Search by job, company or skills

O

Senior Information Security Risk Analyst - Audit, GRC/CISA/CISSP

new job description bg glownew job description bg glownew job description bg svg
  • Posted 13 hours ago
  • Be among the first 10 applicants
Early Applicant

Job Description

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.

As an IT Security Risk Manager, you would support information security policies, standards, and procedures to secure and protect data. Work directly with user departments to implement procedures and systems for the protection, conservation, and accountability of proprietary, personal, or privileged electronic data.

Primary Responsibilities:

  • Perform audits to identify control gaps and implement corrective action plans
  • Ensure alignment of security policies/standards with IT infrastructure frameworks (e.g., ISO 2700x, NIST, ITIL)
  • Monitor compliance with corrective action plans, and address non-compliance issues appropriately
  • Demonstrate understanding of discovery technologies to identify system vulnerabilities (e.g. scanning tools)
  • Establish appropriate security controls based on defined data classifications to align with applicable laws/regulations/standards
  • Facilitate/lead security incident investigation
  • Analyse business requirements and ensure that solutions meet established security policies and controls
  • Maintain metrics and report them.
  • Maintain current knowledge on information security topics and their applicability program requirements
  • Communicate professionally with stakeholders/end users through multiple communication

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications:

  • Bachelor's degree or higher level of education
  • 6+ years of Information security experience
  • Experience with ISO27001 (ISMS), ISO31000 (Risk management), HITRUST CSF, NIST Cybersecurity Framework, SOC Type1/2
  • Proven auditing skills and the ability to manage risk assessments / projects independently
  • Proven excellent communication skills both verbal and written
  • Proven good presentation skills particularly ability to present technology elements in manner personnel can follow and act

Preferred Qualification:

  • CISSP, CISA or ISO27001 Lead Implementer or Lead Auditor certification

#njp

About Company

Optum, Inc. is an American pharmacy benefit manager and health care provider. It is a subsidiary of UnitedHealth Group since 2011. UHG formed Optum by merging its existing pharmacy and care delivery services into the single Optum brand, comprising three main businesses: OptumHealth, OptumInsight and OptumRx.In 2017, Optum accounted for 44 percent of UnitedHealth Group's profits and as of 2019, Optum's revenues have surpassed $100 billion.Also in early 2019, Optum gained significant media attention regarding a trade secrets lawsuit that the company filed against former executive David William Smith, after Smith left Optum to join Haven, the joint healthcare venture of Amazon, JPMorgan Chase, and Berkshire Hathaway.

Job ID: 139065767