Under the strategic direction of the AVP of IT&S, support and accelerate the information security program and cloud computing strategies and initiatives. Maintain and continuously improve security-related operational metrics that support strategic plans. Develop and manage a more streamlined IS&T change management process to deliver quality solutions aligned with strategic initiatives in collaboration with department liaisons. Continuously assess healthcare-related technology and the effectiveness of current information security solutions. Stay apprised of current information security trends and risks to ensure compliance and mitigate vulnerabilities. Establish processes and methodologies to ensure effective use of current technology solutions, with a future focus on cloud computing support strategy. Have the hands-on ability to assess and assist with managing a VMWare server, storage, or network environment. Provides leadership in developing a more robust security awareness program for IS&T and end users. Develop and maintain positive working relationships with a wide-ranging group of executives, clinicians, business, and technical staff.
Key Job Responsibility Areas
General
Information Systems & Technology
Information Security
IT Security Leadership
Project Management
Miscellaneous
Detail of Key Job Responsibility Areas
General
Serve as an IS&T technical team leader, with a strong focus on IT security, on all project and operational discussions, that can be at an operational or strategic level.
Possess current hands-on technical skills and knowledge of IT systems and technology (e.g., network, servers, storage) to identify issues or mitigate assessment findings related to IT security.
Identify solutions with practical applications to enhance Trillium's IT security posture and processes to provide a more secure environment.
Strong communication skills (listening, written, and verbal) with the ability to communicate effectively with staff of varying technical expertise.
Relationship Building: Internal and external rapport with all team members, objectivity, credibility, confidentiality, proactivity, responsiveness, teamwork, and mutual respect.
Demonstrable ability to independently prioritize and manage own and others' time efficiently, including meeting target dates without overlooking critical tasks or issues needing resolution.
Information Systems & Technology
Identify and assess opportunities for innovation and advances with new technology solutions and services that directly support clinical and business objectives.
Implement and facilitate a robust technology change management system and process between IS&T and the departments.
Responsible for managing the data security associated with the backup and recovery software and data on-premises and in the cloud.
Benchmarks industry standards to stay current with trends regarding information technology and its use inside and outside of healthcare.
Participates in organization-wide planning activities to ensure information technology investments support the business plan and other tactical and operational priorities.
Effectively manages and leverages information technology vendor relationships to maximize the organization's value, including vendor performance and adherence to contract terms and conditions.
Promotes effective, open communication and develops collaborative working relationships with all levels of staff, clinicians, educators, researchers, and leadership.
Demonstrated ability to translate complex technical concepts into impactful statements for various audiences and levels of sophistication
Contributes to enterprise-wide committees, task forces and performance improvement teams.
Assist in the development and accountability for monitoring KPIs to ensure that the quality and delivery of IT services meet desired targets.
Stay current and knowledgeable regarding IT security-related technological advances in the industry, including maintaining an expert understanding of national initiatives such as interoperability, digital health, and telemedicine. Work with IS&T Leadership to recommend a strategic course of action.
Develop an appropriate cloud computing application and information security risk strategy.
Information Security
In partnership with the Associate Vice President, Information Systems and Technology:
Works to build and maintain a strong information systems control environment responsive to the risks across all aspects of the organization’s information technology environment.
Ensure that all systems, assets, and data are protected and subject to appropriate security reviews and independent security assessments.
Collaborate with the business teams to envision and maintain the information security strategy.
Formulate an information security governance framework based on a nationally recognized catalog of security and privacy controls (e.g., NIST 800-53 rev. 5, CMMC).
Accountable for the operations of an information security program to ensure the day-to-day activities required to carry out the information security strategy, including annual risk assessments, PCI DSS certification, and other applicable local, state, federal, and contractual requirements.
Maintain information security policies and procedures that accurately reflect the organization's current practices.
Participate in the Security Governance Committee with the business leadership to propose, ratify, and document information security policy.
Participate in the organization’s risk management functions through the information security governance committee.
Maintain competency concerning industry regulations, best practices and any industry-specific control frameworks required to mitigate risk.
In conjunction with the compliance functions of the organization, participate in any information security audits.
Infrastructure Systems Security: in partnership with the Supervisor of Information Systems and Infrastructure Support:
Maintain IT Security competence concerning the industry's best practices in data center operations, server management, storage, telecommunications, firewalls, and network management.
Assist with projects and maintain a future state vision supporting infrastructure from an IT Security best practices perspective.
IT Security Leadership
Participate in hiring, managing, coaching, and developing an Information Security Awareness program for Trillium users and IS&T staff members.
Participate in weekly IS&T team project meetings to ensure input and feedback related to IT security.
Collaborate to ensure compliance with all laws and regulations.
Maintains departmental climate that attracts, retains, and motivates high-performing talent.
Develop and manage appropriate policies and procedures related to all areas of responsibility.