Senior Security Controls Engineer
2 weeks ago
Experience the HCA Healthcare difference where colleagues are trusted, valued members of our healthcare team. Grow your career with an organization committed to delivering respectful, compassionate care, and where the unique and intrinsic worth of each individual is recognized. Submit your application for the opportunity below:Senior Security Controls EngineerHCA Healthcare
BenefitsHCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
- Comprehensive medical coverage that covers many common services at no cost or for a low copay. Plans include prescription drug and behavioral health coverage as well as free telemedicine services and free AirMed medical transportation.
- Additional options for dental and vision benefits, life and disability coverage, flexible spending accounts, supplemental health protection plans (accident, critical illness, hospital indemnity), auto and home insurance, identity theft protection, legal counseling, long-term care coverage, moving assistance, pet insurance and more.
- Free counseling services and resources for emotional, physical and financial wellbeing
- 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service)
- Employee Stock Purchase Plan with 10% off HCA Healthcare stock
- Family support through fertility and family building benefits with Progyny and adoption assistance.
- Referral services for child, elder and pet care, home and auto repair, event planning and more
- Consumer discounts through Abenity and Consumer Discounts
- Retirement readiness, rollover assistance services and preferred banking partnerships
- Education assistance (tuition, student loan, certification support, dependent scholarships)
- Colleague recognition program
- Time Away From Work Program (paid time off, paid family leave, long- and short-term disability coverage and leaves of absence)
- Employee Health Assistance Fund that offers free employee-only coverage to full-time and part-time colleagues based on income.
Learn more about Employee Benefits
Note: Eligibility for benefits may vary by location.
We are seeking a Senior Security Controls Engineer for our team to ensure that we continue to provide all patients with high quality, efficient care. Did you get into our industry for these reasons? We are an amazing team that works hard to support each other and are seeking a phenomenal addition like you who feels patient care is as meaningful as we do. We want you to apply
Job Summary and QualificationsThe Security Controls Engineer is a technology and process focused security professional with an emphasis in information security controls, risk assessment, regulatory compliance, and security consultation. Applies information security concepts, knowledge, and skills to support a comprehensive information protection program. The Security Controls Engineer evaluates and monitors the current state of security controls across the organization related to people, process, and technology as well as with 3rd party vendors external to the organization.
GENERAL RESPONSIBILITIES
- Performs the collection of the top and most pressing IT security risks (regulatory, security of critical enterprise applications and infrastructure, vendors, etc.), analyze, monitor, and derive strategic decisions that balance risk with operation and economic costs of protective measures.
- Performs interviews with company senior management and business owners to confirm anticipated business effects resulting from the actual occurrence of any of the identified enterprise security risks.
- Leverages inventory of key vendors, applications, processes, and infrastructure items and their impact to the top and most pressing IT security risks. Additionally, maps applications, processes, and infrastructure items to appropriate security risks.
- Performs activities to identify key controls (policy, procedure, practice, or organizational structure) that if implemented would provide reasonable assurance that security objectives will be achieved and undesired events will be prevented or detected and corrected
- Performs activities to review, develop, and implement security controls plans, vendor security agreements, and security exceptions to control standards.
- Performs activities to conduct technical security reviews and assessments of vendors, applications, processes, and IT infrastructure.
- Performs activities related to the analysis of data collected during security reviews and assessment of vendors, applications, processes, and IT infrastructure in order to determine current state of security risk across the company.
- Performs activities to develop remediation plans to address issues discovered as result of security reviews and/or assessments of vendors, applications, processes, and IT infrastructure. Works with management to assign remediation responsibilities, actions, and priorities.
- Performs activities to monitor and track remediation activities to address weaknesses and issues discovered through security reviews or audits of vendors, applications, processes, and IT infrastructure.
- Performs activities to develop strategies to ensure compliance with security standards as well as regulatory and audit issues.
- Performs activities to provide periodic reporting including assessment findings and recommendations for improvement to applicable constituencies (e.g., executive management, facility leadership, and governance committee).
- Identifies security related regulatory requirements (ie. PCI-DSS, SOX, HIPAA), and interacts with internal and external assessors and auditors to ensure ongoing compliance.
