Senior Security Consultant/Engineer - Eden Prairie, MN

Apply Now

Company: Georgia IT, Inc.

Location: Eden Prairie, MN 55347

Description:

Job Title : Senior Security Consultant/Engineer
Location : Eden Prairie, MN
Salary : DOE (salary Plus benefits)
Position Type : Fulltime
Interview : Phone

(US Citizens/ GC/GC-EAD/TN/E3/ H1B preferred)

C2C Available

Job Description

Sr. IT Security Consultant - Vendor Information Security Risk Assessment (VISRA)

Reporting to the VISRA Team, the individual will act as a liaison & SME for internal departments & vendors to successfully perform Onsite Risk Assessments in USA. We leverage HITRUST CSF Version 7.0for our program.

What are the top 5-10 responsibilities for this position?
(Please be detailed as to what the candidate is expected to do or complete on a daily basis)
  • Perform and manage Onsite Risk Assessments as per process documents
  • Ensure vendor compliance to the business agreement, policies, procedures, & regulations along with ability to map controls and compliance requirements
  • Review vendor supplied policies & procedures, internal/external assessment reports, agreements and provide feedback
  • Provision assessment reports and executive summaries with recommendations & direction regarding remediation efforts and disposition of the third party
  • Communicate, escalate, and track vendor progress on assessment remediation activities
  • Act as a liaison & SME for internal departments & vendors to successfully manage Vendor Risk Assessment
  • Understand information security risks that are inherent to a business and articulate those risks in business terms
  • Maintain current knowledge on information security topics and their applicability program requirements
  • Engage VRO regarding any delays/deviations during remediation


Software tools/skills
  • Advance level experience in MS Word, MS Excel, and MS PowerPoint etc.

Mandatory Skills/attributes
  • Experience working with senior levels of management
  • Good follow-up skills and detail oriented
  • Security expertise including knowledge on different security risk assessment frameworks (NIST/Octave), standards (ISO27001/HITRUST/ITIL/Cobit), and act such as (HIPAA/GLBA).
  • Experience in examining the SSAE 16 Audit report
  • Knowledge and understanding of different security products (web/email filtering, disk encryption, IDS/IPS, antivirus, DLP, firewall etc.)
  • Knowledge of software development methodologies, application security, and OWASP Top 10 guidelines
  • Ability to document assessment work papers and preparing assessment report
  • Ability to manage vendor assessment independently with minimal supervision
  • Strong Communication and Presentation Skills

Skills/attributes nice to have
  • Possess good project management skills

Similar Jobs