that covers many common services at no cost or for a low copay. Plans include prescription drug and behavioral health coverage as well as free telemedicine services and free AirMed medical transportation. + Additional options for dental and vision benefits, life and disability coverage, flexible spending accounts, supplemental health protection plans (accident, critical illness, hospital indemnity), auto and home insurance, identity theft protection, legal counseling, long-term care coverage, moving assistance, pet insurance and more. + Free counseling services and resources for emotional, physical and financial wellbeing + 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service) + Employee Stock Purchase Plan with 10% off HCA Healthcare stock + Family support through fertility and family building benefits with Progyny and adoption assistance. + Referral services for child, elder and pet care, home and auto repair, event planning and more + Consumer discounts through Abenity and Consumer Discounts + Retirement readiness, rollover assistance services and preferred banking partnerships + Education assistance (tuition, student loan, certification support, dependent scholarships) + Colleague recognition program + Time Away From Work Program (paid time off, paid family leave, long- and short-term disability coverage and leaves of absence) + Employee Health Assistance Fund that offers free employee-only coverage to full-time and part-time colleagues based on income. Learn more about Employee Benefits ( **_Note: Eligibility for benefits may vary by location._** Our teams are a committed, caring group of colleagues. Do you want to work as a(an) Director of Information Security Assurance where your passion for creating positive patient interactions is valued? If you are dedicated to caring for the well-being of others, this could be your next opportunity. We want your knowledge and expertise! **Job Summary** The Director of Information Security Assurance (DISA) leads the Information Protection & Security (IPS) program for their assigned area of responsibility, including: driving consistency and visibility of risk management activities; working with key stakeholders to protect patients and prevent data loss; and partnering with leadership to reduce or eliminate risky workforce behaviors. This role is responsible for helping business and IT leadership, as well as the colleagues, comply with IPS requirements while meeting patient care and business needs. This position oversees the assessment of controls and works with appropriate leadership to ensure any deficiencies are addressed. They manage operational processes that monitor and respond to potential security events. They are also responsible for the planning, communication, and/or oversight of IPS initiatives, to ensure consistent program implementation and efficient resource use. This role requires extensive focus on building and expanding relationships with key stakeholders such as business and IT leadership; workforce members; physicians; local IT teams; business owners; vendors; and other people and entities who support IPS objectives and activities. DISAs may have management responsibility for one or more staff members, who are each responsible for an assigned aspect of IPS program as defined by the DISA. The DISA must have a combination of skills including strong written and verbal communication skills, interpersonal skills, and the ability to influence, guide, and/or lead others necessary to accomplish IPS goals. This role will function as the Business Information Security Officer (BISO) fort the South Atlantic Division's acute care hospitals. **Major Responsibilities** **Risk Management** + Implement and manage risk management activities to facilitate effective, efficient, and standardized approach to align with the IPS program + Identify, establish, and maintain strategic relationships with key stakeholders to help accomplish IPS objectives. + Lead their IPS risk management program, using corporate-provided tools and templates, to assure the presence and effectiveness of administrative, technical, and physical controls. + Partner with appropriate leadership -- including Facility Privacy Officials (FPO), Ethics & Compliance Officers (ECO), IT Directors, and physical security leaders -- to respond timely to time-sensitive information requests, by providing evidence of security controls. + Guide risk-based decisions by appropriate decision-makers that focus on preventing or correcting identified security risks through implementation of reasonable controls. + Provide leadership and oversight for acquisition or divestiture due diligence efforts + Represent IPS needs in local strategic planning, budgeting, and work prioritization. + Collaborate with other IPS leaders to ensure consistency of IPS program and solutions. **Issues Tracking and Resolution** + Manage operational processes that monitor and respond to potential security threats. + Partner with corporate departments and/or external entities (e.g., law enforcement) as required to facilitate rapid response to security events. + Partner with HR Director, FPO, Legal, and ECO on cross-disciplinary incident investigation and reporting. + Partner with IT colleagues to assure ongoing maturity of IT operational security controls. + Lead follow-up education and consultation activities for workforce members with risky behaviors and/or behaviors that violate IPS policies and standards. **Execution** + Round on leadership and colleagues to build relationships necessary to influence decisions that protect the company and educate workforce on how to reduce or eliminate risky behaviors. + Lead and coordinate the implementation and adoption of process and technology changes necessary to support IPS program goals and strategic objectives. + Oversee processes for review and approval of security exception requests. **Vendor Systems Security** + Ensure proper vendor contracts and security terms are in place for systems, devices, and services. + Partner with appropriate business and IT leadership to help ensure systems, services, and devices receive appropriate assessments and remediation as part of local on-boarding processes. + Partner with business and IT leadership to ensure proper controls are in place for existing vendor-maintained solutions. **Communication** + Coordinate with local HR and training departments to ensure that periodic workforce training includes company-required IPS content. + Facilitate, and lead where appropriate, proactive IPS communication and awareness activities. **Staff Development** + Recruit and manage IPS staff. + Ensure appropriate training and development programs are utilized to attract, retain, and develop personnel required to support the IPS program. + Participate in succession planning activities. **Education & Experience:** + Bachelor's degree Required + Master's degree Preferred + 7+ years of experience in a relevant field Required + 7+ years of experience in security risk management, information security domains, and/or hospital operations. Preferred + 3+ years of experience in management Required **Licenses, Certifications, & Training:** + CISSP, CISA, HCISPP, CHC, CHPC, CHSP, CISM or other relevant certifications in information security or privacy preferred **Additional Information:** + Must live in or be willing to relocate to the Greater Charleston, SC area + Up to 50% of travel withing the South Atlantic Division and Corporate Headquarters located in Nashville, TN HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses. "Bricks and mortar do not make a hospital. People do."- Dr. Thomas Frist, Sr. HCA Healthcare Co-Founder If you are looking for an opportunity that provides satisfaction and personal growth, we encourage you to apply for our Director of Information Security Assurance opening. We promptly review all applications. Highly qualified candidates will be contacted for interviews. **Unlock the possibilities and apply today!** We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Job Tags

