Jobs
>
Kansas City

    Regulatory & Compliance, Information Security Risk Analyst - Kansas City, United States - Children's Mercy KC

    Default job background
    Description

    Thanks for your interest in Children's Mercy:

    Do you envision finding a meaningful role with an inclusive and compassionate team? At Childrens Mercy, we believe in making a difference in the lives of all children and shining a light of hope to the patients and families we serve.

    Our employees make the difference, which is why we have been recognized by U.S. News & World Report as a top pediatric hospital, for eleven consecutive years.

    Childrens Mercy is in the heart of Kansas City

    a metro abounding in cultural experiences, vibrant communities and thriving businesses. This is where our patients and families live, work and play. This is a community that has embraced our hospital and we strive to say thanks by giving back.

    As a leader in childrens health, we engage in meaningful programs and partnerships throughout the region so that we can improve the lives of children beyond the walls of our hospital.


    Overview:
    The

    Information Security Risk Analyst

    is a member of the Corporate Compliance team reporting to the Privacy Officer.

    The Information Security Risk Analyst is responsible for assessing risk to Hospital systems and data in accordance with regulatory requirements, industry standards, accepted best practices, and CM policy.

    The Information Security Risk Analyst work activities include but are not limited to:
    (1) assisting with regulatory readiness, including but not limited to privacy rounds to identify potential privacy and security concerns (2) evaluate the implementation of information security controls within the computing environment (3) coordinates risk assessment of vendor-supported systems located at CM or hosted offsite (4) assists with security audits, privacy and security investigations, and participate in incident response efforts, and prevention of security breaches (5) acts as a resource to employees regarding the HIPAA Security Rule and Hospital expectations (6) routine review of policies related to ensuring security practices are consistent with law and standards

    At Childrens Mercy, we are committed to ensuring that everyone feels welcomed within our walls.

    A successful candidate for this position will join us as we strive to create a workplace that reflects the community we serve, as well as our core values of kindness, curiosity, inclusion, team and integrity.

    Additionally, its important to us that we remain transparent with all potential job candidates.

    Because we value the safety of the patients and families we serve, as well as the Childrens Mercy staff, we want to let you know that the seasonal influenza and COVID-19 vaccines are a condition of employment for all employees in our organization.

    New employees must be willing to be vaccinated if found non-immune to measles, mumps, rubella (MMR) and chicken pox (varicella) and/or without evidence of tetanus, diphtheria, acellular pertussis (Tdap) vaccination since 2005.

    If you are selected for this position, you will be asked to supply your immunization records as proof of vaccination.

    If you and have any concerns about receiving these vaccines, medical and/or religious exemptions can be further discussed with Human Resources.


    Responsibilities:
    Information Security Risk Assessment
    Performs information security risk assessments of new systems and related processes.
    Identifies gaps, vulnerabilities, or other weaknesses in the implementation of security controls, and recommends strategies to remediate risk.

    Works with the Privacy Officer and other departments as applicable to formally document risks and align recommendations for remediation with industry-regarded best practices including ISO 27001/27002, NIST Special Publications, and HITRUST security framework.

    Reassesses risk periodically and when major changes occur within the computing environment.
    Monitoring of Information Security Controls
    Executes audit reports and analysis of employee and non-employee access to the Hospital's medical record system.
    Examines employee and third-party compliance or deficiencies regarding access policies.
    Performs continuous monitoring to verify applicable risk factors are formally documented for each system.
    Works with responsible staff to ensure issues identified through the monitoring process are addressed and corrected.

    Requests and reviews compliance status of CMs vendors and partners who are subject to GDPR, HIPAA and other applicable laws.

    Maintaining Compliance
    Develop privacy rounding report that outlines the items to be checked with a regulatory reference. Schedule privacy rounds to operational and administrative with the involvement of the manager of the area to accompany.

    Document findings, send report to the manager.

    Schedule unannounced return visit to validate any corrective actions are resolved.

    Review of HIPAA Security policies with individuals involved in the outlined process to ensure that the process is consistent with the policy.

    Inconsistencies will be addressed and memorialized in the revised policy. If applicable work with the Office of General Counsel for review of the policy changes.

    Privacy and Security Incident Response

    Work privacy and security cases in accordance with the Corporate Compliance Department investigation and resolution policies and procedures with the established HIPAA 60 day requirement.

    Effectively and professionally collaborate with other department management and Employee Relations to investigate, mitigate, and ensure appropriate corrective action has occurred prior to closing the case.

