Information Security Specialist

Partners Consulting, Inc.
  • Philadelphia, PA
  • Instant Apply
2 days ago

Job Description

Title:Information Security Specialist – Level 3
Location:Philadelphia, PA (hybrid)
Type: Contract
 
Our direct client is seeking a InfoSec Specialist with demonstrated experience leading security design for new technologies across the full lifecycle, from initial evaluation through implementation. The ideal candidate has technical experience with security logging and security monitoring technology (i.e. security incident and event management technology, managed detection and response technology, etc.), Microsoft technology experience, experience working with Managed Security Service Providers (MSSPs) and Cloud providers, and experience with managing governance over security initiatives, such as security logging governance.
 
The InfoSec Specialist must be able to work independently and draw upon extensive professional knowledge and experience to make independent judgement regarding analysis, evaluation, development, and implementation of enterprise long-term solutions and operating initiatives. Excellent communication and documentation skills are a must.
 
The position is primarily remote; however, there is potential to come on site so local candidates highly preferred. Security certifications are preferred but not required.
 
Key Accountabilities:
  • RFP and technology evaluation: Develop or tailor security requirements and questions based on the technology being evaluated; assess vendor responses; identify security considerations and risks; and document clear, actionable recommendations.
  • Security architecture and design: Partner closely with the Security Architect to translate approved architecture, standards, and requirements into practical security designs for selected technologies.
  • Security engineering and implementation: Engineer security controls and configurations and work collaboratively with technical, application, infrastructure, vendor, and project teams through build, implementation, validation, and transition to operations.
  • Security-by-design mindset: Quickly learn unfamiliar healthcare technologies, understand their architecture and data flows, identify the security considerations that matter most, and apply appropriate controls early in the technology lifecycle.
  • Communication and collaboration: Demonstrate strong written and verbal communication skills, with the ability to explain technical security requirements and recommendations clearly to both technical and non-technical stakeholders and work effectively across multidisciplinary teams.
     
 Required Skills:
  • Bachelor's degree in Computer Science, Information Systems, or related field.
  • At least twelve (12) years of industry-related experience, including experience in one to two IT disciplines (such as technical architecture, network management, application development, middleware, information analysis, database management, or operations) in a multitier environment.
  • At least six (6) years of experience with information security, regulatory compliance and risk management concepts.
  • At least three (3) years of experience with Identity and Access Management, user provisioning, Role-Based Access Control, or control self-assessment methodologies and security awareness training.
  • Experience with Cloud and/or virtualization technologies.
  • Comprehensive knowledge and understanding of Information Security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.
  • Knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, and ISO 27000 series).
  • Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.
  • Good knowledge of basic database query techniques and data mining to analyze data or other related database functionality.
  • Knowledge of Microsoft Active Directory, UNIX, and Clinical applications is a plus.
  • Experience implementing application-level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience is a plus.
  • General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.
  • Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, and Project).
  • Experience with risk management frameworks.
  • Ability to understand and comply with all enterprise and IS departmental information security policies, procedures, and standards.
  • Demonstrates specialized and comprehensive knowledge in Information Security management practices, disciplines, regulations, industry standards, related frameworks, project management principles and methodologies, security engineering concepts, security operations model, and industry standards around architecture principles.
  • Demonstrates exceptional skills in managing multiple projects and priorities in order to meet strategic goals and timelines.
  • Exhibits the ability to plan, manage, and implement highly complex enterprise architecture and security implementations, enhancements, or modifications that require in-depth knowledge across multiple technical areas and business segments.
  • Exhibits exceptional understanding of emerging regulatory and healthcare issues in order to develop internal and external checks and controls to ensure proper governance, security and quality of information assets.
  • Demonstrates exceptional troubleshooting and collaborative skills required to identify, analyze and resolve complicated security issues.
  • Demonstrates advanced proficiency in creating detailed documentation, performing budget planning and oversight, and providing input on infrastructure strategic planning, technology standards, and information security and risk practices.
  • Exhibits ability to communicate effectively with clients, colleagues, vendors, and management and the ability to translate complex technical solutions into non-technical requirements documents.
  • Performs planning, development, implementation, and delivery of enterprise architecture and engineering principles for new, existing, and future strategic and operational activities.
  • Demonstrates the ability to provide technical expertise and consultation to the CIO, CTO, CISO, executive leadership, and other business and clinical leaders.
  • At least three (3) years of experience working with matrixed high-performance teams is preferred.



Partner's Consulting is an award-winning IT Consulting and Recruiting firm based in the Philadelphia area. We’ve built personal relationships with our clients over many years and work directly with decision makers on all open positions. Our core values are focused on the highest level of professional dedication to our client's requirements coupled with our desire to partner with highly qualified talent for joint success.
 
 
37712024

Numbers & Facts

LocationPhiladelphia, PA

Skills

  • Access Controlunmatched
  • Analysis Skillsunmatched
  • Applications Securityunmatched
  • Bid Analysisunmatched
  • Budget Managementunmatched
  • Change Controlunmatched
  • Change Managementunmatched
  • Clinical Information Systemsunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Consultingunmatched
  • Cross-Functionalunmatched
  • Customer Relationsunmatched
  • Data Analysisunmatched
  • Data Miningunmatched
  • Data Qualityunmatched
  • Database Administrationunmatched
  • Documentationunmatched
  • ERP (Enterprise Resource Planning)unmatched
  • Enterprise Architectureunmatched
  • Enterprise Protectionunmatched
  • Epic Systemsunmatched
  • Financial Systemsunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Healthcareunmatched
  • ISO (International Organization for Standardization)unmatched
  • Identify Issuesunmatched
  • Identity Data Managementunmatched
  • Industry Standardsunmatched
  • Information Assetsunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology Consultingunmatched
  • Information/Data Security (InfoSec)unmatched
  • Intranetunmatched
  • Leadershipunmatched
  • Local Area Network (LAN)unmatched
  • Maintain Complianceunmatched
  • Medical Record Systemunmatched
  • Microsoft Access Databaseunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft PowerPointunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Visiounmatched
  • Microsoft Wordunmatched
  • Middlewareunmatched
  • Multitaskingunmatched
  • Network Architecture/Engineeringunmatched
  • Network Management Softwareunmatched
  • Operational Strategyunmatched
  • PCIunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Project/Program Managementunmatched
  • Protective Servicesunmatched
  • Regulationsunmatched
  • Riskunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • Security Architectureunmatched
  • Security Designunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Software Developmentunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Strategic Planningunmatched
  • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
  • Team Playerunmatched
  • Technical Writingunmatched
  • Technology Analysisunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Unix Operating Systemsunmatched
  • Vendor/Supplier Evaluationunmatched
  • Virtualizationunmatched
  • Wide Area Network (WAN)unmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder