Jobs and Careers
MI

Information Security Specialist

Midwest Transplant Network
United Statesfull_timeVerifiedPosted 2 Sept 2025

About the role

Job Details

Job Location MTN Westwood - Westwood, KSPosition Type Full Time

Description

The Information Security Specialist is responsible for driving information security initiatives. The individual will perform internal and external security compliance monitoring activities, manage client compliance audits, IT control audits, security gap analyses and security risk assessments/analyses. This role will assist in the management of key compliance areas such as HIPAA and the implementation of administrative, physical, and technical safeguards, PCI DSS, policy, process, and procedure governance, and the implementation of industry standards.                     

ESSENTIAL JOB FUNCTIONS

  1. Maintain security and compliance initiatives to ensure that corporate policies, standards, procedures, and audit activities are in alignment with business, IT, legal, and regulatory requirements.
  2. Develop and maintain a comprehensive set of policies, standards, processes, and procedures to ensure compliance with industry standards (,e.g., the NIST Cybersecurity Framework, the HIPAA Security Rule, and applicable laws.
  3. Maintain a written information security program (WISP) that ensures security policies, standards and process are being adhered to by the business.
  4. Monitor electronic systems for security incidents and vulnerabilities; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities, and evolving and emerging cybersecurity attack vectors.
  5. Respond to electronic system security incidents, including investigation of, countermeasures to, and recovery from computer-based attacks, unauthorized access, and policy breaches; interact with third-party incident responders, including law enforcement, and legal counsel.
  6. Partner with IT leadership to administer authentication and access controls, including provisioning, changes, and deprovisioning of user and system accounts, security/access roles, and access permissions to information assets according to industry standards.
  7. Lead the development, implementation and management of MTN’s WISP, ensuring compliance and auditing for improvements on an ongoing basis.
  8. Ensure compliance with healthcare information security best practices and HIPAA.
  9. Ensure compliance with, and management of, the MTN cybersecurity incident response plan and provide guidance for improvements on an ongoing basis in conjunction with the HIPAA Compliance Officer.
  10. Monitor security trends and drive information security best practices throughout the organization.
  11. Evaluate, design, test, and recommend new or improved controls to keep MTN current with industry standards and compliance requirements.
  12. Work with third party firms and consultants to conduct independent security audits, vulnerability scans, and penetration tests including social engineering.
  13. Work together with the business to provide an interface for client information security audits
  14. Collaborate with IT, legal, and other teams by providing cybersecurity input and guidance in relation to MTN’s mission.
  15. Conduct regular risk analyses, advise Senior Director, Information Technology Services and Senior management on appropriate recommendations and implement recommendations in an efficient and timely manner documenting remedial actions as directed. 
  16. Be informed about changes to the HIPAA Security Rule and other applicable laws and their impact on MTN’s compliance obligations and business operations. 
  17. Work with the Manager, Corporate Education & Development and HIPAA Compliance Officer to develop and administer, or provide advice, evaluation, and oversight for, ePHI information security training and awareness programs.

Qualifications

QUALIFICATIONS AND PHYSICAL DEMANDS

  1. Undergraduate degree in information systems or a related field or similar experience leading cybersecurity/information security initiatives.
  2. Five or more years experience managing security in a healthcare environment where HIPAA/HITECH regulations and guidelines for sec

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Midwest Transplant Network

View company profile →