Security Third Party Specialist

State of OklahomaOklahoma City, OK
59d

About The Position

The Security Third Party Specialist at the Oklahoma Health Care Authority (OHCA) is responsible for ensuring compliance with state and federal regulations while supporting key security and risk management functions targeted towards supply chain and third-party risks. This position provides technical expertise, initiates security program development, manages vulnerability submissions, and vendor security metrics. It plays a critical role in evaluating third-party security documentation, maintaining related security standards, and ensuring the effectiveness of our compliance programs based on NIST 800-53r5. The Security Third Party Specialist collaborates closely with both internal and external stakeholders to mitigate risks, enhance security protocols, and maintain the integrity of organizational processes, aligning with OHCA's core values of accountability, transparency, and excellence. The successful candidate will be able to lead and develop strategies.

Requirements

  • A bachelor's degree AND
  • 3 years of professional Information Security experience, preference for being in a federal and/or healthcare environment OR
  • An equivalent combination of education and experience, substituting 1 year of qualifying graduate experience in Business or IT Security for each year of the required experience.

Nice To Haves

  • Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Health Care Compliance (CHC) Certification, Certified Information Systems Auditor (CISA), or HIPAA Certification.
  • Strong knowledge in NIST SP 800 series guidance and control standards.
  • Strong knowledge of HIPAA standards for security and privacy.
  • Strong experience with supply chain/third party governance programs in a large complex environment.
  • Work experience in a federal government and/or healthcare environment.

Responsibilities

  • Vulnerability management and monitoring; This includes understanding vulnerability management principles and technical scan reports for working with system vendors to review and develop relevant risks metric reports.
  • Provide technical expertise and analysis; Keep aware of current industry trends and news to be more proactive in efforts. Be able to handle and interpret more technical questions and information. Must be proficient in data analysis and related tools such as MS Excel to identify issues, trends, patterns, track information and other techniques to achieve objectives and craft usable report summaries. This includes skilled use of formulas, pivot tables, and principles of good design.
  • Third Party Document Reviews; Support Business Enterprise projects by providing expertise in reviewing security documentation providing comments and escalation of any issue identified as appropriate. May be required to attend project meetings to clarify comments and listen for other security concerns that may need coordination. Coordination with subject matter experts or stakeholders may be required for detailed issues and resolutions.
  • Coordinate workgroup meetings to identify, address, and drive third party risk and issues.
  • Coordinate closely with Risk and Compliance Manager to support; Communicate and coordinate effectively with teams to identify support needs.
  • Draft and Maintain Security Documentation; This includes, but is not limited to, Standards, Guidance, and Supply Chain Risk Management (SCRM) Plan related to NIST 800-161. Documents shall be reviewed annually or during significant changes for updates and maintenance. Technical concepts should be written at a level commensurate with the audience for the document.
  • Other duties as assigned.

Benefits

  • Generous state-paid benefit allowance to offset insurance premiums.
  • A wide selection of top-tier health insurance plans.
  • Optional flexible spending accounts for health care or dependent care expenses.
  • Employee Assistance Program (EAP) offering confidential support.
  • Wellness benefits, including an on-site gym and fitness center discounts.
  • 11 paid holidays annually.
  • 15 vacation days and 15 sick days in your first year.
  • Retirement Savings Plan with substantial employer contributions.
  • Longevity Bonus to reward years of service.
  • Public Service Loan Forgiveness eligibility and reimbursement for educational expenses.
  • Professional development training opportunities, including CEU support.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Industry

Administration of Human Resource Programs

Number of Employees

251-500 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service