Client: State of North Carolina Job Title: Compliance Officer Duration: 12 Months Start Date: ASAP Location: 221 E Lane Street Raleigh NC 27601 (Hybrid) Position Type: Contract Interview Type: Webcam Interview Only Ceipal ID: SNCSECU232VH Requirement ID: NCDIT Security Specialist Mid Level (747232)
**The candidate will be allowed to work remotely but will need to be onsite at short notice. There is a mandatory threeweek training onsite at the beginning of the engagement. Once all staff return to site the candidate will need to work onsite full time.
Description The Compliance Officer will be familiar with risk management comfortable leading internal risk assessments and possess knowledge of HIPAA and NIST privacy and security requirements for health information networks.
The NC HIEA Compliance Officer will ensure that operations follow all relevant state and federal requirements for securely transacting health information via the HIE Network NC HealthConnex. The Compliance Officer will be familiar with risk management comfortable leading internal risk assessments and possess knowledge of HIPAA and NIST privacy and security requirements for health information networks. This position will work closely with the NC HIEA leadership team DIT legal counsel and DIT Privacy Team and DIT Security and Risk Management Team to ensure continual improvement of the NC HIEAs security and risk profile.
Responsibilities:
Assist with the development and implementation of a compliance program for the NC HIEA that includes preparation for HITRUST certification
Create sound internal controls and monitor adherence to them
Draft and revise policies
Proactively audit processes practices and documents to identify weaknesses
Evaluate activities to assess compliance risk
Collaborate with external auditors and DIT Security Team when needed
Set plans to manage a crisis or compliance violation
Educate and train employees on regulations and industry practices
Address employee concerns or questions on compliance
Keep abreast of industry standards and business goals.
Required/Desired/Highly desired Skills:
Knowledge of privacy laws (state and federal such as HIPAA (preferred) PCI CJIS); proven risk management experience. (Required 3 Years)
Experience in creation of risk management strategies and policy development to handle data breaches and other incidents. (Required 3 Years)
Knowledge of NIST controls and experience with completing/conducting assessments; written and verbal communication. (Required 3 Years)
Strong conflict management skills in order to work with senior management to ensure security and data protection rules and regulations are in place. (Required 3 Years)
Knowledge of cybersecurity and privacy principles. (Required 3 Years)
Ability to determine whether a security incident violates a privacy principle or legal standard requiring specific legal action. (Required 3 Years)
Ability to work across departments and business units to implement organizations privacy principles and programs. (Required 3 Years)
Ability to develop update and/or maintain standard operating procedures (SOPs). (Required 3 Years)
Ability to develop clear directions and instructional materials. (Required 3 Years)
V Group Inc. is an IT Services company which supplies IT staffing project management and delivery services in software network help desk and all IT areas. Our primary focus is the public sector including state and federal contracts. We have multiple awards/ contracts with the following states: AR CA DE FL GA IL KY MD ME MI NC NJ NY OH OR PA SC TX VA and WA. If you are considering applying for a position with V Group or in partnering with us on a position please feel free to contact me for any questions you may have regarding our services and the advantages we can offer you as a consultant.
Please share my contact information with others working in Information Technology.
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.