Information Security Program Manager Job Description
At the Center for Health Information and Analysis (CHIA), we serve as stewards of Massachusetts health data, employing multifaceted datasets and cutting-edge analytics to ensure transparency in our healthcare system. By joining CHIA as the Information Security Program Manager, you'll become immersed in the efforts of protecting one of the largest and most disparate collection of healthcare data in the Commonwealth and play a pivotal role in the success of CHIA’s Information Security team in its continued quest to improve CHIA’s overall security posture.
In this exciting role, you will use your expertise in program management, budgeting and planning to drive the Information Security team to attain greater compliance with security frameworks such as NIST and FedRAMP. You will use your excellent communication skills to partner and collaborate with the leaders of CHIA’s information security, IT Operations, application development, and data operations to realize CHIA’s information security strategic goals.
This new role is a full-time, contract position reporting to the Center’s CISO. The hourly rate will be $90-$95/ hour commensurate with experience. The contractor will primarily work off-site, but occasional meetings in the Center’s Boston office at 501 Boylston Street. The engagement will run for approximately 12-months and there may be opportunity for longer-term work.
Specifically, as the Information Security Program Manager, you will have the opportunity to:
- Create a multi-year information security roadmap: Create a roadmap to remediate findings from CHIA’s most recent security audit report. Assist the Information Security team with the development of security strategies, including guiding principles and future state vision, ensuring that the strategic objectives are aligned with agency goals. Maintain a weekly task list to streamline and prioritize work for Information Security Resources.
- Maintain a budget of potential information security investments: Keep current with Azure offerings in security as they relate to the technical and business problems CHIA faces and work with the organization to continue to evolve our capabilities and infrastructure by leveraging and procuring new and emerging offerings.
- Lead the effort to create a business continuity plan for CHIA: Lead cross-team effort to create a comprehensive business continuity plan (BCP) for CHIA. Include periodical tabletop exercises and testing activities to maintain the robustness of the BCP.
- Be the point of contact for Legal/Privacy on joint projects with Information Security: Lead project teams in creating, planning, and delivering far-reaching, clear and concise documentation and policies to CHIA as required by various information security and privacy frameworks. Report on monthly Security/Privacy meetings with roadmap and status updates.
Here are the important qualifications we are looking for:
- Working knowledge of cloud architectures: Demonstrate your proven familiarity with an Azure cloud environment.
- Understanding of industry regulatory and compliance requirements (i.e., FedRAMP, NIST, HIPAA)
- Effective Communicator: Demonstrate excellent written and verbal communication skills, with an ability to articulate complex technical issues clearly and persuasively. Engage stakeholders and foster collaboration through compelling communication.
- Educational Foundation: Possess a bachelor’s degree in computer science, information systems or engineering providing the necessary foundational skills for success in this role.
- Specialized Expertise: Bring at least 10 years of professional experience, with at least 5 years of demonstrated success in Program Management.
An Equal Opportunity / Affirmative Action Employer. Females, minorities, veterans, and persons with disabilities are strongly encouraged to apply.
The Commonwealth is an Equal Opportunity Employer and does not discriminate on the basis of race, religion, color, sex, gender identity or expression, sexual orientation, age, disability, national origin, veteran status, or any other basis covered by appropriate law. Research suggests that qualified women, Black, Indigenous, and Persons of Color (BIPOC) may self-select out of opportunities if they don't meet 100% of the job requirements. We encourage individuals who believe they have the skills necessary to thrive to apply for this role.
Information submitted by applicants is collected through the JazzHR Platform, your submission of application materials constitutes your express consent for this information to be provided to JazzHR for processing. Please do not include any personally identifiable information with your application materials other than that specifically requested by CHIA. CHIA requests basic information such as name, address, telephone number, and email address. You may also self-identify with your race/ethnicity, gender, disability and/or veteran status. However, you should not provide more detailed personal information such as your date of birth or Social Security Number with your application materials.