Skip to main content

This job has expired

IT Senior Data Security Specialist - Remote

Employer
University of Massachusetts Medical School
Location
333 South Street

View more

Administrative Jobs
Institutional & Business Affairs, Safety & Security
Employment Type
Full Time
Institution Type
Four-Year Institution

Job Details

Overview

GENERAL SUMMARY OF POSITION: 

Under the direction of the Information Security Officer, the Senior Data Protection Specialist will ensure that security programs, processes and controls are in-place and effective to ensure compliance with numerous Data Protection requirements. The role is responsible for identifying and assessing security risks associated with Data Protection control development, architecture, implementation and operationalization of UMMS networks, systems and applications. Specific attention to UMMS research Data Protection regulatory and security control preparedness and response is expected.

Responsibilities

ESSENTIAL FUNCTIONS:

  • Compose reports and other documents to provide decision support on information security risks associated with Data Protection for Sr. Mgt., project managers, system owners, Researchers, and business stakeholders
  • Conduct internal and third-party risk assessments focused on Data Protection Requirements and make risk-based recommendations towards achieving compliance
  • Contribute to the enhancement/refinement of the Information Security Risks & Controls library
  • Manage and perform cybersecurity assessments on emerging/ongoing research and business initiatives, third-party services by assessing the impact and likelihood of risk events
  • Assess the impact of potential adverse events, recommend effective controls and mitigations
  • Evaluate third-party products/services by reviewing responses to standardized questionnaires (SIG), evidencing their internal controls
  • Utilize and maintain systems and procedures to effectively assess the information risk
  • Help our business partners understand information security risks, standards, and best practices
  • Support the continuous improvement of Information Security Policies, Standards, Processes, and Procedures
  • Play a key role in the development of GDPR and general Data Protection training
  • Develop IT Procedures/guidance for GDPR compliance (system inventory, data retention/destruction)
  • Document GDPR actions/workflows impacting Information Security
  • Develop enhancements to breach notification processes with a focus on in-scope Data Protection laws (GDPR, CCPA, HIPAA)
  • Develop recertification processes that support relevant Data Protection regulations
  • Support ongoing Data Protection Risk Analysis/Assessment initiatives
  • Develop, communicate, and implement information security programs that address people, process and technology risks
  • Provide expert guidance to UMMS in respect to achieving and maintaining privacy compliance with CCPA, GDPR, HIPAA and other regulations as applicable
  • Report regularly to the Privacy Officer and Chief Information Security Officer as well as present quarterly updates to the Privacy Officer and Executive Leadership
  • Work with Security Architects, Security Analysts, Security Administrators and other IT and business departments to design effective and efficient procedures and controls to meet privacy compliance requirements.
  • Research industry trends for compliance and control implementations to ensure National General maintains reasonable and appropriate privacy compliance controls acceptable within our industry
  • Provide expert guidance and assist in the design of the controls assessment program as it relates to privacy controls
  • Review audit findings and risk and gap analysis reports for accuracy and effectiveness for elements related to privacy compliance
  • Assist in recommending remediation activity for privacy compliance activities found deficient and evaluates remediation effectiveness upon completion
  • Monitor changes in the regulatory and privacy landscape and reports on the impact of those changes to the Director/Privacy Officer and CISO
  • Serve as staff support to the University's Information Security/Privacy Council
  • Participate in annual University audit and other data security/privacy reviews as needed
  • Develop and manage University-wide risk management, assessment, and remediation programs that meets University requirements and federal and state regulations
  • Coordinate the University’s security compliance management and response initiatives
  • Develop and manage information security policies and standards based on industry best practices and compliance requirements
  • Develop and enhance risk management processes and play a lead role in publishing and communicating policies that provide clear direction and guidance
  • Develop and manage a security information response process which will standardize and streamline how requests for university information security control information is captured and disseminated
  • Facilitate internal and third-party information security risk assessments and work closely with functional groups or departments to prioritize and remediate findings
  • Drive the implementation of a framework to support Governance, Risk and Compliance (“GRC”) objectives. Realize significant, measurable gains in GRC practice maturity
  • Act as a risk and compliance thought leader within the University, provide end-to-end expert guidance on how to manage relevant security risks, influence priorities and decisions across the organization
  • Communicate strategic vision and agenda to key stakeholders to ensure proper alignment and support, provide insightful advice and skillful execution
  • Provide end-to-end expert leadership on how to effectively achieve and sustain compliance with regulatory, industry and contractual obligations, as well as information security policies and practices
  • Ensure that contracts provide adequate protection in the areas of legal/regulatory compliance and information security
  • Direct security risk assessments and manage testing of information security controls
  • Represent UMMS in internal / external audits involving information security controls. Assist stakeholders in providing audit responses and remediating security control findings
  • Work closely with attorney’s, regulators and third-parties while representing the University’s security position;
  • Drive continuous improvement in information security risk and compliance based on expert knowledge in domain areas, industry best practices, business objectives and risk tolerances
  • Lead initiatives to regularly assess the adequacy and effectiveness of information security controls, security policies, direct remediation activities, compliance as related to process and workflows, and initiate actions to ensure that compliance and security gaps are successfully addressed
  • Partner with IT and program management teams to define and implement a secure SDLC framework
  • Perform other duties as required
Qualifications