Full time, Temporary work, Part time, Live in, Local area, Relocation, Flexible hours,

Similar Jobs

HDR

Education & Science Associate Principal Job at HDR

At HDR, our employee-owners are fully engaged in creating a welcoming environment where each of us is valued and respected, a place where everyone is empowered to bring their authentic selves and novel ideas to work every day. As we work to weave diversity, equity, and... 

NavitsPartners

Travel Registered Nurse - Labor & Delivery - TRN25-34643 Job at NavitsPartners

 ...Travel Registered Nurse (RN) Labor & Delivery Location: Maryville, TN Duration: 13 Weeks Shift: Night Shift | 312-Hour Shifts (6:45 PM 7:15 AM) Weekly Hours: 36 Hours Pay Rate: $50.00 $56.12 per hour Estimated Weekly Gross... 

Ardent Health

Medical Assistant / MA Urgent Care Job at Ardent Health

 ...Overview Join our team as a full-time, West Loop Urgent Care Medical Assistant (MA) in Tyler, TX. You may be eligible for a sign on bonus up to $1000. Why Join Us? Thrive in a People-First Environment and Make Healthcare Better Thrive: We empower... 

US AMRJones Lang LaSalle Americas, Inc.

Strategic Occupancy Planner Job at US AMRJones Lang LaSalle Americas, Inc.

 ...analyze client portfolios and identify opportunities to optimize space for all organizations within existing and committed portfolios...  ...headcount projections by business unit for rolling three-year planning horizons while creating migration plans and stacking diagrams based... 

Boom Therapy Group

Speech Language Pathologist Job at Boom Therapy Group

 ...Job Title: Speech Language Pathologist About Us: Boom Therapy Group is a patient focused practice with offices in Kings Mountain, Lincolnton...  ...Requirements: Valid NC license in Speech-Language Pathology Masters degree in Speech-Language Pathology or...