*Hi All,*

*Please check and let me know*


*Kindly mail me at nik...@apetan.com <nik...@apetan.com>*


*Sr. IT Security Consultant with HITRUST experience and CISA Cert*

*Location: Minneapolis*

*12 months*

*Interview: Phone*





*Sr. IT Security Consultant - Vendor Information Security Risk Assessment
(VISRA) ​- *


*Eden Prairie *Must pass a drug test and background check once offered
position**
------------------------------

*PROJECT:*

Supporting UHC's accelerated approach for assessing high risk critical
vendors

*TEAM:*

Reporting to the VISRA Team, the individual will act as a liaison & SME for
internal departments & vendors to successfully perform Onsite Risk
Assessments in USA. We leverage HITRUST CSF Version 7.0 for our program.

*RESPONSIBILITIES:*

   - Perform and manage Onsite Risk Assessments as per process documents
   - Ensure vendor compliance to the business agreement, policies,
   procedures, & regulations along with ability to map controls and compliance
   requirements
   - Review vendor supplied policies & procedures, internal/external
   assessment reports, agreements and provide feedback
   - Provision assessment reports and executive summaries with
   recommendations & direction regarding remediation efforts and disposition
   of the third party
   - Communicate, escalate, and track vendor progress on assessment
   remediation activities
   - Act as a liaison & SME for internal departments & vendors to
   successfully manage Vendor Risk Assessment
   - Understand information security risks that are inherent to a business
   and articulate those risks in business terms
   - Maintain current knowledge on information security topics and their
   applicability program requirements
   - Engage VRO regarding any delays/deviations during remediation

*TOOLS:*

Advance level experience in MS Word, MS Excel, and MS PowerPoint etc.


*MUST HAVE:*

   - Experience working with senior levels of management
   - Good follow-up skills and detail oriented
   - Security expertise including knowledge on different security risk
   assessment frameworks (NIST/Octave), standards
   (ISO27001/HITRUST/ITIL/Cobit), and act such as (HIPAA/GLBA).
   - Experience in examining the SSAE 16 Audit report
   - Knowledge and understanding of different security products (web/email
   filtering, disk encryption, IDS/IPS, antivirus, DLP, firewall etc.)
   - Knowledge of software development methodologies, application security,
   and OWASP Top 10 guidelines
   - Ability to document assessment work papers and preparing assessment
   report
   - Ability to manage vendor assessment independently with minimal
   supervision
   - Strong Communication and Presentation Skills

*NICE TO HAVE:*

Possess good project management skills

***Travel within USA for onsite risk assessments required. Travel Required
: Up to 50%

-- 

Thanks

Nikhil Prasad

nik...@apetan.com

201-620-9700*130

Apetan Consulting LLC

-- 
You received this message because you are subscribed to the Google Groups 
"project managment" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to project-managment+unsubscr...@googlegroups.com.
To post to this group, send email to project-managment@googlegroups.com.
Visit this group at https://groups.google.com/group/project-managment.
For more options, visit https://groups.google.com/d/optout.

Reply via email to