    File OCR reports when indicated.
    Tracks remediation activity as needed to ensure issues are addressed.
    Information Security Compliance Awareness, Education and Training
    Identifies staff to receive targeted information security compliance training based on issues investigated and inquiries identified.
    Communicates training requirements to Education for the delivery of information security compliance training.
    Verifies completion of information security compliance training.
    Assists with review and maintenance of HIPAA Privacy and Security intranet website content as needed.


    Qualifications:
    Bachelor's Degree Information Systems, Computer Science, or related field, and 3-5 years' experience. Combination of knowledge and technical expertise in risk assessment, auditing, data analysis, vendor management, and information systems principles and controls OR
    High School diploma, or equivalent, 5-7 years' experience. Years' of experience may be accepted in lieu of a Bachelors degree.
    Certified Information Systems Security Professional
    Employees must obtain Certified Information Systems Security Professional or equivalent within 365 days
    Certified Information Systems Security Professional (CISSP) Required 1 Year


    Starting Pay:
    Our pay ranges are market competitive.

    The pay range for this job begins at $32.26/hr, but your salaried offer will be determined based upon your education and experience.


    Remote Work/Work from Home:


    This is an intermittent remote position, which means that the person hired will work with his or her manager to determine a schedule that includes both at home and on-site hours at a Childrens Mercy location.

    The incumbent must live in the Kansas City metro area.


    EEO Employer/Disabled/Vet:


    Childrens Mercy hires individuals based on their job skills, expertise and ability to maintain professional relationships with fellow employees, patients, parents and visitors.

    A personal interview, formal education and training, previous work experience, references and a criminal background investigation all are factors used to select the best candidates.

    The hospital does not discriminate against prospective or current employees based on the race, color, religion, sex, national origin, age, disability, creed, genetic information, sexual orientation, gender identity or expression, ancestry or veteran status.

    A drug screen will be performed upon hire. Childrens Mercy is smoke and tobacco free.

    Our commitment to Diversity & Inclusion:
    CM is committed to creating a diverse and inclusive workforce. Our patients and families come from all walks of life, and so do we.

    We know that our greatest strengths come from the people who make up our team so we hire great people from a wide variety of backgrounds, not just because its the right thing to do, but because it makes our hospital stronger and our patient care more compassionate.

    If you share our values and our enthusiasm for service, you will find a home at CM.

    In recruiting for our team, we welcome the unique contributions that you can bring, including education, ideas, culture, ethnicity, race, sex, sexual orientation, gender identity and expression, national origin, age, languages spoken, veteran status, color, religion, disability and beliefs.

    #J-18808-Ljbffr

  • Lockton Companies

    Risk Analyst

    2 weeks ago


    Lockton Companies Kansas City, United States

    At Lockton, we're passionate about helping our people achieve their ultimate potential. Our people are curious, action-oriented and always striving to make ourselves and those around us better. We're active listeners working to ensure understanding and problem solvers developing ...

  • Lockton, Inc.

    Risk Analyst

    3 weeks ago


    Lockton, Inc. Kansas City, United States Full time

    Job Summary: · The Risk Analyst will develop and perform analyses to facilitate a deeper understanding of a client's expected future losses, claim trends and optimal program design, enabling our clients to make informed risk retention and risk financing decisions. · Job Responsib ...

  • Lockton Companies

    Risk Analyst

    2 weeks ago


    Lockton Companies Kansas City, United States

    At Lockton, we're passionate about helping our people achieve their ultimate potential. Our people are curious, action-oriented and always striving to make ourselves and those around us better. We're active listeners working to ensure understanding and problem solvers developing ...


  • Children's Mercy KC Kansas City, United States

    Thanks for your interest in Children's Mercy: · Do you envision finding a meaningful role with an inclusive and compassionate team? At Childrens Mercy, we believe in making a difference in the lives of all children and shining a light of hope to the patients and families we serv ...


  • TMobile Overland Park, United States Full time

    Be unstoppable with us · T-Mobile is synonymous with innovation–and you could be part of the team that disrupted an entire industry We reinvented customer service, brought real 5G to the nation, and now we're shaping the future of technology in wireless and beyond. Our work is as ...

  • Superior Bowen

    Financial Analyst

    2 weeks ago


    Superior Bowen Kansas City, United States

    The Financial Analyst role will support Haskell Lemon Group ("Haskell Lemon"), as well as our holding company, Legacy Infrastructure Group ("Legacy"). At Haskell Lemon, the financial analyst is a key position requiring a high level of financial and operational analysis. The analy ...

