Security Third Party Specialist
Oklahoma State GovernmentAbout the role
Job Posting Title
Security Third Party SpecialistAgency
807 HEALTH CARE AUTHORITYSupervisory Organization
Business EnterprisesJob Posting End Date
Refer to the date listed at the top of this posting, if available. Continuous if date is blank.
Note: Applications will be accepted until 11:59 PM on the day prior to the posting end date above.
Estimated Appointment End Date (Continuous if Blank)
Full/Part-Time
Full timeJob Type
RegularCompensation
$68,049.00 / annualJob Description
Agency/Division Information
The Oklahoma Health Care Authority (OHCA) works to ensure Oklahomans have access to better health and better care. The agency’s core values include passion for purpose, trust and transparency, empowerment and accountability, best in class and outcome-driven, and servant leadership. As part of the interview process, candidates may be required to attend an in-person interview at our Oklahoma City office.
Position Purpose
The Security Third Party Specialist at the Oklahoma Health Care Authority (OHCA) is responsible for ensuring compliance with state and federal regulations while supporting key security and risk management functions targeted towards supply chain and third-party risks. This position provides technical expertise, initiates security program development, manages vulnerability submissions, and vendor security metrics. It plays a critical role in evaluating third-party security documentation, maintaining related security standards, and ensuring the effectiveness of our compliance programs based on NIST 800-53r5. The Security Third Party Specialist collaborates closely with both internal and external stakeholders to mitigate risks, enhance security protocols, and maintain the integrity of organizational processes, aligning with OHCA's core values of accountability, transparency, and excellence. The successful candidate will be able to lead and develop strategies.
Principal Activities May Include:
Vulnerability management and monitoring; This includes understanding vulnerability management principles and technical scan reports for working with system vendors to review and develop relevant risks metric reports.
Provide technical expertise and analysis; Keep aware of current industry trends and news to be more proactive in efforts. Be able to handle and interpret more technical questions and information. Must be proficient in data analysis and related tools such as MS Excel to identify issues, trends, patterns, track information and other techniques to achieve objectives and craft usable report summaries. This includes skilled use of formulas, pivot tables, and principles of good design.
Third Party Document Reviews; Support Business Enterprise projects by providing expertise in reviewing security documentation providing comments and escalation of any issue identified as appropriate. May be required to attend project meetings to clarify comments and listen for other security concerns that may need coordination. Coordination with subject matter experts or stakeholders may be required for detailed issues and resolutions.
Coordinate workgroup meetings to identify, address, and drive third party risk and issues.
Coordinate closely with Risk and Compliance Manager to support; Communicate and coordinate effectively with teams to identify support needs.
Draft and Maintain Security Documentation; This includes, but is not limited to, Standards, Guidance, and Supply Chain Risk Management (SCRM) Plan related to NIST 800-161. Documents shall be reviewed annually or during significant changes for updates and maintenance. Technical concepts should be written at a level commensurate with the audience for the document.
Other duties as assigned.
**To be considered for this position your application must include a resume/CV with complete work and education history.**
Education and/or Experience:
A bachelor's degree AND
3 years of professional Information Security experience, preference for being in a federal and/or healthcare environment OR
An equivalent combination of education and experience, substituting 1 year of qualifying graduate experience in Business or IT Security for each year of the required experience.
Preference may be given to candidates with:
Certifications such as Certif
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s