Engineer, Information Security and Risk

Cardinal Health
Providence, RI, United States
$92.1K-$131.6K a year
Full-time
We are sorry. The job offer you are looking for is no longer available.

Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE : CAH) is a global, integrated healthcare services and products company connecting patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management.

Backed by nearly 100 years of experience, with more than 50,000 employees in nearly 60 countries, Cardinal Health ranks among the top 20 on the Fortune 500.

Cardinal Health’s Information Security team aims to be a world-class cybersecurity and risk management organization that enables Cardinal Health to be healthcare’s most trusted partner.

We are a remote-first team and are excited to offer full-time remote opportunities. We currently have a full-time career opening for an Information Security and Risk Engineer role within the Information Security Organization.

This role will report to the manager of IT control compliance council within our Information Security Team and will serve as the first line of defense role responsible for defining, implementing, and evaluating the effectiveness of IT controls.

Qualifications :

Bachelor’s Degree in related field or equivalent work experience

4+ years’ experience in related field preferred, such as IT audit, IT compliance function

Strong understanding and experience with SOX and / or other regulatory compliance processes

Team Player and Collaborative Ability to work well with team members to achieve the desired results

Willing to independently navigate through complex scenarios and uncharted compliance topics

Ability to multi-task with organization, efficiency, accountability, and attention to detail

Driven and self-motivated to learn new technologies and achieve objectives

A great & effective verbal and written communicator

Professional certification preferred : CISA, CISSP, CISM, CRISC

Essential Duties and Responsibilities :

Perform IT risk assessment for pilot areas and identify control gap

Work with IT stakeholders to design effective IT controls and monitor the execution to manage risk and ensure compliance with regulations (e.g., SOX, HIPAA, GDPR)

Design IT controls that increase operational efficiency and reduces the likelihood of control failure (e.g., automated and preventative controls vs. manual and detective)

Challenge status quo - recommend new or improved controls to keep IT applications current with industry standards and compliance requirements.

Carry out analysis on third party audit reports, such as SOC 1 / 2, to identify potential control issues.

Track and drive remediation of IT control issues within our IT risk governance process Strong in educating / influencing of IT stakeholders to raise awareness and promote a mindset focused on IT controls and compliance

Oversee information security compliance activities, including daily, weekly, quarterly and / or annual security risk assessments both performing internal assessments and responding to external assessments.

Collaborate cross-functionally within the information security and risk management department to ensure alignment with existing compliance, risk management and information security activities

Research new security compliance requirements and assist in the evaluation of compliance control requirements.

Any other duties that may be required as assigned

Experiences :

Experience participating in external control audits; SOX and / or SOC1 / 2 Type II audit experiences are preferred

Solid working knowledge of governance frameworks including NIST, ISO27000, FedRAMP

Experience with Corrective Action Plans (CAP) to remediate deficiencies identified through monitoring, auditing, or a Compliance Issue Report (CIR).

These activities should consist of improvements to health plan processes or vendor processes taken to eliminate causes of non-compliance or other issues

Strong personality, ability, and credibility to influence key decision-makers, and highly technical resources.

Strong Knowledge / experience of IT controls for mainstream ERPs, such as SAP, is a plus

Strong in root cause analysis and problem solving

Strong flowcharting skill is a plus

Experience with IT risk governance software (i.e. Archer, AuditBoard, ServiceNow GRC) is a plus

Anticipated salary range : $92,100 - $131,600

Bonus eligible : No

Benefits : Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

Medical, dental and vision coverage

Paid time off plan

Health savings account (HSA)

401k savings plan

Access to wages before pay day with myFlexPay

Flexible spending accounts (FSAs)

Short- and long-term disability coverage

Work-Life resources

Paid parental leave

Healthy lifestyle programs

Application window anticipated to close : 3 / 11 / 2024 *if interested in opportunity, please submit application as soon as possible.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day.

Cardinal Health is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity / expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here ()

14 days ago
Related jobs
Promoted
Citizens Financial Group, Inc
Johnston, Rhode Island

Applying extensive knowledge on data stores and best engineering practices: handling and logging errors, monitoring the system, building human-fault-tolerant pipelines, scalability, continuous integration, understanding database administration, and maintaining data cleaning. Citizens, its parent, su...

Motion Recruitment
Providence, Rhode Island

You will collaborate with third party providers and optimize security measures to protect and enhance the infrastructure of their security posture. The ideal candidate for this role is someone with a strong understanding of compliance, network security, and cloud technologies. Understanding/hands on...

CDW
Providence, Rhode Island

As a Senior Security Engineer of Threat Detection Operations, you will play a crucial role in identifying and analyzing cyber threat tactics, techniques, and procedures to ensure proactive detection capabilities in support of the global threat detection and response mission. Threat Research and Repo...

CVS Health
Work from home, RI, US
Remote

Information Security Risk Metrics Lead will drive efforts to build a comprehensive and sustainable Information Security risk metrics and reporting program. Identify and maintain key performance, risk, and control indicators and risk metrics library that will drive actions and decisions to address ar...

Motion Recruitment
Providence, Rhode Island

You will collaborate with third party providers and optimize security measures to protect and enhance the infrastructure of their security posture. The ideal candidate for this role is someone with a strong understanding of compliance, network security, and cloud technologies. Understanding/hands on...

CVS Health
Work from home, RI, US
Remote

The Staff Security Engineer of IAM will be a product owner and lead engineer within Identity Access Management (IAM) space for CVS Health. Operating within DevOps and Agile frameworks as part of our Product Management Model, an ideal candidate will have strong soft skills and engineering skills. We ...

Promoted
NTT DATA, Inc.
Providence, Rhode Island

We are currently seeking a Senior Business Analyst to join our team in Providence, Rhode Island (US-RI), United States (US). The Senior Business Analyst (Sr. Assist in the business and technical assessments of vendor deliverables such as Project Management Plan and Schedule, Requirements Validation ...

Promoted
Bally's Corporation
Lincoln, Rhode Island

Unable to act as current law enforcement security officers and cannot assist with disturbances or arrests. Staff the Security Dispatch Center 24 hours a day. Officers assigned to dispatch will answer phones, answer/monitor all radio communications from all departments, will monitor surveillance came...

Promoted
United States Army
Providence, Rhode Island

Collaborate with senior leaders in decision-making processes by transforming information into life-saving intelligence. Integrating your skills with cutting-edge information collection technology, you will become a critical player in our team’s success. Similar Career Fields Include: Intelligence An...

Promoted
Dexian - DISYS
Smithfield, Rhode Island

Proven ability in a data analysis role (minimum 3-5 years experience). Data Exchange knowledge and analysis skills to lead, execute, or assist on all assigned work throughout the project; examples of projects: implementation of a new client or Corporate Actions. Excellent analysis skills, preferably...