Information Security Policy Business Consultant Job in Aurora, California US

Information Security Policy Business Consultant

The Information Security Policy Business Consultant plays a critical role in the successful execution of KP's Information Security Strategy by supporting development and communication of KP's Policy instruments. This position consistently supports compliance and the Principles of Responsibility (Kaiser Permanente's Code of Conduct) by maintaining the privacy and confidentiality of information, protecting the assets of the organization, acting with ethics and integrity, reporting non-compliance, and adhering to the applicable federal, state and local laws and regulations, accreditation and licenser requirements (if applicable), and Kaiser Permanente's policies and procedures. Under direction of the Director, Security Governance and Risk Management: - Facilitate processes related to Information Security Policy and Standards development and governance: - Support development of Information Security Policy instruments, including Business and Technical Security Standards. - Support development of implementation and communications plans for new and revised policies and standards. - Support the operation of Information Security Policy monitoring programs. - Advise operational teams regarding use of standards for development of security-related procedures. - Manage the repository of Policy instruments. - Support the activities of the Information Security Policy and Standards Focus Team as appropriate. - Support the coordination of responses to Health Plan customer groups related to KP security practices. - Provide support as needed to IT Compliance in collecting evidence related to security practices for internal and external audit reviews. Working Relationships: - KP Information Security Leaders - KP IT Functional Areas - National Compliance Office - Business Information Officers - Regional Privacy and Security Compliance Officers - National and Regional Membership Account Teams Qualifications: Basic Qualifications: - Bachelor's degree in related field and/or 4 years of equivalent experience - A minimum of12 years of experience in analysis of business processes and business case development to support IT solutions. - Professional certification(s) desired (CISSP, CISM, and/or CISA) - Basic understanding of healthcare, financial analysis, and demonstrated competencies in teamwork, customer service, analytical and organizational skills - 5 or more years of experience working as an IT or technical communication professional with an emphasis on production of deliverables such as policies, standards, and procedures. In addition, the ideal candidate will have 3 or more years experience (may be concurrent) producing deliverables related to the policy and technical aspects of information security disciplines and governance - Experience with CobiT, ISO27002, ITIL, FFIEC, GLBA, HIPAA, etc. - Experience with GRC or policy management methodologies, tools and enablers in the financial services or healthcare sector (e.g., Agiliance, Archer, BWise, BPS, Chase Cooper, Paisley, etc.) - Strong thought leadership in technical communication - Strong project management skills - Advanced written and verbal communication and presentation skills with the ability to produce deliverables requiring minimal editing - Excellent leadership, teamwork and client service skills - Demonstrated integrity within a professional environment - Ability to work independently in a dynamic environment