acts in a security assessor role to review acquisition environments of diverse scopes and complexity ranging from moderate to substantial against well-known cyber security frameworks.
help Humana assess and integrate acquired companies into the organization.
work with Humana's technology organization and various internal groups to review and contribute to integration initiatives with available technology including hardware, software, applications, and peripherals with the purpose of ensuring that security meets Humana's expectations.
review acquisition environments and assists the teams with creating, tracking, and implementing remediation plans to address identified security gaps.
Lead a risk assessment and/or audit of IT controls and systems.
conduct audit review procedures and evaluate the company's technological infrastructure against HITRUST, NIST, PCI and other internal security control frameworks.
communicate well verbally and in writing to various types of audiences.
understand when an identified risk is worthy of escalation to leadership and can manage discussions that support the escalation.
Requirements
8 years' experience as a Security Assessor/auditor, IT controls implementation professional or Risk professional working with complex systems, teams, GRC processes and tools
Bachelor's or Master's degree in information security, IT, or business-related field
Experience in Healthcare industry with a solid understanding of HIPAA
Knowledge and experience in mergers & acquisitions relative to reviewing various technology systems/controls.
Knowledge of Humana's Minimum Necessary Security framework and processes.
Ability to manage multiple assignments for various entities at the same time