Systems Security Officer Job in Old Saybrook, Connecticut Us

SECTION I * Position Classification Requirements
Position: Systems Security Officer (SSO)
Employment Status: Exempt
Department: Operations
Reports to: To be determined (compliance function)
Base Location: To be determined
Education: Bachelor*s Degree in Computer Science, Health Information Systems, or a related field of study.
Credentials: Security certification or working towards certification preferred: Certified Information Systems Security Professional (CISSP), Certified Information System Security Professional (CISM), Certified in Healthcare Privacy and Security (CHPS) or other related certification.

The SSO should earn a minimum of 40 hours in continuing professional education credits each year from a recognized national information systems security organization. The educational sessions at the CMS Security Best Practices Conference may be used toward fulfilling CMS business partners* continuing professional education credits. The qualifying sessions and associated credit hours will be noted on the CMS Security Best Practices Conference agenda.
Travel: Up to 25% of the time; within the U.S.
Period of Performance: Per active Contracts and/or task orders
Last Update: November 2011

SECTION II * Summary Description

The Systems Security Officer (SSO) is responsible for the on-going management of information security policies, procedures, and technical systems in order to maintain the confidentiality, integrity and availability of all Our client*s information systems. In addition, the SSO will manage the system security program and ensure the implementation of necessary safeguards to comply with contractual parameters of engagements and contracts. The SSO works independently of IT operations and will not have responsibility for operation, maintenance, or development.

Specific duties are listed below but are not intended to be an all-inclusive listing of responsibilities that are or may later be assigned. Job descriptions and duties may be modified when deemed appropriate by management. The employee is expected to perform any duties required by the Firm to insure its successful operation.

SECTION III * Duties Responsibilities

As called out by individual contracts, the SSO ensures compliance with Federal Guidance and industry best practices by:

* Facilitating the IT system security program and ensuring that necessary safeguards are in place and working.
* Coordinating system security activities throughout the project or contract organization.
* Ensuring that IT system security requirements are considered during budget development and execution.
* Reviewing compliance IAW federal policies and procedures and reporting vulnerabilities to Our client*s Corporate management and government security offices.
* Establishing an incident response capability, investigating system security breaches, and reporting significant problems to Our client*s Corporate management and where appropriate or required to business partners* and client*s Security Office.
* Validating that technical and operational security controls are incorporated into new IT systems by participating in all business planning groups and reviewing all new systems/installations and major changes.
* Ensuring that IT systems security requirements are included in Requests for Proposal (RFP) and subcontracts involving the handling, processing, and analysis of data with Confidentiality, Integrity and Availability of Moderate.
* Planning for system security enhancements or changes for potential handling of data with a CIA of High.
* Maintaining systems security documentation in the System Security Profile for review by government and external auditors.
* Completing Risk Assessments for new system development and implementation.
* Ensuring that an operational IT Systems Contingency Plan is in place and tested.
* Documenting and updating the monthly Plan of Action and Milestones (POAM).

The SSO is responsible for Our client*s Corporate system security IAW corporate policies and procedures and industry best practices. This includes:

* Developing and maintaining a Corporate Continuity of Operations Plan (COOP).
* Developing and coordinating Corporate Disaster Recovery Planning.
* Keeping all elements of the business partner's System Security Profile secure.
* Coordinating system security activities across contracts to provide a holistic security program.
* Cooperating in all official external evaluations of the business partner's system security program.
* Establishing and arranging appropriate safety and control measures with local fire, police, and health agencies for handling emergencies.

SECTION IV * Production Standards Expectations
Production and quality standards are set forth by government contracts and our client*s policy and procedure Regular evaluations will be conducted to measure work performance and ensure goals are met on a consistent basis.

* Maintains high quality work while meeting strict deadlines.
* Works as a team player, as well as independently.
* Practices effective communication when completing all tasks.
* Displays professionalism at all times. Demonstrates reliability.
* Maintains strict confidentiality of all clients and the firm*s business.
* Becomes familiar with client names and industries.
* Works hours as specified by contract obligations.
* Meets productivity standards; completes work in a timely manner; strives to increase productivity; works quickly.
* Solves practical problems and deals with a variety of concrete variables in situations where only limited standardization exists.
* Interprets a variety of instructions furnished in written, oral, diagram or schedule form.
* Demonstrates accuracy and thoroughness; looks for ways to improve and promote quality; applies feedback to improve performance; monitors own work to ensure quality.
* Follows policies and procedures; supports the organization*s goals and values.

SECTION V * Skills Qualifications
* Three (3) to five (5) years of information security experience, including program analysis, development, and testing.
* One (1) to two (2) years of health operations experience (preferred).
* Knowledge of Medicare, managed care, or insurance preferred.
* Knowledge of healthcare organization operations, ethical principles, and information systems security program elements.
* Solid knowledge of information technology and security including firewalls, VPN*s, penetration testing, intrusion detection, and other information security devices and services.
* In-depth knowledge of federal guidelines surrounding HIPAA and HITECH preferred.
* Knowledge of risk management investigation and root cause analysis processes.
* Proven analytical and research skills to define and solve problems.
* Ability to negotiate in a variety of situations and maintain objectivity and professionalism in difficult situations.
* Ability to quickly assess and prioritize multiple tasks, projects and demands.
* Ability to educate the workforce and present information to colleagues and senior leadership.
* Proven skills in interpreting and applying ethical standards; federal and state laws and regulations; rules; policies and procedures; and professional practice standards for information systems security program activities.
* Outstanding verbal and written communication skills as the SSO will be expected to draft complex documentation and present security concepts and plans to executive level personnel both internally and externally.
* Ability to develop/maintain interpersonal relationships.
* Proficient with Microsoft Office suite, including Word, Excel, PowerPoint, Project and Outlook.
* Not currently sanctioned or excluded from any program operated by Federal or State Agencies including Medicare and Medicaid.
* Must be able to pass a Background Investigation.

SECTION VI * Physical Working Conditions/Requirements
This position operates in a typical office environment. The functions of this position are performed largely at a desk utilizing typical office materials and equipment including a computer and telephone. The position requires normal physical movement and endurance and requires a high level of attention to details and the ability to make decisions based on sound judgment. The position requires the ability to handle many different projects simultaneously within time constraints. The incumbent in this position must be able to see well enough to examine reports, forms and other documents and hear and speak well enough to handle extensive telephone and interpersonal communications. The position also requires the ability to sit and work at a computer for an extended period of time and perform repetitive motion of hands periodically throughout the day.