REQUIRED QUALIFICATIONS:

  • Detailed knowledge of federal, state and international laws and regulations concerning privacy and information security
  • Requires a Bachelor’s in Information Systems, Information Security, Compliance or Audit related degree program
  • 7+ years of experience in an information security / privacy / compliance / risk management, thought leadership role
  • Experience in cybersecurity risk analysis and related security products/systems (i.e., RSA Archer, MetricStream, ServiceNow GRC)
  • Demonstrable knowledge of information security standards, data security practices and procedures, network security, application security, and database security
  • Understanding the impact of various data protection and integrity controls, operating systems and network security controls, authentication controls, and security protocols
  • This role requires an effective relationship builder with an understanding of cyber risk, Data Protection regulations (HIPAA, GDPR, CCPA, etc.) and the ability to articulate response and remediation requirements in business terms.
  • Requires strong analytical, interpersonal and communication skills
  • Requires demonstrable knowledge of security principles to a diverse range of risk scenarios to coordinate acceptable solutions between business needs, technology operations, and information security best practices
  • Comfortable working independently and collaboratively to achieve business outcomes
  • Strong written and spoken English with excellent communication, reasoning, and presentation skills
  • A GDPR Practitioner or similar qualification for other privacy-related requirements
  • The ability to liaise with senior stakeholders and conduct meetings at this level
  • Demonstrated ability to translate information security/privacy compliance requirements and University business needs into enterprise-wide data security/privacy standards and policy.
  • Working knowledge of information security/privacy standards and best practices (e.g., NIST, SANS).
  • Must possess a high degree of integrity relative to computer security and the confidentiality of information.
  • Bachelor’s degree in an Information Technology, Information Security, Compliance discipline or equivalent experience
  • Experience in the successful development and implementation of enterprise-wide information security programs which reduce risk
  • Experience in implementing a risk management program which defines risk assessment and remediation requirements, in conducting information security risk assessments which map to ISO/IEC 27000, NIST, BITs, etc., and in defining and implementing SDLC security requirements
  • Experience in developing effective information security policies and standards, and in protecting PHI in compliance with HIPAA, HITECH, FISMA, etc.
  • Ability to collaborate with IT, executive management, and business stakeholders towards achieving business and security objectives
  • Excellent oral and written communication skills
Additional Information

PREFERRED QUALIFICATIONS:

  • Information security management qualifications such as CISSP, CISM or CISA
  • Hold at least one Data Protection and/or Privacy certification such as CIPP, CIPT, ISEB preferred
  • Experience in a higher education environment
  • Demonstrative knowledge of information security standards such as ISO/IEC 27000, NIST, FISMA, PCI, etc.
  • Experience managing systems and networks towards ensuring Data Protection compliance 

#LI-LG1

Organization

Realize Your Opportunities – A Career at UMASS Medical School

Inside Workings at UMASS Medical School

The University of Massachusetts Medical School (UMMS), the Commonwealth's only public medical school, is proud of our role in serving the people of Massachusetts. Although, its the inside workings of UMMS that makes the difference.

Mission and Culture

  • We’re serious about our mission and about our people. 
  • Real World Impact - Our people get excited about our mission of real-world impact in health sciences education, research and public service.
  • International Prominence and New Opportunities - As this institution has grown to national – and international – prominence, we’ve found new opportunities to train tomorrow’s physicians, nurses and scientists,  discover causes of and cures for disease and help improve the quality of health care.
  • Deep Commitment - With our clinical partner, UMass Memorial Health Care, and our other teaching affiliates, we share a deep commitment to national distinction in patient care.
  • Valued Partnerships – UMMS partners with Commonwealth Medicine, the health care consulting arm of UMMS. Also, UMMS partners with MassBiologics in scientific collaborations, technology management and creating partnerships for the development of products for the benefit of patients.  These valued partnerships help us to provide services and programs to help meet our needs at UMMS and the public.
  • Proud Contributors - People at UMMS enjoy the feeling of going to work every day knowing what they do is truly important and worthwhile.
  • Complementary and Inseparable - These varied parts of our mission and culture are complementary and inseparable.                 

