Job Closed

This listing is no longer active.

Vanderbilt University Medical Center logo
Vanderbilt University Medical Center

Based in Nashville, Tennessee, Vanderbilt University Medical Center (VUMC) is a comprehensive healthcare facility and a leader in medical research, education, a

IT Risk Analyst (Remote Available)

Location

United States

Posted

79 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

IT Risk Analyst (Remote Available)

Vanderbilt University Medical Center

Discover Vanderbilt University Medical Center: Located in Nashville, Tennessee, and operating at a global crossroads of teaching, discovery, and patient care, VUMC is a community of individuals who come to work each day with the simple aim of changing the world. It is a place where your expertise will be valued, your knowledge expanded, and your abilities challenged. Vanderbilt Health is committed to an environment where everyone has the chance to thrive and where your uniqueness is sought and celebrated. It is a place where employees know they are part of something that is bigger than themselves, take exceptional pride in their work and never settle for what was good enough yesterday. Vanderbilt’s mission is to advance health and wellness through preeminent programs in patient care, education, and research. Organization: VEC ClinicalCyberRisk Job Summary: This position will conduct application risk assessments crucial to enterprise-wide systems. This position will provide support in security architecture and participate in incident response as dictated. This position will leverage IT risk management tools to determine appropriate measures for risk mitigation as needed. The position will be part of the Clinical Cyber Risk assessment team and is a critical component of processing assessments in a timely fashion and providing enhanced user training for VUMC employees and contractors. . KEY RESPONSIBILITIES • Conducts application focused risk assessments. • Assists application owners with security best practices. • Participates in incident response activities related to systems. • Executes passive and active user training activities. • Monitors systems for suspect behavior. • The responsibilities listed are a general overview of the position and additional duties may be assigned. TECHNICAL CAPABILITIES • Risk Assessment (Novice): Demonstrates familiarity with professional risk assessment processes and understands risk prioritization. Evaluates risks with an eye toward regulatory concerns while staying aware of current attack vectors. Identifies viable mitigation strategies that can be presented to business owners for consideration. Documents risk findings and suggested mitigations in a concise manner that can be clearly communicated to stakeholders. • Regulatory Awareness (Novice): Demonstrates knowledge of healthcare regulations and security best practices. Identifies appropriate sources of governmental and industry guidance. Interprets regulations and guidance to assist application and business stakeholders with compliance and security best practice efforts. • Security Control Knowledge (Novice): Understands and has direct familiarity with common information security technical toolsets (e.g. firewall, SIEM, IPS, vulnerability scanner, etc.). Demonstrates knowledge of non-technical controls (e.g. physical and administrative). Able to effectively communicate with teams directly administering controls to identify suitable responses to identified risks. • User Training (Novice): Conducts formal, ad-hoc, and covert user training activities. Effectively communicates security risks to users of every skill level. Utilizes technical toolsets to aid and report on the training process (e.g. LMS, phishing campaigns, etc.) • Incident Response (Novice): Understands incident response processes and is able to work in a professional manner during an incident. Serves as a liaison between technical and non-technical parties. Has an understanding of the forensic process and is able to identify appropriate skillsets necessary to handle investigative activity. About the Department: Vanderbilt Health - VUMC Enterprise Cybersecurity (VEC) VEC provides information security service solutions for securing all administrative, clinical and research operations for all of Vanderbilt Health, the largest non-government employer in Middle Tennessee. Vanderbilt Health is always growing, with our current environment of 7 hospitals, nearly 40K staff, over 40K workstations, over 160K network connections, and numerous data centers and cloud environments, securing our health system is truly a challenge! To meet the challenge, VEC is led by 2 Vice Presidents and is structured with many dedicated teams, including: Active Vulnerability Assessment, Business Information Security Office, Business Resilience Services, Identity and Directory Services, Policy and Compliance, Security and Architecture Assurance, Security Engineer Services, Security Operations Center, and Threat Detection and Response. VEC also employs state-of-the-art technology and partners with the many IT and operational teams across the enterprise to ensure a partnered, cohesive, and comprehensive approach to information security. Our professional administrative functions include critical supporting roles in information technology and informatics, finance, administration, legal and community affairs, human resources, communications and marketing, development, facilities, and many more. At our growing health system, we support each other and encourage excellence among all who are part of our workforce. High-achieving employees stay at Vanderbilt Health for professional growth, appreciation of benefits, and a sense of community and purpose. Core Accountabilities: Organizational Impact: Executes job responsibilities with the understanding of how output would affect and impact other areas related to own job area/team with occasional guidance. Problem Solving/ Complexity of work: Analyzes moderately complex problems using technical experience and judgment. Breadth of Knowledge: Has expanded knowledge gained through experience within a professional area. Team Interaction: Provides informal guidance and support to team members. Core Capabilities : Supporting Colleagues:- Develops Self and Others: Invests time, energy, and enthusiasm in developing self/others to help improve performance e and gain knowledge in new areas.- Builds and Maintains Relationships: Maintains regular contact with key colleagues and stakeholders using formal and informal opportunities to expand and strengthen relationships.- Communicates Effectively: Recognizes group interactions and modifies one's own communication style to suit different situations and audiences. Delivering Excellent Services:- Serves Others with Compassion: Seeks to understand current and future needs of relevant stakeholders and customizes services to better address them.- Solves Complex Problems: Approaches problems from different angles; Identifies new possibilities to interpret opportunities and develop concrete solutions.- Offers Meaningful Advice and Support: Provides ongoing support and coaching in a constructive manner to increase employees' effectiveness. Ensuring High Quality: - Performs Excellent Work: Engages regularly in formal and informal dialogue about quality; directly addresses quality issues promptly.- Ensures Continuous Improvement: Applies various learning experiences by looking beyond symptoms to uncover underlying causes of problems and identifies ways to resolve them. - Fulfills Safety and Regulatory Requirements: Understands all aspects of providing a safe environment and performs routine safety checks to prevent safety hazards from occurring. Managing Resources Effectively: - Demonstrates Accountability: Demonstrates a sense of ownership, focusing on and driving critical issues to closure.- Stewards Organizational Resources: Applies understanding of the departmental work to effectively manage resources for a department/area.- Makes Data Driven Decisions: Demonstrates strong understanding of the information or data to identify and elevate opportunities. Fostering Innovation:- Generates New Ideas: Proactively identifies new ideas/opportunities from multiple sources or methods to improve processes beyond conventional approaches.- Applies Technology: Demonstrates an enthusiasm for learning new technologies, tools, and procedures to address short-term challenges.- Adapts to Change: Views difficult situations and/or problems as opportunities for improvement; actively embraces change instead of emphasizing negative elements. Position Qualifications: Responsibilities: Certifications: CompTia Security+ - Licensure-Others Work Experience: Relevant Work Experience Experience Level: 2 years Education: Bachelor's Vanderbilt Health is committed to fostering an environment where everyone has the chance to thrive and is committed to the principles of equal opportunity. EOE/Vets/Disabled.

