Compliance Security Specialist Job in Baltimore, Maryland US

Compliance Security Specialist

The Compliance Security Specialist is responsible for providing support in the area of information security assurance. The CSS must have familiarity with performing administrative and technical audits, monitoring mitigation efforts and enforcing organizational compliance. The CSS should have a working knowledge of Federal and State regulations related to business, finance and healthcare including: Health Insurance Portability and Accountability Act (HIPAA), Health Information Technology for Economic and Clinical Health (HITECH) Act, Payment Card Industry (PCI), Graham-Leach-Bliley (GLB) and Sarbanes-Oxley (SOX). The CSS must have a background in systems security review and information security management. Essential Job Functions Designs audits of computer systems to ensure they are operating securely and that data is protected from both internal and external attack. Makes recommendations for preventive measures as necessary. Assesses assigned system to determine system security status. Designs and recommends security policies and procedures to implement; ensures compliance to policies and procedures. Designs training materials for computer security education and awareness programs. Evaluates highly complex security systems according to industry best practices to safeguard internal information systems and databases. Defines and reviews security requirements and subsequently reviews complex systems to determine if they have been designed and established to comply with established standards. Leads investigations of security violations and breaches and recommends solutions; prepares reports on intrusions as necessary and provides analysis summary to management. Responds to more complex queries and request for computer security information and reports from both internal and external customers. Provides technical consultation on highly complex tasks; may assist and/or provide limited direction to lower level technical personnel. Provides product recommendations of security packages to customers; Reviews vendor products and makes recommendations as appropriate. Conducts cost analyses to determine feasibility of new products for clients. Qualifications Basic Qualifications Bachelor's degree or equivalent combination of education and experience Bachelors degree in computer science, management information systems, or related field preferred CISSP certification preferred Seven or more years of experience in computer science, management information systems, or data security experience Experience working with information security practices, networks, software, and hardware Experience working with computer programming Experience working with operating systems Experience working with computer desktop packages such as Microsoft Word, Excel, etc. Experience working with security architecture Other Qualifications One or more of the following security certifications are required: CISSP, CISA, CISM or SSCP Experience with administrative and technical assessments as well as enforcing organizational compliance Understanding of security practices and procedures; knowledge of security tools and outputs; implementation of security for hardware/software; network communication protocols and encryption tools/techniques Excellent recordkeeping and attention to details Working knowledge of information security principles and best practices Familiarity with National Institute for Standards and Technology (NIST) special publications pertaining to information security assurance including SP800-30, SP800-53, SP800-66 and SP800-122 Strong analytical and problem solving skills for resolving security issues Good organization skills to balance work and lead projects Basic leadership skills to effectively mentor and lead junior level personnel Good interpersonal skills to interact with customers and team members Strong communication skills to interact with team members and support personnel Strong skills implementing and configuring networks and network components Ability to work with relational databases Ability to work in a team environment