  • State of Kansas

    Crime Analyst I

    3 weeks ago


    State of Kansas Kansas, United States

    Employment Benefits · : Comprehensive medical, mental, dental, vision, and additional coverage · Sick & Vacation leave · Work-Life Balance programs: parental leave, military leave, jury leave, funeral leave · Paid State Holidays · Fitness Centers in select locations · Employee ...


  • Burns & McDonnell Kansas City, United States Paid Work

    Description · The Power Market Project Manager will support electric utilities in generation and power supply planning decisions, including the decisions and justifications of new generation facility construction, generation facility retirements, and facility retrofits or convers ...

  • UMB Bank

    Financial Analyst Sr

    2 weeks ago


    UMB Bank Kansas City, United States

    UMB's Capital Markets Division works with financial institutions, institutional investment clients, municipalities, public and not-for-profit organizations to deliver a full range of innovative capital solutions, including fixed income sales and trading, underwriting, and more. O ...


  • Kellanova Kansas City, United States

    The Sr. Financial Analyst plays a critical role in helping the plant make informed financial decisions by collecting, analyzing, and interpreting financial data. In this role, you will pair financial planning and analysis best practices to help business partners understand financ ...

  • Owens Corning

    Mechanic

    2 weeks ago


    Owens Corning Kansas City, United States

    Mechanic · Location(s): Kansas City, KS, US, · Function: Manufacturing Audience: Hourly Work Arrangement: On Site Requisition ID: 62438 Mechanic · Job Description · Job Title:Mechanic · Department:Maintenance · Reports to: Maintenance Leader and/or Shift Leader · Supervises:Not ...


  • Commerce Bank Kansas City, United States

    About Working at Commerce · Building a career here is more than just steps on a ladder. It's about helping people find financial safety and success, helping businesses thrive, and making sure people and their money are taken care of. And our commitment doesn't stop there. Our c ...


  • Evergy Kansas City, United States

    JOB TITLE: Project Controls Analyst · REQUISITION: TRE0010 · DEPARTMENT: · Development · LOCATION: Topeka General Office or One Kansas City Place · Topeka, KS or Kansas City, MO · PAY RANGE: Project Controls Analyst I: $51,200 - $63,700 · Project Controls Analyst II: $62,3 ...


  • North Kansas City Hospital Kansas City, United States

    SUMMARY: SUMMARY: The Senior Information Security Analyst will provide advanced technical support, lead security events investigation, and participate with various security initiations and projects. They will assist with the security reports documentation, provide support to memb ...

  • NCM Associates

    Operations Analyst

    3 weeks ago


    NCM Associates Kansas City, United States

    Job Description · Job DescriptionThe Operations Analyst is responsible for collecting, analyzing, and interpreting operation data to identify trends and areas for improvement. Responsibilities include generating reports, providing data-driven insights and collaborating with teams ...

  • NCM Associates

    Operations Analyst

    2 weeks ago


    NCM Associates Kansas City, United States

    The Operations Analyst is responsible for collecting, analyzing, and interpreting operation data to identify trends and areas for improvement. Responsibilities include generating reports, providing data-driven insights and collaborating with teams to implement process improvement ...


  • Burns & McDonnell Kansas City, United States Paid Work

    Description · The Assistant Electrical Engineer (or Energy & Utilities Analyst) will assist our clients by helping execute a variety of engineering and power system studies, to bring together the technical and economic knowledge needed to develop strategic roadmaps. Our goal is t ...


  • Burns & McDonnell Kansas City, United States

    · The Assistant Electrical Engineer (or Energy & Utilities Analyst) will assist our clients by helping execute a variety of engineering and power system studies, to bring together the technical and economic knowledge needed to develop strategic roadmaps. Our goal is to help our ...


  • Citigroup Inc Kansas City, United States

    Compliance Business Control Sr. Analyst · The Compliance Business Control Sr. Analyst is a seasoned professional role. Applies in-depth disciplinary knowledge, contributing to the development of new techniques and the improvement of processes and work-flow for the area or functi ...


  • Burns & McDonnell Kansas City, United States

    **Description** · The Senior Transmission Planning Consultant will utilize extensive knowledge in electrical transmission planning and application of grid technologies to assess grid performance and ready the grid for the future challenges represented by plant retirements and re ...