Company

ExperisSee more

addressAddressKansas City, MO
type Form of workContractor
CategoryInformation Technology

Job description

Job Description

Experis/ManpowerGroup has partnered with a leading Construction Engineering organization in Kansas City, MO, Denver, CO, Phoenix, AZ and Minneapolis, MN for a contract with possible extension Staff info Security Specialist role to assist their team. This is an on-site role.
Industry: Construction Engineering
Title: Staff info Security Specialist
Location: Preferred- Kansas City, MO, (Secondary)-Denver, CO, Phoenix, AZ and Minneapolis,
Duration: 6 months contract with possible extension. Duration till nov 2023
Develops and maintains information security related documentation, e.g., policies, frameworks, standards, methods & procedures, executive presentations, corporate communications, and knowledge base (KB) articles.
Provide principal assistance and proactively lead coordination as Information Security Manager’s designated representative for compliance related duties, e.g., scheduled reviews of internal policies and procedures, internal audits and external audits
Provide principal assistance and proactively lead coordination as Information Security Manager’s designated representative for risk related duties, e.g., contract reviews, as well as risk assessments of newly requested software or hardware
The GRC Specialist serves as a critical resource for staff and leaders regarding information security policy implementation, interpretation, and compliance. This includes active communication with key stakeholders in Corporate Services and with Business Unit Leaders as appropriate.
The GRC Specialist assesses and prioritizes information security and cybersecurity risk across the organization, facilitates compliance with regulatory requirements and information security policies, and develops and reports on information security metrics.
Provide principal assistance and proactively lead coordination as Information Security Manager’s designated representative for governance related duties, e.g., reviews of existing documents, as well as development of newly requested documents
Provide essential support on a supplemental basis as needed and as appropriate for other key functions of the Information Security program, namely Incident Response, Vulnerability Management, as well as approved Projects or Enhancements.
The GRC Specialist is responsible for reducing information security and cybersecurity risk to client by helping to prioritize and drive remediation efforts throughout the organization through the following:
Establishing and maintaining governance and compliance standards.
Conducting risk assessments of vendor services or products, including but not limited to software, hardware, or other professional services as applicable.
Advising senior leadership on risk management strategies, including risk mitigation, risk reduction, risk transfer, the risk exception process and residual risk analysis.
Develops and implements a data security risk reporting framework, aligned with designated frameworks (ISO 27001, NIST SP 800-171, etc.) for management teams and governance committees.
Designs and documents technical, administrative, and physical controls to ensure the business demonstrates compliance, ensuring that client meets both the requirements and intent of its regulatory and compliance obligations.
Facilitates the remediation of control gaps and escalates critical issues to leadership.
Manages an exception review and approval process, and assures exceptions are documented and periodically reviewed.
Prepares for and facilitates examinations by qualified security assessors for regulations such as CMMC. Works closely with control owners and internal and external auditors to ensure requests are completed in a timely manner.
Assists with the evaluation of the effectiveness of the information security program by developing, monitoring, gathering, and analyzing information security and compliance metrics for management.
Identifies, analyzes, evaluates, and documents information security risks and controls based on established risk criteria.
Conducts security risk assessments of planned and installed information systems to identify vulnerabilities and risks.
Recommends controls to mitigate security risks identified via risk assessment process.
Communicates risk findings and recommendations that are clear and actionable by business stakeholders.
Supports workforce security activities including culture, awareness, and training.
Facilitates eDiscovery and collection of data to support investigations of possible security or policy violations. Analyzes information security incidents in collaboration with other stakeholders. Coordinates remediation and awareness training.
Researches, recommends, and contributes to information security polices, standards, and procedures. Assists with the lifecycle management of information security policies and supporting documents.
Performs third-party supplier risk assessments to ensure supply chain risk is managed throughout the supplier's lifecycle. Assesses and reports on the risks and benefits for the business as well as mandates for supplier compliance.
Articulates results of the final assessments to business stakeholders, project sponsors, program managers, and other internal parties.
Assists with review of information security sections within supplier contracts, identifies gaps, and recommends security and data privacy content to close gaps.
Maintains inventory of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities.
Education        Minimum         associate degree in healthcare, Information Technology, Business, or related field (2 years of relevant experience may be considered in lieu of degree in addition to experience below)
Preferred         bachelor’s or master’s degree in healthcare, Cybersecurity, Information Technology,
Demonstrated success performing risk assessments, writing policies to comply with governmental regulations, or implementing other key GRC functions.
Demonstrated success leading small to medium scale projects.
Preferred         5-7 years of progressively responsible experience in a healthcare setting, addressing risk and compliance with regulatory requirements (e.g., ISO 27001, SOC 2, PCI DSS, FedRAMP,).
Preferred         Advanced certifications such as HCISSP, CISSP, CEH, CISM, CISA, CCSP, and/or specific training and certification in security risk management and IT controls frameworks, such as NIST CSF and 800-53 and 800-171.
 

