Vanderbilt University Medical CenterVC

FISMA Support / IT Risk Analyst (Remote Available)

Apply now

Discover Vanderbilt University Medical Center: Located in Nashville, Tennessee, and operating at a global crossroads of teaching, discovery, and patient care, VUMC is a community of diverse individuals who come to work each day with the simple aim of changing the world. It is a place where your expertise will be valued, your knowledge expanded, and your abilities challenged. Vanderbilt Health recognizes that diversity is essential for excellence and innovation. We are committed to an inclusive environment where everyone has the chance to thrive and where your diversity of culture, thinking, learning, and leading is sought and celebrated. It is a place where employees know they are part of something that is bigger than themselves, take exceptional pride in their work and never settle for what was good enough yesterday. Vanderbilt’s mission is to advance health and wellness through preeminent programs in patient care, education, and research.

Organization:

VEC FISMAandSpecialCompliance

Job Summary:

The IT Risk Analyst conducts application risk assessments delivered to application and business owners under occasional guidance. Educates user community through information security training programs. Assists with incident response when issues relate to systems or regulatory matters. Establishes automated and manual monitoring of systems to detect suspect activity.

.

KEY RESPONSIBILITIES

• Conducts application focused risk assessments.
• Assists application owners with security best practices.
• Participates in incident response activities related to systems.
• Executes passive and active user training activities.

• Monitors systems for suspect behavior.

• The responsibilities listed are a general overview of the position and additional duties may be assigned.

REQUIREMENTS

• Knowledge of NIST Risk Management Framework

• Familiar with NIST Publications (NIST 800-53, NIST 800-171, NIST RMF, FISMA / FedRAMP)

• Security + certification (Required)

TECHNICAL CAPABILITIES

• Risk Assessment (Novice): Demonstrates familiarity with professional risk assessment processes and understands risk prioritization. Evaluates risks with an eye toward regulatory concerns while staying aware of current attack vectors. Identifies viable mitigation strategies that can be presented to business owners for consideration. Documents risk findings and suggested mitigations in a concise manner that can be clearly communicated to stakeholders.
• Regulatory Awareness (Novice): Demonstrates knowledge of healthcare regulations and security best practices. Identifies appropriate sources of governmental and industry guidance. Interprets regulations and guidance to assist application and business stakeholders with compliance and security best practice efforts.
• Security Control Knowledge (Novice): Understands and has direct familiarity with common information security technical toolsets (e.g. firewall, SIEM, IPS, vulnerability scanner, etc.). Demonstrates knowledge of non-technical controls (e.g. physical and administrative). Able to effectively communicate with teams directly administering controls to identify suitable responses to identified risks.
• User Training (Novice): Conducts formal, ad-hoc, and covert user training activities. Effectively communicates security risks to users of every skill level. Utilizes technical toolsets to aid and report on the training process (e.g. LMS, phishing campaigns, etc.)
• Incident Response (Novice): Understands incident response processes and is able to work in a professional manner during an incident. Serves as a liaison between technical and non-technical parties. Has an understanding of the forensic process and is able to identify appropriate skillsets necessary to handle investigative activity.

Our professional administrative functions include critical supporting roles in information technology and informatics, finance, administration, legal and community affairs, human resources, communications and marketing, development, facilities, and many more.

At our growing health system, we support each other and encourage excellence among all who are part of our workforce. High-achieving employees stay at Vanderbilt Health for professional growth, appreciation of benefits, and a sense of community and purpose.

Core Accountabilities:

Organizational Impact: Executes job responsibilities with the understanding of how output would affect and impact other areas related to own job area/team with occasional guidance. Problem Solving/ Complexity of work: Analyzes moderately complex problems using technical experience and judgment. Breadth of Knowledge: Has expanded knowledge gained through experience within a professional area. Team Interaction: Provides informal guidance and support to team members.

Core Capabilities :

Supporting Colleagues:- Develops Self and Others: Invests time, energy, and enthusiasm in developing self/others to help improve performance e and gain knowledge in new areas.- Builds and Maintains Relationships: Maintains regular contact with key colleagues and stakeholders using formal and informal opportunities to expand and strengthen relationships.- Communicates Effectively: Recognizes group interactions and modifies one's own communication style to suit different situations and audiences. Delivering Excellent Services:- Serves Others with Compassion: Seeks to understand current and future needs of relevant stakeholders and customizes services to better address them.- Solves Complex Problems: Approaches problems from different angles; Identifies new possibilities to interpret opportunities and develop concrete solutions.- Offers Meaningful Advice and Support: Provides ongoing support and coaching in a constructive manner to increase employees' effectiveness. Ensuring High Quality: - Performs Excellent Work: Engages regularly in formal and informal dialogue about quality; directly addresses quality issues promptly.- Ensures Continuous Improvement: Applies various learning experiences by looking beyond symptoms to uncover underlying causes of problems and identifies ways to resolve them. - Fulfills Safety and Regulatory Requirements: Understands all aspects of providing a safe environment and performs routine safety checks to prevent safety hazards from occurring. Managing Resources Effectively: - Demonstrates Accountability: Demonstrates a sense of ownership, focusing on and driving critical issues to closure.- Stewards Organizational Resources: Applies understanding of the departmental work to effectively manage resources for a department/area.- Makes Data Driven Decisions: Demonstrates strong understanding of the information or data to identify and elevate opportunities. Fostering Innovation:- Generates New Ideas: Proactively identifies new ideas/opportunities from multiple sources or methods to improve processes beyond conventional approaches.- Applies Technology: Demonstrates an enthusiasm for learning new technologies, tools, and procedures to address short-term challenges.- Adapts to Change: Views difficult situations and/or problems as opportunities for improvement; actively embraces change instead of emphasizing negative elements.

Position Qualifications:

Responsibilities:

Certifications:

CompTia Security+ - Licensure-Others

Work Experience:

Relevant Work Experience

Experience Level:

2 years

Education:

Bachelor's

Vanderbilt Health recognizes that diversity is essential for excellence and innovation. We are committed to an inclusive environment where everyone has the chance to thrive and to the principles of equal opportunity and affirmative action. EOE/AA/Women/Minority/Vets/Disabled

Elevate your application

Let our AI craft your perfect cover letter and align your resume to this job's criteria.

By using our AI tools, you consent to sharing your profile with our AI partner for this purpose.

Apply now

Please let Vanderbilt University Medical Center know you found this job on Himalayas. This helps us grow!

Apply now

About the job

Apply before

Aug 29, 2024

Posted on

Jun 30, 2024

Job type

Full Time

Experience level

Entry-level

Location requirements

Hiring timezones

United States +/- 0 hours

About Vanderbilt University Medical Center

Learn more about Vanderbilt University Medical Center and their company culture.

View company profile
Claim this profileVanderbilt University Medical Center logoVC

Vanderbilt University Medical Center

View company profileVisit vumc.org

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

28 remote jobs at Vanderbilt University Medical Center

Explore the variety of open remote roles at Vanderbilt University Medical Center, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Vanderbilt University Medical Center

Remote companies like Vanderbilt University Medical Center

Find your next opportunity by exploring profiles of companies that are similar to Vanderbilt University Medical Center. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join thousands of other remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan