Information Security Compliance Specialist I (Remote)
American Specialty Health, Inc.About the role
American Specialty Health Incorporated is seeking an Information Security Compliance Specialist I to join our Information Security Programs (ISP) department. This position will assist the Information Security Compliance team with our third-party compliance efforts. This includes conducting oversight of our third-party vendors, responding to and providing evidence for external audits, and managing our annual business impact analysis and continuity plan update.
Salary Range
American Specialty Health complies with state and federal wage and hour laws and compensation depends upon candidate’s qualifications, education, skill set, years of experience, and internal equity. $56,700 to $82,000 Full-Time Annual Salary Range.
Remote Worker Considerations:
Candidates who are selected for this position will be trained remotely and must be able to work from home (WFH) in a designated work area with company-provided technology equipment. This remote/WFH position requires you have a stable connection to your Internet Service Provider with the ability to participate by video in online meetings over a reliable and consistent network (minimum internet download of 50 Mbps and 10 Mbps upload speed).
Responsibilities
- Assists with Information Security tasks and projects.
- Works with business owners throughout the company to coordinate and conduct on-boarding and periodic third-party risk assessments. Communicates both internally and externally to gather required information and evidence.
- Reviews third-party documentation and provide recommendations on whether to proceed with a vendor.
- Develops and manages the annual third-party audit plan.
- Maintains and reports on metrics around vendor oversight.
- Participates in weekly vendor oversight meetings; including documenting notes, action items, and updating third-party records based on meeting discussions.
- Coordinates the annual business impact analysis effort. Provides training to key stakeholders, gathers and reviews questionnaire responses, and assists with updating the business continuity plan.
- Assists with other compliance functions, including gathering and providing HITRUST evidence, responding to client and other external audits, and identifying and escalating cybersecurity risks.
- Reviews and updates related policies and procedures at least annually.
- Promotes understanding and adherence to the necessary policies, standards, and procedures to maintain security posture.
- Documents and/or diagrams technology, solutions, and configurations; including, but not limited to: Identity management, network management, change control, systems monitoring, incident response, vulnerability management, and configuration management; as needed, to support audit and reporting consistency.
- Assists both Information Security Compliance and Information Security Operations teams with initiatives and projects, as assigned.
- Attends online industry seminars, conferences, and training classes to maintain knowledge and skills.
Qualifications
- Bachelor’s degree in an applicable field, such as Information Security (IS), Information Technology (IT), Computer Science, Business Administration, or equivalent experience. If equivalent experience, high school diploma required.
- Minimum of 2 years of technical compliance or audit experience.
- Professional security certification, such as CISA, preferred.
- Demonstrated experience with implementing and maintaining compliance to both internal policies and procedures, and external frameworks such as HIPAA and the HITRUST Common Security Framework (CSF).
- Must have demonstrated experience in a dynamic, fast-paced working environment.
- Must have demonstrated experience in business continuity and third-party management a plus.
- Familiarity with IT risk and control concepts; including auditing, analysis, governance, risk assessment, and application of IT security controls.
- Strong analytical skills required; must be very detail-oriented with an ability to develop and apply complex concepts.
- Must have demonstrated experience with building workflows and automating manual tasks.
- Working knowledge of common enterprise technologies, such as Governance, Risk and Compliance (GRC) tools, Active Directory, networking, Windows, and MS 365 required.
- Must be technically proficient in performing assi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s