Job Views:  
6607
Applications:  73
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

332077

UnitedHealth Group - Associate Lead - Risk Assessment

5 - 7 Years.Delhi NCR
Posted 8 years ago
Posted 8 years ago

Associate Lead - Risk Assessment

Discipline - Information Technology

Industry - IT Security

Job Description :

Responsibilities:

- Execute the vendor's lifecycle process from information risk (security) standpoint.

- Support the process with linkages from Business and sourcing & procurement, Vendor Management teams etc.

- Maintain current knowledge on information security topics and their applicability to the program requirements.

- Ensure vendor compliance to the business agreement, policies, procedures, & regulations along with ability to map controls and compliance requirements.

- Support remediation efforts with business / vendor managers.

- Maintains metrics and report them.

- Ensure alignment of security policies/standards with IT infrastructure frameworks.

- Investigates non-standard requests and problems, with some assistance from others.

- Prioritizes and organizes own work to meet deadlines.

- Plans and manages awareness campaigns and other similar needs.

- Plans, manages and executes compliance programs in support of the conformance to stated policies.

- Responsibility for maintaining relationships with business leaders.

No. of Openings - 1

Qualification :

CISA or CISSP certified

- 5-7 years experience working as IT Auditor or Information Security Advisor/Consultant with external audit firm (preferably Big 4)

- Expert knowledge in the following Information Security Domains

- Information Security Management System, Risk Management, Access Control, Network Management

- Information Systems Acquisition, Development, and Maintenance

- Communications and Operations Management

Expert Knowledge or actual application of the following frameworks/standard/control requirements:

- ISO 27002, HiTrust CSF

- COBIT and/or PCI/DSS

- HIPAA Security Rules/Standards

- Solid experience in vendor risk assessments/3rd party security assessment/SOX

Qualifications and Experience :

- Risk assessment skills and the ability to manage risk assessments / projects independently.

- 6+ years of experience in internal / departmental or vendor information security audits/assessments.

- Security expertise including knowledge on different security risk assessment frameworks (NIST/Octave), standards (ISO27001/HITRUST/ITIL/Cobit), and acts such as (HIPAA/GLBA).

- Familiarity with ISO standards and frameworks.

- Excellent communication skills both verbally and written

The Apply Button will redirect you to website. Please apply there as well.

Didn’t find the job appropriate? Report this Job

Job Views:  
6607
Applications:  73
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

332077

UPSKILL YOURSELF

My Learning Centre

Explore CoursesArrow