IT Security and Compliance Specialist

Urgent

Job Description

Job Details: IT Security and Compliance SpecialistFull details of the job. IT Security and Compliance Specialist Craneware PLC Technology Permanent Edinburgh Let’s transform the business of healthcare! At The Craneware Group, we are dedicated to empowering our customers with industry-defining insights that pave the way for a brighter future. If you are an energetic, forward-thinking individual with a passion for innovation, we invite you to join our thriving team of more than 750 dedicated professionals. Together, we’ll fuel the expansion of our SaaS platform and develop cutting-edge applications that redefine the healthcare landscape. The Craneware Group supports a flexible work environment as well as a collaborative and teamwork focused atmosphere. Employees will be expected to work a hybrid working arrangement spending 40% of their time per month in the Tanfield office – approx 2 days per week. Our Information Security team manages IT cyber security risks and acts as the responsible officer for IT cyber risk management and responding to audits. This role will be involved in all aspects of Information Security. The remit covers all aspects of Information Security across People, Processes and Technology. Working alongside colleagues in the IT Infrastructure, IT Operations, HR and Engineering teams, this role will support the team in delivering the information security strategy by implementing plans, and aligning this with the wider needs of the organisation. Proposing security requirements by evaluating business requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; identifying integration issues; preparing cost estimates. In conjunction with the Head of Information Security and Security Council, develop, communicate and maintain a security roadmap Serving as an expert across security functional areas within Craneware, which includes network security, cloud security, data encryption, privileged account management and security monitoring. Planning and proposing for approval to the Head of Information Security the security systems by evaluating network and security technologies; developing requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related security and network devices; designs public key infrastructures (PKIs), including use of certification authorities (CAs) and digital signatures as well as hardware and software; adhering to industry standards. Implementing security systems, specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation. Supporting the Head of Information Security in ensuring the policy and plans exist, are regularly maintained, and monitored and reviewed and revised where necessary in which to manage the business risks and support the discharge of the company’s responsibilities with respect to legislative requirement, in addition ensure that all employees comply with IT security requirements and escalate appropriately any related breach. Supporting the Head of Information Security in the data protection office role, securing data from internal and external attack; ensuring that customer sensitive data is always secure and ensuring compliance with any legislative and regulatory requirements for the storing and use of data. Assisting the Head of Information Security to ensure an effective disaster recovery and crisis management policy and plans regarding cybersecurity exists and that everyone involved is educated and regularly trained on their roles. Ensure regular disaster recovery simulations occur, which may involve complex cybersecurity scenarios. Helping the Head of IT Security and Product Development across the enterprise ensure Craneware adheres to and does not breach data protection legislation in each business region including, but not limited to, HIPAA compliance. Reviewing and completion of relevant sections of customer issued security information requests and RFPs. Being the lead resource from data security in audits, and as part of the wider audit team ensuring the business remains GDPR, HIPAA and HITRUST compliant. Maintaining security by implementing and using appropriate tools to monitor and ensure compliance to standards, policies, and procedures, assisting incident response analyses. Ensuring security and integrity of network infrastructure and services such that unauthorised activity can be recognised and prevented. Planning and coordinating internal and third-party led security tests, assessments, and audits of our information security policies, procedures, and systems Upgrading security systems by monitoring security environment; identifying security gaps; evaluating and ensuring implementation of enhancements. Providing regular updates to the CIO and security Council covering information security key performance indicators as well as any incidents / events and key security risks. Updating job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations. Be proactive in understanding new IT trends related to Information and Security and informing relevant teams about new security risks and evaluate technical opportunities proposing to the CIO as to how these could be translated into business opportunities Managing risk identification and mitigation associated with data and systems Providing technical support and guidance to project teams and other business areas in relation to Information Security. Validating delivered solutions against approved security architecture Educated to Degree level and 2+ years of commercial experience working in a Cyber Security role or alternatively 4+ years of commercial experience working in an IT Infrastructure role with significant elements of IT security experience. One or more relevant security certifications. At least 2 years’ proven experience in prototyping security solutions for hand over to appropriate business function. At least 3 years’ proven experience in building or working in network and engineering IT architecture . Background in technical IT roles such as IT architecture, development or operations, with a clear and abiding interest in information security. Track record in working with multiple and diverse projects. Experience in multiple technical areas such as: + Linux and Windows systems + Router, switch, LAN and VLAN security; wireless security + Firewalls, IDS/IPS, network access control + Risk assessments, policy formation and their security implications + Third party auditing and risk assessment methodologies + NIST, ISO 27001, HITRUST, HIPAA Good knowledge of Cyber/Information Security frameworks, supporting processes and toolsets Experience designing and leading the execution of Information and Security across businesses Good knowledge and understanding of healthcare regulatory/compliance requirements in information security and data protection Knowledge of third-party auditing and risk assessment methodologies Ability to breakdown and solve complex problems across multiple domains and successfully lead the recovery of major and/or complex security incidents Ability to collate and present data to be shared at an executive level, such as proposals, proof of concepts reports and technical papers Possession of an innovative mind-set Ability to keep abreast of new and emerging technologies as well as new security methodologies and design patterns. Excellent level of commercial awareness, keeps abreast of market trends/changes through external and internal stakeholders. Ability to collaborate effectively with other senior colleagues across the organisation. Independent and self-motivated in driving improvement Excellent knowledge of Craneware’s operations in relation to information security Experience in managing audit requirements Be motivated and passionate for self-learning/self-development Security, including information security management, physical security, application security, network security and security incident management Exceptional customer service, strong analytical and problem-solving skills Good stakeholder management skills, with an ability to understand and communicate technical detail to a non-technical audience Ability to analyse and solve technical problems regardless of technology stack Problem Solving will be utilised in this role, expected to undertake very complex tasks, including, but not limited to, analytical thinking and developing highly innovative solutions Ability to build and articulate a business case to propose new solutions to the organisation

Location