RELEVANT WORK EXPERIENCE
- 5+ years
EDUCATION
- Bachelor's Degree Preferred
OTHER/SPECIAL QUALIFICATIONS
Certifications (preferred, not required):
- CISSP Certified Information Systems Security Professional
- GSEC GIAC Security Essentials Certified
- CISA Certified Information Systems Auditor
- PCIP PCI Professional Training
- HCISPP Healthcare Information Security and Privacy Practitioner
Preferred areas of experience:
- Security Technologies / Methodologies
- IT Audit/Risk Management
- Information Security Metrics and Reporting
- Systems Control Review Process
- Application/Infrastructure Control Review Process
- Working knowledge of the COSO and COBIT methodologies
- Experience with ISO17799, HIPAA, Sarbanes-Oxley, PCI-DSS
- Experience with IT risk, regulatory, or compliance responsibilities
- Possession of excellent analytical and interpersonal skills
- Possession of excellent oral and written communication skills
PHYSICAL DEMANDS/WORKING CONDITIONS
- Occasional travel may be required
HCA Healthcare has been recognized as one of the World's Most Ethical Companies by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"There is so much good to do in the world and so many different ways to do it."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
If you find this opportunity compelling, we encourage you to apply for our Senior Security Controls Engineer opening. We promptly review all applications. Highly qualified candidates will be directly contacted by a member of our team. We are interviewing apply today
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
-
Senior Principal Offensive Security Engineer
2 weeks ago
Nashville, Tennessee, United States Oracle Full time $120,000 - $200,000 per yearJob DescriptionOffensive Security Engineer Oracle Cloud Infrastructure GroupThe Oracle Cloud Infrastructure (OCI) Offensive Security team provides OCI with the capabilities to ensure our systems and services meet the security objectives we communicate to customers. The Offensive Security group performs security assessments, vulnerability research, static...
-
Security Access Control
4 days ago
Nashville, Tennessee, United States Allied Universal Full time $45,120 - $93,624 per yearOverview Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. Job Description As...
-
Armed Security Officer
4 days ago
Nashville, Tennessee, United States H-Team Security Full time $36,000 - $72,000 per yearWe are seeking a highly motivated and experienced Armed Security Officer to join our team, responsible for maintaining a safe and secure environment for our facilities, personnel, and assets.Responsibilities:Patrol assigned areas, both interior and exterior, to ensure the safety and security of the property and personnel.Control access to the facility,...
-
Senior IT Engineer
4 days ago
Nashville, Tennessee, United States Built Technologies Full time $115,000 - $150,000COMPANY OVERVIEW About BuiltBuilt is the AI-powered platform transforming the way real estate is financed, developed, and managed. Purpose-built for real estate and construction, Built began by fixing construction draw management for lenders and has grown into a comprehensive operating system addressing some of the industry's most complex challenges....
-
Network Security Engineer
4 days ago
Nashville, Tennessee, United States Mental Health Cooperative Full time $80,000 - $120,000 per yearRanked one of Tennessee's top places to work, MHC is a rare and special place where outstanding company culture is intentional. Where clients and associates are treated the same, as equals.Mental Health Cooperative, Inc. (MHC) was formed in 1993 to serve individuals with severe and persistent mental illness. Since then, we have expanded our services to...
-
Security Access Control Specialist
4 days ago
Nashville, Tennessee, United States Allied Universal Full time $40,000 - $80,000 per yearOverview Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. Job Description As...
-
Truck Gate Security Officer-WEEKENDS
4 days ago
Nashville, Tennessee, United States Security Engineers, Inc Full time $32,920 - $36,600 per yearTruck Gate Security Officer-WEEKENDSWeekends (Saturday and Sunday)7pm-7amPay Range: $16.45- $17.50/hourRole OverviewSecurity Engineers is seeking dedicated Unarmed Security Officers to help maintain safe and secure environments for our clients. Officers play a vital role in deterring incidents through visibility, vigilance, and proactive engagement....
-
HVAC controls engineer
2 days ago
Nashville, Tennessee, United States Rise Technical Full time $1,220,000 - $1,320,000 per yearHVAC Controls Engineer - Progress into Controls EstimatorNashville, Tennessee - (NO State Tax) Relocation Package Available$100,000 - $130,000 + Bonus ($20k) + Progression + Excellent training + Commission + Healthcare + 401(k) + Holiday & PTOAre you a Controls Engineer looking to step up into estimating with further progression on offer? Are you looking to...
-
Controls Project Engineering Manager
2 days ago
Nashville, Tennessee, United States Hitachi Full time $180,000 - $200,000 per yearLocation:Nashville, Tennessee, United States of AmericaJob ID: R0109301Date Posted: Company Name:WRIGHT INDUSTRIES, LLCProfession (Job Category):Engineering & ScienceJob Schedule: Full timeRemote:NoJob Description:The Opportunity: JR Automation, a Hitachi Group Company, is driven to deliver customer success worldwide. We provide intelligent automated...
-
Automation and Controls Engineer
2 days ago
Nashville, Tennessee, United States Rogers Group, Inc. Full timeRogers Group, Inc., headquartered in Nashville, is a privately held aggregates and asphalt highway construction company operating in 12 states with over 3,000 employees. RGI, established in 1908, has the distinction of being recognized as the largest privately held aggregate producer in the United States.We have 86 quarries and 56 asphalt plants across...