Related Categories

Related Job Pages

More Risk Jobs

Pull Skill Technologies Inc. logo

Data Governance Analyst

Pull Skill Technologies Inc.

Staffing needs simplified, customized and cost effective!!

Risk79 days ago
ContractRemoteTeam 51-200H1B No Sponsor

• Document, assess, influence, and synthesize business requirements to develop, enable, and advance data governance and stewardship capabilities • Serve as a dedicated liaison to a community of Business Data Stewards and other stakeholders by providing mentorship and guidance on data governance processes, capabilities, and best practices • Be the expert in the use of, establish standards for, configure, and provide training on data governance technologies with a concentration on the data glossary and catalog tools • Act as technical support to Business Data Owners and Data Stewards • Facilitate and promote usage and adoption of the data governance tools, particularly among business users • Utilize the data quality technology to design and develop rules, mappings, and transformations to measure and improve the quality of data as well as routines and algorithms to identify and match potential duplicate records • Create, deploy, and execute workflows to automate data quality procedures and escalate identified exceptions and defects to Business Data Stewards for remediation • Develop candidate Key Performance Indicators and dashboards to measure the success and ROI of the data governance program with a concentration on the data glossary and catalog • Maintain and promote key data governance deliverables/assets, including data policies, data standards, and data management roles and decision frameworks. • Support design of future state concept of operations through the analysis of business process models and data flow diagrams • Interact with business and technical peers in the evaluation of emerging industry trends and technologies relevant to data management

New Jersey
ContractRemoteTeam 1-10H1B No Sponsor

• Deliver on the vision and roadmap for our HR Data Governance Strategy o Driving metadata management (alignment on definitions, capturing data lineage, capturing data classification, maintaining/updating HR items in data catalogue) • Driving the cultural change agenda; raising awareness regarding data governance principles; coaching relevant stakeholders • Facilitate Data Governance forums and workshops with relevant stakeholders to promote adherence to governance policies. • Develop and implement Data Quality processes to support more proactive resolution of issues. • Support Data Access controls implemented for Global Data Products • Working with the Global Data Governance Director, the Global Data Stewards for HR data, the Data Governance CoE, and leaders in the HR space, to continuously drive our HR Data Governance Strategy • Ensure sustainable delivery of customer value on the agreed Data Governance roadmap • Clear narrative and articulation of Data Governance principles linked to business value-add, communicating these regularly to stakeholders across Data and HR. • Track and report on specific and measurable aligned KPIs and key results, developing metrics to measure maturity and Data Quality • Proactively identify and escalate risks and mitigation plans, along with key decisions, to relevant stakeholders • Support and align with the Data Governance community (Data Governance Directors, and Data Stewards) to ensure alignment and best practice sharing

India
Airbnb logo

Senior Risk Functional Specialist

Airbnb

Airbnb is a community based on connection and belonging.

