- 经验
- 4–7 yrs
- 薪水
- —
- 职位空缺
- 1
- 发布
- 6小时前
- 工作模式
- 在家办公
- 学历
- Bachelor’s degree or equivalent
- 恢复
- 需要申请
职位描述
Role Overview
We seek an Information Security Manager based in the United States for a partner organization committed to strengthening security within a fully remote, technology-focused healthcare setting. The role is pivotal in safeguarding sensitive healthcare data, advancing compliance adherence, and enhancing security maturity.
Key Responsibilities
- Manage and improve identity and access management processes, including Microsoft Entra ID, Active Directory, user lifecycle procedures, conditional access policies, MFA, SSO integrations, and role-based access controls.
- Perform access audits, reviews, and remedial tasks to enforce least-privilege principles and fortify security measures.
- Oversee and optimize security monitoring tools such as SIEM systems, security alert handling, endpoint monitoring, and threat identification operations.
- Lead investigations and responses to security incidents, including detection, containment, recovery, documentation, and ongoing improvement.
- Maintain robust security controls aligned with layered defense strategies and organizational risk management objectives.
- Support SOC 2, URAC, HIPAA, and HITRUST CSF compliance through evidence gathering, control mapping, audit preparation, and remediation oversight.
- Coordinate security certification readiness activities, including gap analysis, control implementation, and stakeholder collaboration.
- Conduct security reviews for applications, integrations, data flows, and configurations to ensure secure operations.
- Manage data governance functions such as Microsoft Purview administration, data classification, loss prevention, retention policies, eDiscovery, and legal hold supports.
- Assess and manage security tools, vendors, and third-party risks including evaluations, renewals, configurations, and security appraisals.
- Create and maintain security-related documentation including policies, standards, procedures, technical baselines, and operational playbooks.
- Respond timely to security inquiries providing clear, documented solutions to internal teams.
- Effectively communicate security concepts, risks, and recommendations to both technical teams and non-technical stakeholders.
Candidate Profile
- Bachelor’s degree in Computer Science, Information Security, IT, or equivalent experience.
- 4 to 7 years of experience in information security, cybersecurity operations, or security engineering roles.
- Proficient with Microsoft security technologies such as Entra ID, Active Directory, Microsoft 365, and Azure.
- Experienced in compliance frameworks including SOC 2, HITRUST, URAC, and HIPAA.
- Hands-on knowledge with identity and access management, single sign-on, SIEM platforms, and data governance tools.
- Skilled in vendor security assessments and third-party risk management.
- Preferred experience with healthcare or pharmacy benefits management sectors.
- Familiarity with certifications like CISSP, CISM, CompTIA Security+, SC-200, SC-300, AZ-500, or HITRUST CCSFP is advantageous.
- Strong technical aptitude with an ability to convey complex security ideas clearly.
- Excellent communication skills, both verbal and written.
- Demonstrates a problem-solving attitude, capable of working independently and handling multiple priorities.
- Reliable remote work setup with strong availability and communication standards.
- Prepared to provide support occasionally during after-hours to handle security incidents or audit deadlines.
- Willingness to travel approximately 10-20% as required.
Benefits and Work Environment
- Competitive salary and compensation package.
- Comprehensive health, dental, and vision insurance benefits.
- 100% remote work arrangement.
- Chance to improve healthcare technology security and data protection.
- Collaborative culture emphasizing innovation, trust, and career development.
- Influence overall enterprise security strategies and capabilities.
- Supportive environment fostering employee growth and meaningful impact.
Additional Information
This position operates fully remotely within the United States and requires occasional travel and after-hours availability. Applications are managed directly by the partner company, with a transparent AI-assisted application review process to ensure fairness and confidentiality. The role offers impactful work within a highly regulated healthcare domain prioritizing trust and privacy.
技能
Work styles they’re looking for
沟通技巧
remote work skills