Last year our HCA Healthcare colleagues invested over 156,000 hours volunteering in our communities. As a(an) Consulting Security Analyst with Galen College of Nursing you can be a part of an organization that is devoted to giving back!
Job Summary and Qualifications
Consulting Security Analysts are responsible for performing a wide range of tasks that support the ongoing maturation of the IPS program, including: driving consistency and visibility of IPS risk management activities; working with business owners to protect customers and prevent data loss; providing guidance and consultation to colleagues at every level to reduce or eliminate risky behaviors; and consult and support IT teams to implement, validate, and tune security controls in alignment with company standards. They are responsible for helping workforce members appropriately comply with the company’s IPS requirements while balancing customer care, business objectives, and technical realities.
This role requires extensive focus on building and expanding relationships with key stakeholders who support IPS objectives and activities. IPS Consulting Security Analysts are tasked with complex work efforts, requiring them to leverage their IT, security, risk management, and business experience to address IPS program deficiencies while meeting customer care and business needs. This position blends cybersecurity consulting and risk management with system, infrastructure, and security engineering support to help business and IT teams reduce risk and improve control maturity.
The IPS Consulting Security Analyst must have a combination of written and verbal communication skills, interpersonal skills, the ability to influence, guide, and/or lead others necessary to accomplish IPS goals, and the technical capability to assist IT teams with the implementation, configuration, and tuning of security controls.
Risk Management and Security Consulting
- Coordinate and perform risk assessments using corporate-provided tools and templates.
- Work with local leaders to assess, submit and approve exceptions to IPS standards while working with them to implement controls to mitigate risk and remediate as able.
- Drive and manage execution of corrective and risk treatment plans in concert with Cyber Issues Management to address deficiencies identified during risk assessments.
- Assist the DISA in ensuring that designated committees (e.g., Security Committee, Ethics & Compliance Committee) receive, document, track, investigate, and sponsor remediation of security control deficiencies, suspected IPS incidents, and complaints.
- At the direction of the DISA, provide education and guidance to ensure designated committees make informed, risk-based decisions necessary to balance business needs and security objectives.
- Perform Security Risk Analysis (SRA) to validate that required security controls are in place to drive ongoing compliance with IPS policies, standards, and operational procedures.
- Lead audit response activities to address IPS issues identified by internal or external auditors.
- Serve as an internal security consultant across business units to provide technical security consultation on appropriate controls that balance business and security requirements.
- Translate security standards and regulatory requirements into actionable technical and business requirements.
- Evaluate and recommend security solutions that balance risk mitigation with business functionality.
Security Engineering and Control Enablement
- Work with Corporate IPS / Centralized Architect Team to identify appropriate security controls as part of the field intake process and provide assurance that the required security controls are implemented, configured, and working as designed.
- Assist IT teams in the implementation, configuration, validation, and tuning of security controls.
- Evaluate new and proposed security technologies and assist in their integration.
- Assist in the design and implementation of secure network, application, and system architectures.
- Partner with IT colleagues to assure ongoing maturity of IT operational security controls.
- Partner with appropriate stakeholders on vulnerability remediation.
- Lead and support the IPS program by assessing new applications and technologies and ensuring they are implemented in accordance with company standards.
- Engage in Architecture Review Committee discussions to identify and address Third Party solution variance from company standards.
- Provide hands-on support for corporate-driven security efforts, as appropriate.
- Participate in the development, documentation, and testing of Disaster Recovery (DR) and contingency plans.
Issues Tracking and Resolution
- Support, coordinate, and manage non-technical cyber security event/incident response investigation activities (i.e., Lost/Stolen Devices, Privacy RI, E&C).
- Investigate information leaving the organization with appropriate leadership (i.e. Manager, ECO, HR, Legal) in support of Data Loss Prevention (DLP).
- Coordinate with HR Director, Facility Privacy Official and Ethics & Compliance Officer to ensure that sanctions related to IPS issues are applied appropriately and consistently.
- Perform follow-up education and consultation with workforce members exhibiting risky behaviors and/or behaviors that violate Company IPS policies and standards.
- Partner with corporate and local departments as required to facilitate rapid response to cybersecurity events and determine appropriate technical mitigations as necessary.
