Lead Security Engineer at Remote, Remote, USA |
Email: [email protected] |
From: Navnish Kumar, Stellent It [email protected] Reply to: [email protected] Lead Security Engineer Location: Remote Interview: Phone +Skype J.D: Responsibilities: Seeking Lead Security Engineer for Remote Assignment in Washington, DC We are looking to fill a Lead Security Engineer role for th The ideal candidate has 16+ years of experience, 10+ years of experience working in IT Security for the Health and Human Services sector, 10+ years of experience managing a team of IT professionals specializing in IT Security, and 8+ years of knowledge of HIPAA, state and federal guidelines on security, transactions and security. Executive Summary: looking to hire a Lead Security Engineer who will be responsible for the organization's security program including but not limited to daily operations of the IT security program. Position Description: The Security Lead will support the District of Columbia Access System (DCAS) under the Technical Program manager to identify security vulnerabilities, design, and implement security solutions, monitor security systems, and respond to security incidents impacting DHCF on-premises and cloud hosted resources. The contractor shall provide subject matter expertise in the design, development and implementation of security best practices which includes, but is not limited to, network security, application security, access control, and security policy development. Responsibilities: Conduct security assessments and audits to identify vulnerabilities and provide recommendations for remediation of DHCF assets. Design, implement, and manage security infrastructure and tools, including firewalls, intrusion detection systems, vulnerability management systems, antivirus systems. Collaborate with IT teams to ensure security best practices are integrated into IT projects and operations for divisions providing services internally and externally. Develop and maintain security policies, procedures, and standards. Monitor security systems and respond to security incidents in a timely manner. Provide security awareness training to employees and stakeholders. Stay up to date with the latest security trends, threats, and technologies. Should have experience with Center for Medicaid Services (CMS), Internal Revenue Services (IRS) and Social Security Administration (SSA) Audits and Remediation. Deliverables: Comprehensive cybersecurity strategy document outlining short-term and long-term goals. Updated security policies and procedures manual. Regular compliance reports and documentation of security measures taken. Security assessment reports detailing identified vulnerabilities and recommended remediation strategies. Documentation of implemented security measures and configurations. Incident reports for security incidents, including analysis, containment, eradication, recovery, and lessons learned. Create a detailed implementation plan outlining the steps and timeline for deploying security solutions, configuring firewalls, intrusion detection systems, and other security tools. Integrate and configure security tools, such as SIEM (Security Information and Event Management) systems, intrusion detection systems, and vulnerability scanners, for continuous monitoring and threat detection. Develop a comprehensive incident response plan outlining procedures for identifying, containing, eradicating, recovering from, and documenting security incidents. Conduct tabletop exercises to validate the plan. Configure network security devices, including firewalls, routers, and switches, to enforce access controls, segmentation, and threat detection. Complete Remediation of all findings from audit reports and communicate with the federal agencies that conduct audit. Remote conditions: Remote with Preference for a Local Candidate from the DMV (District, Maryland, and Virginia). General skills (must have): 16+ yrs. MS Office/PowerPoint experience 10+ years of experience Knowledge and exp in state and federal information security laws, including but not limited to HIPAA, including NIST, PCI and all other regulations 8 year(s) of experience Proven expertise in presenting executive level reports on project security and compliance 8 year(s) of experience Proven track record in the successful completion of an SDLC from a security workstream standpoint 10+ years of experience Expertise translating security protocols and requirements to stakeholders and/or technical project managers 8 year(s) of experience Knowledge of project management tools - JIRA, SharePoint, Sciforma, Salesforce, MS Project (preferably) 8 year(s) of experience Proven documentation expertise for the purpose of security policy development, audit finding responses, security risks/gap analysis reports etc. 8 year(s) of experience Proven experience functioning as the prim POC for IT security audits 8 year(s) of experience Knowledge of HIPAA, state and federal guidelines on security, transactions and security 8 year(s) of experience Experience working in IT Security for the Health and Human Services sector 10+ years of experience Expience managing a team of IT professionals specializing in IT Security 10+ years of experience Expert knowledge of the MS Office Suite 10+ years of experience Proven knowledge and expertise with health care relevant legislation and standards for the protection of health information and patient security 7 year(s) of experience 16 Years of Professional Experience that Meets the requirements for a Master Level Business Systems Analyst 10+ years of experience General skills (nice to have): Healthcare Privacy and Security (CHPS) certification and/or other healthcare industry related security credentials Knowledge and/or understanding of Curam - V6 or higher (desired) 1 year(s) of experience Language skills (must have): English Native or bilingual proficiency Experience required: - **Qualifications:** - Minimum of 15 years of experience working in the field of cybersecurity. - Knowledge of federal and industry-specific regulations and compliance requirements related to cybersecurity (e.g., FISMA, HIPAA, GDPR). - Experience in preparing for and participating in security audits and assessments. - Expertise in network security, including firewalls, intrusion detection/ prevention systems, and VPNs. - Proven experience with security assessment tools and methodologies. - Proficiency in security technologies such as SIEM (Security Information and Event Management) systems and endpoint protection solutions - Experience with security monitoring tools, log analysis, and incident response procedures in Azure environments. - Strong leadership skills with the ability to motivate and manage a team effectively. - Excellent communication and interpersonal skills to work collaboratively with diverse teams and stakeholders. - Demonstrated ability to develop and implement security policies, procedures, and standards. - Experience in incident response, including conducting investigations and managing security incidents. - Strong understanding of cloud security principles and best practices. - Strong knowledge of network security, encryption, authentication methods, and security protocols. - Excellent problem-solving skills and attention to detail. - Strong communication skills and ability to work collaboratively with cross-functional teams. **Skill** | **Required /Desired** | **Amount** 16+ yrs. MS Office/PowerPoint experience | Required Bachelors degree in IT or related field or equivalent experience | Required Knowledge and exp in state and federal information security laws, including but not limited to HIPAA, including NIST, PCI and all other regulations | Required | 8 Proven expertise in presenting executive level reports on project security and compliance | Required | 8 Healthcare Privacy and Security (CHPS) certification and/or other healthcare industry related security credentials | Highly desired Proven track record in the successful completion of an SDLC from a security workstream standpoint | Required | 10 Expertise translating security protocols and requirements to stakeholders and/or technical project managers Required | 8 Knowledge of project management tools - JIRA, SharePoint, Sciforma, Salesforce, MS Project (preferably) | Required | 8 Proven documentation expertise for the purpose of security policy development, audit finding responses, security risks/gap analysis reports etc. | Required | 8 Proven experience functioning as the prim POC for IT security audits | Required | 8 Knowledge of HIPAA, state and federal guidelines on security, transactions and security | Required | 8 Experience working in IT Security for the Health and Human Services sector | Required | 10 Experience managing a team of IT professionals specializing in IT Security | Required | 10 CISSP Certification (preferred) | Highly desired Excellent communication and leadership skills | Required | 10 Expert knowledge of the MS Office Suite | Required | 10 Knowledge and/or understanding of Curam - V6 or higher (desired) | Highly desired ITIL Certification (desired) | Highly desired Proven knowledge and expertise with health care relevant legislation and standards for the protection of health information and patient security | Required | 7 Professional Experience that Meets the requirements for a Master Level Business Systems Analyst Keywords: information technology microsoft |
[email protected] View all |
Fri Nov 17 23:52:00 UTC 2023 |