Risk79 days ago
Full TimeRemoteTeam 5,001-10,000Since 2007H1B Sponsor

• Protect our community by reviewing and making exceptional decisions for platform exemptions to maintain trust and safety across Airbnb • Own incident resolution of risky pay-in procedures from escalation to closure, ensuring swift and thorough case management that protects our hosts and guests • Navigate complex operational issues by partnering with Legal, Public Affairs, and other teams to respond to regulatory inquiries related to fraud and criminal activities • Tell the story through data by drafting business requirements and concept briefs that highlight key operational needs for platform development

United States
$82K - $96K / year
Job Closed
Full TimeRemoteTeam 5,001-10,000

Your Journey at Crowe Starts Here: At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you’re trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That’s why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services. Join us at Crowe and embark on a career where you can help shape the future of our industry. Job Description: Third Party Senior Staff Job Summary: The position will be primarily responsible for assessing the information security posture of key clients’ third parties and coordinating the overall execution and delivery of assessments. The position will work within a Crowe team at a client or third party site and be responsible for leading the effort to identify key risks and information security gaps. Projects would be performed through interacting with the client’s IS and Business Unit leadership, as well as the client’s vendors, service providers, and partners. Specific projects may include: - Conducting Third Party Risk Assessments by evaluating third party questionnaire responses, performing control validation, and assessment of documentation per established procedures and standards - Performing site visits to third-party facilities - Evaluating the effectiveness of security controls for compliance with applicable policies, security laws, and regulations - Assessing cloud technologies such as Software as a Service (SaaS) hosted applications, Platform as a Service (PaaS), and Infrastructure as a Service deployments (IaaS) - Documenting information security risk and compliance findings and recommendations for remediation - Perform quality assurance and review of assessments performed by other team members - Delivering high quality, thorough reports - Coordinating the schedules and assessments for key third party clients and overseeing all key deliverables Our clients operate in and our team members work across the following industries: - Pharmaceutical - Life Sciences - Biotechnology - Healthcare - Manufacturing - Financial Services - Technology, Media and Telecomm Minimum Qualifications: - Bachelor's Degree - Information Technology and/or Cybersecurity background and/or experience, including 2-4 years IT experience with network, platform, and/or application technology - Willingness to obtain the Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Third Party Risk Assessor (CTPRA) designations - Knowledge of security areas such as auditing, policy, database security, firewall design and implementation, risk analysis, identity management, access management, or web - Working knowledge of at least one compliance framework, such as SOC2, ISO 27001, NIST, HIPAA - Experience managing multiple projects, in a fast-paced environment - Proven ability to learn new technologies and systems, especially through independent research and self-study - Ability to communicate technical information verbally and through written documentation - Ability to manage project schedules and client expectations - Ability to travel domestically an average of 20%-50% per year Desired Qualifications: - Bachelors and/or advanced degree with a concentration in: Cybersecurity, Risk Management, Computer Science, or Management Information Systems - Any experience working with or assessing third party vendors is preferred but not required - IT experience at a leading industry public company. This might include either IT auditing or being a member of an IT or Cybersecurity team - Experience with Archer, Process Unity, ServiceNow or other GRC/VRM tools - Experience with security ratings platforms - Bilingual - Open to remote We expect the candidate to uphold Crowe’s values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Crowe is not sponsoring for work authorization at this time. The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Crowe, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $80,500.00 - $159,300.00 per year. Our Benefits: Your exceptional people experience starts here. At Crowe, we know that great people are what makes a great firm. We care about our people and offer employees a comprehensive total rewards package. Learn more about what working at Crowe can mean for you! How You Can Grow: We will nurture your talent in an inclusive culture that values diversity. You will have the chance to meet on a consistent basis with your Career Coach that will guide you in your career goals and aspirations. Learn more about where talent can prosper! More about Crowe: Crowe (www.crowe.com) is one of the largest public accounting, consulting and technology firms in the United States. Crowe uses its deep industry expertise to provide audit services to public and private entities while also helping clients reach their goals with tax, advisory, risk and performance services. Crowe is recognized by many organizations as one of the country's best places to work. Crowe serves clients worldwide as an independent member of Crowe Global, one of the largest global accounting networks in the world. The network consists of more than 200 independent accounting and advisory services firms in more than 130 countries around the world. Crowe LLP provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, sexual orientation, gender identity or expression, genetics, national origin, disability or protected veteran status, or any other characteristic protected by federal, state or local laws. Crowe LLP does not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a pre-existing agreement signed by both parties covering the submission will be considered the property of Crowe, and free of charge. Crowe will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, San Francisco Fair Chance Ordinance, and the California Fair Chance Act. Please visit our webpage to see notices of the various state and local Ban-the-Box laws and Fair Chance Ordinances, where applicable. We are committed to a merit-based hiring process, evaluating all candidates consistently using objective, job-related criteria such as relevant experience, demonstrated skills, measurable impact, and alignment with the role’s responsibilities, and making employment decisions in a fair and inclusive manner free from discrimination. If you are interested in applying for employment with Crowe and are in need of an accommodation or require special assistance to navigate our website or to complete your application, please visit our Applicant Assistance and Accommodations page for more information: https://careers.crowe.com/crowe-applicant-assistance-and-accommodation

United States
$80.5K - $159K / year