- Coordinate Cyber Defense Center (CDC), MSSP, and Cyber Problem Effort and Resiliency (CPER) response efforts and report on progress.
- Augment IT response capabilities by providing hands-on technical support and remediation guidance, where appropriate.
- Manage operational processes that monitor and respond to potential security threats.
Execution
- Provide ad hoc IPS guidance and consultation to all types and levels of workforce members and colleagues that balances business and security requirements.
- Educate ITG colleagues on security policies and standards to help ensure compliance.
- Facilitate, and lead where appropriate, proactive IPS communication and awareness activities including coordinating with HR and training departments to ensure that periodic workforce training includes company-required IPS content.
- Coordinate development, documentation and testing of Disaster Recovery (DR) plans.
- Assist the Division DISA in supporting and driving enterprise and division IPS projects and security efforts to a successful end and ensure that required processes are adopted and maintained.
- Lead and coordinate implementation and adoption of technology and process changes.
- Maintain awareness of emerging threats, vulnerabilities, and mitigation techniques.
- Drive targeted security risk reduction within IT.
Vendor Systems Security
- Collaborates with system business owners to ensure vendor contracts are in place for department and IT systems and services.
- Work with appropriate business, IT, supply chain, and corporate IPS stakeholders to help ensure specific systems, services, and devices receive proper security assessments and remediation.
- Work with business, purchasing, and IT stakeholders to ensure proper controls are in place for existing vendor-maintained solutions.
- Support IT, system business owners, and vendors to document system vulnerabilities and document mitigation controls or remediation actions.
- Support IT to ensure vendor systems use approved connectivity, remote management and monitoring.
- Support IT to remediate security vulnerabilities in response to vendor security events.
- Performs other duties as assigned
- Practices and adheres to the “Code of Conduct” philosophy and “Mission and Value Statement.”
What qualifications you will need:
- Bachelors Degree and seven or more years of experience in a relevant field required
- High School Graduate/Equivalent and 14+ years of experience in a relevant fieldRequired
- Seven or more years experience in security, risk management, information security domains. infrastructure/security engineering ptrfrttrf
- Master's Degree preferred
Licenses, Certifications, & Training:
- Advanced ISC(2), ISACA, GIAC, EC-Council, Offensive Security or other relevant certification types in information security, or cyber risk management preferred
- Up to 25% travel
Knowledge, Skills, Abilities, Behaviors:
- Experience in developing and assessing technical and process-based controls, managing risk assessments/investigations, and working with organization management to integrate controls into the scope of existing business practices. Required
- Working knowledge of information security concepts, including risk management, engineering, networking, and cloud. Required
- Understanding of cloud fundamentals and concepts, as well as experience with a popular cloud provider, like Microsoft, Google, or Amazon. Required
- Knowledge of information security regulations (FERPA, HIPAA Privacy/Security, SOX IT, PCI) Required
- Experience in some combination of audit, risk management, information security, privacy, and information technology. Required
- Knowledge of supported operating systems, utilities, vendor products, applicable communications protocols, and hardware configurations. Required
- Experience supporting implementation, configuration, or tuning of technically complex infrastructure or security solutions across platforms and components. Required
- Excellent written and oral skills. Required
- Possesses the ability to build and maintain positive team relationships at all levels of the facility, market, and corporate levels. Required
- Possesses a sense of responsibility and accountability and takes ownership and initiative. Required
- Creative thinker, always looking for a “better way” to deliver value; not stopped or discouraged by adversity. Required
- Demonstrates respect for diversity of experience, characteristics, viewpoints, and opinions. Required
- Maintains professional demeanor, appearance, and positive attitude. Required
- Adaptable and flexible, with the ability to handle ambiguity and sometimes changing priorities. Required
Benefits
Galen College of Nursing, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
- Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
- Wellbeing support, including free counseling and referral services
- Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
- Savings and retirement resources, including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
- Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
- Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts
Learn more about Employee Benefits
Note: Eligibility for benefits may vary by location.
HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"There is so much good to do in the world and so many different ways to do it."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
Be a part of an organization that invests in you! We are reviewing applications for our Consulting Security Analyst opening. Qualified candidates will be contacted for interviews. Submit your application and help us raise the bar in patient care!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.