Hi,

Please check and let me know.


*Sr. IT Security Consultant 12 months*

*Location: Minneapolis*

*Interview: Phone*



*Looking for someone with HITRUST experience  and CISA Cert.*




*Eden Prairie *Must pass a drug test and background check once offered
position**
------------------------------

*PROJECT:*

Supporting UHC's accelerated approach for assessing high risk critical
vendors

*TEAM:*

Reporting to the VISRA Team, the individual will act as a liaison & SME for
internal departments & vendors to successfully perform Onsite Risk
Assessments in USA. We leverage HITRUST CSF Version 7.0 for our program.

*RESPONSIBILITIES:*

   - Perform and manage Onsite Risk Assessments as per process documents
   - Ensure vendor compliance to the business agreement, policies,
   procedures, & regulations along with ability to map controls and compliance
   requirements
   - Review vendor supplied policies & procedures, internal/external
   assessment reports, agreements and provide feedback
   - Provision assessment reports and executive summaries with
   recommendations & direction regarding remediation efforts and disposition
   of the third party
   - Communicate, escalate, and track vendor progress on assessment
   remediation activities
   - Act as a liaison & SME for internal departments & vendors to
   successfully manage Vendor Risk Assessment
   - Understand information security risks that are inherent to a business
   and articulate those risks in business terms
   - Maintain current knowledge on information security topics and their
   applicability program requirements
   - Engage VRO regarding any delays/deviations during remediation

*TOOLS:*

Advance level experience in MS Word, MS Excel, and MS PowerPoint etc.


*MUST HAVE:*

   - Experience working with senior levels of management
   - Good follow-up skills and detail oriented
   - Security expertise including knowledge on different security risk
   assessment frameworks (NIST/Octave), standards
   (ISO27001/HITRUST/ITIL/Cobit), and act such as (HIPAA/GLBA).
   - Experience in examining the SSAE 16 Audit report
   - Knowledge and understanding of different security products (web/email
   filtering, disk encryption, IDS/IPS, antivirus, DLP, firewall etc.)
   - Knowledge of software development methodologies, application security,
   and OWASP Top 10 guidelines
   - Ability to document assessment work papers and preparing assessment
   report
   - Ability to manage vendor assessment independently with minimal
   supervision
   - Strong Communication and Presentation Skills

*NICE TO HAVE:*

Possess good project management skills

***Travel within USA for onsite risk assessments required. Travel Required
: Up to 50%

-- 
Best Regards
Mohit Arora
[email protected]
*201-620-9700* ** 152 *

-- 
You received this message because you are subscribed to the Google Groups 
"Vendors" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at https://groups.google.com/group/vendors.
For more options, visit https://groups.google.com/d/optout.

Reply via email to