Job Description
Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant you will be a key advisor for IBM’s clients analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.
Your Role and Responsibilities
Staff run and maintain the security program based on DHCS requirements provided to IBM as documented within Appendix R:
1) Migrate and transition services from the current security office to IBM
2) Ongoing security risk analysis
3) Update and maintain all security policy and procedure documents in accordance with the in-scope regulatory requirements (such as HIPAA FIPS FISMA FedRamp State of California Privacy Laws)
4) Perform business and security impact analysis on all application development SDN’s or other appropriate change vehicles that meet the requirements as defined in the State SDLC process (Based on Secure by Design for infrastructure and applications)
5) Third party risk management
6) Update and maintain security policy and procedure based on NIST Cyber Security Framework (NIST CSF)
Required Technical and Professional Expertise
Qualifications: shall have a minimum of five (5) years’ experience in computing or related area with a focus on information security technology management and policy; experience in the development and implementation of planning security policy procedure and/or safeguards; extensive knowledge of security administration and computer security tools; successful experience in retrieving analyzing reporting addressing and /or tracking security intrusions and vulnerabilities; demonstrated knowledge in systems design development documentation testing implementation and/or maintenance; demonstrated ability to work effectively with technical and non-technical managerial and professional staff.
In addition the ISO shall possess the following:
- A minimum of two (2) years additional management experience in a government or private sector healthcare payer claims payment processing or in an MMIS environment may substitute for the degree on a year-for-year basis) in Computer Science Computer Information Systems Management Information Systems Business Administration Public Policy Law or a related field;
- Three (3) or more years’ experience in at least three (3) of the following domains in the Certified Information Systems Security Professional certificate:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management (IAM)
- Security Assessment and Testing
- Security Operations
- Software Development Security
- Proven technical and functional problem solving tracking and resolution skills;
- Ability to manage complex projects;
- Excellent verbal written and presentation communications skills.
- Experience in technology management or information security in both government and healthcare environments; and
- One or more of the following certifications:
- CISM (Certified Information Security Manager)
- GIAC (Global Information Assurance Certificate)
- SSCP (Systems Security Certified Practitioner)
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
Preferred Technical and Professional Expertise
Qualifications: shall have a minimum of seven (7) years’ experience in computing or related area with a focus on information security technology management and policy; experience in the development and implementation of planning security policy procedure and/or safeguards; extensive knowledge of security administration and computer security tools; successful experience in retrieving analyzing reporting addressing and /or tracking security intrusions and vulnerabilities; demonstrated knowledge in systems design development documentation testing implementation and/or maintenance; demonstrated ability to work effectively with technical and non-technical managerial and professional staff.
In addition the ISO shall possess the following:
- A minimum of four (4) years additional management experience in a government or private sector healthcare payer claims payment processing or in an MMIS environment may substitute for the degree on a year-for-year basis) in Computer Science Computer Information Systems Management Information Systems Business Administration Public Policy Law or a related field;
- Five (5) or more years’ experience in at least three (3) of the following domains in the Certified Information Systems Security Professional certificate:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management (IAM)
- Security Assessment and Testing
- Security Operations
- Software Development Security
- Proven technical and functional problem solving tracking and resolution skills;
- Ability to manage complex projects;
- Excellent verbal written and presentation communications skills.
- Experience in technology management or information security in both government and healthcare environments; and
- Two or more of the following certifications:
- CISM (Certified Information Security Manager)
- GIAC (Global Information Assurance Certificate)
- SSCP (Systems Security Certified Practitioner)
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
Date Posted
10/04/2024
Views
0
Similar Jobs
Security Services Specialist - IBM
Views in the last 30 days - 0
The job posting is for a Security Services Specialist who will evaluate vendors cybersecurity practices identify risks and recommend mitigations The r...
View DetailsCyber Security Analyst - IBM
Views in the last 30 days - 0
The IBM Cyber Security Analyst role involves providing continuous monitoring of assets detecting intrusions and leading the response to any intrusion ...
View DetailsEntry Level Back End Developer: 2025 - IBM
Views in the last 30 days - 0
IBM offers a new era of technology with opportunities for developers to work on challenging problems create highquality software and contribute to Ope...
View DetailsData Analyst intern Summer 2025 - IBM
Views in the last 30 days - 0
The text is about IBMs approach to work focusing on digital transformation data integration and performance optimization It seeks a team player for a ...
View DetailsSoftware Engineer Austin, Texas - IBM
Views in the last 30 days - 0
The text is a job description for a backend or full stack developer position on the Power Hybrid Cloud development team The role requires strong techn...
View DetailsZ-Stack Hardware Brand Specialist - IBM
Views in the last 30 days - 0
The job description is for a Brand Sales Specialist at IBM responsible for developing relationships with clients understanding their needs and showcas...
View Details