Refer code: 7459016. Experis - The previous day - 2023-12-28 12:11

Experis

Kansas City, MO
Jobs feed

Director of Finance Integration - Remote Opportunity

Surgery Partners

Greensboro, NC

Deputy District Attorney III

Mariposa County, Ca

Mariposa, CA

Apartment Maintenance Technician $18/hr to start

Express Employment Professionals

Colorado, United States

$18 per hour

Deputy District Attorney III

Mariposa County

Mariposa, CA

Front Desk Supervisor

Afterglow: Bronzing & Blowout Bar

Fresno, CA

Bartender PT (Fine Dining)

Table Mountain Casino Resort

Friant, CA

Bartender FT - Experience Required (Casual Dining)

Table Mountain Casino Resort

Friant, CA

Vice President of Food & Beverage

Shamin Hotels Corporate

Richmond, VA

Automation/Controls Engineer

Six Sigma/Winslow Automation Inc.

Milpitas, CA

Registered Dietitian (RD)

Hhs, Llc

Richmond, VA

$60,000 per year

Share jobs with friends

Related jobs

Staff Info Security Specialist

Mid-Level Industrial Security Specialist

Boeing

Saint Charles, MO

4 days ago - seen

IT Security Specialist

Garney Construction

Kansas City, MO

a week ago - seen

Security Specialist

Nestlé

Missouri, United States

2 weeks ago - seen

Security Specialist 2

Eastern Airlines Llc

Kansas City, MO

3 weeks ago - seen

Cyber Security Specialist #551068

State Of Missouri

$84,786 - $99,000 a year

Jefferson City, MO

4 weeks ago - seen

Target Security Specialist

Target

$17.75 an hour

Kansas City, MO

a month ago - seen

Target Security Specialist

Target

$17.50 an hour

Saint Joseph, MO

a month ago - seen

Security Risk Management Specialist

Canonical - Jobs

Kansas City, MO

a month ago - seen

Armed Security Specialist Night Shift

Liberty Defense Group

Carrollton, MO

a month ago - seen

Cyber Security Operations Specialist

Sitec Consulting

Saint Louis, MO

a month ago - seen

Cyber Security Analyst (Phishing Specialist)

Duvari Group

Fenton, MO

2 months ago - seen

Target Security Specialist

Target

$17.50 an hour

Florissant, MO

2 months ago - seen

Specialist, Physical Security

Walmart

Cassville, MO

2 months ago - seen

Sr Security Specialist

Honeywell

$63.5K - $80.5K a year

Kansas City, MO

2 months ago - seen

Target Security Specialist

Target

$17.25 an hour

Arnold, MO

2 months ago - seen

IT Cyber Security Specialist (IT Specialist)

City Of Kansas City

$5,794 - $8,833 a month

Kansas City, MO

3 months ago - seen

IT Security Specialist

Garney Construction

$61.9K - $78.3K a year

Kansas City, MO

4 months ago - seen

IT Security Specialist

Garney Construction

Kansas City, MO

4 months ago - seen