Careers

UMMS, the state’s first and only public academic health sciences center, educates physicians, scientists and advanced practice nurses to heal, discover, teach and care, with compassion.  UMMS is a world-class institution with opportunities to match. 

Competitive Compensation – UMMS offers salaries that are competitive with Worcester-area employers. When combined with our generous benefits, perks, and paid time off, many job seekers are surprised to find a total rewards package that matches or exceeds their current situation.

Targeted Hiring Process – At UMMS, there are actually multiple hiring processes for different segments of our workforce.  In nearly all cases, UMMS hiring process is decentralized, with qualified candidates screened and referred to an academic officer or manager with hiring authority.

24/7 Access to Employment Opportunities – iCIMS is our online job search and application system.  iCIMS is available 24/7 to provide you with a convenient and up-to-date view of the available employment opportunities across our campuses. Updates are made daily and include all faculty and non-faculty position listings from every school and department within the UMMS. When you identify a position you are interested in and qualified for, apply online. New opportunities become available frequently so it pays to check back often!

Benefits

With outstanding benefits, competitive pay, extensive learning opportunities, and a stimulating and attractive work environment, UMMS may be exactly the employer you’ve been looking for.

• Superior Benefits - UMMS offers a wide range of benefits and perks that invite comparison with the best employers in the Worcester area – and with academic institutions anywhere. UMMS provides superior medical and dental coverage for you and your family, fully funded retirement plans, generous time off, a Tuition Assistance Plan – and much more.

• People Centered - UMMS is an employer, but it is also a community. Its comprehensive medical and dental benefits, retirement plans, and even paid holidays reflect an institution built around people, with a deep respect for their differences and needs.

• Commitment to Healthy Living - UMMS provides resources to help you balance work and life and encourages healthy living through great programs and discounts for fitness, physical activity, weight management, nutritional counseling and general wellness available through our health insurance plans.

• Breadth of Offerings - Above all, the breadth of UMMS offerings set the School apart and makes it an environment favored by all sorts of smart, career-savvy people.

Apply for a Job

As an equal opportunity and affirmative action employer, UMMS recognizes the power of a diverse community and encourages applications from individuals with varied experiences, perspectives and backgrounds.

Online - To view all job opportunities and apply online, visit www.umassmed.edu/hr and click on the “Careers” tab.

Start Now and Realize Your Opportunities!

A History of Making Vital Improvements - UMASS Medical School Milestones

1962: Legislation establishes University of Massachusetts Medical School
1970: First medical students begin classes in Shaw Building
1974: First class graduates 16 MDs
1979: PhD program begins
1986: Graduate School of Nursing opens
1986: PhD program becomes Graduate School of Biomedical Sciences
1994: Graduate School of Nursing initiates PhD program
1998: UMass Clinical System and Memorial Health Care merge to form UMass Memorial Health Care
2001: Lazare Research Building opens
2002: Campus Modernization begins on the University Campus
2004: Graduate Entry Pathway Program established at the Graduate School of Nursing
2005: PhD Program in Clinical & Population Health Research established at the Graduate School of Biomedical Sciences
2005: Massachusetts Biologic Laboratories opens new manufacturing and filling facility in Mattapan
2006: Craig Mello, PhD, Blais University Chair in Molecular Medicine and Howard Hughes Medical Institute Investigator, is awarded the Medical School's first Nobel Prize. Dr. Mello shared the 2006 Nobel Prize in Physiology or Medicine with Andrew Fire, PhD, of Stanford University, for their discoveries related to RNA interference.
2007: Michael F. Collins, MD, is named chancellor and Terence R. Flotte, MD, is named dean of the School of Medicine.  
2009: Groundbreaking for the Albert Sherman Center, a 500,000-square-foot research and education facility slated for completion in 2012.
2010: Ambulatory Care Center opens
2012: The Albert Sherman Center, a 500,000-square-foot research and education facility, completed and opens

Get job alerts

Create a job alert and receive personalized job recommendations straight to your inbox.

Create alert