Security Jobs
Director of IT Security
Blue Shield of California
San Francisco
Job Description
Director of IT Security is accountable for proactively overseeing all ongoing activities related to the confidentiality, integrity and availability of sensitive BSC electronic data; as well as compliance with federal, state and local laws and BSC's electronic security policies regarding the handling of legal, financial, personal, health and other sensitive information in compliance with federal and state laws and BSC's electronic security practices.
The Director of IT Security must effectively create and/or coordinate the strategy, architecture and execution of information security plans in support of BSC's strategy and consistent with Security Policy developed by Internal Audit Services. This position reports into the head of infrastructure & Operations, with a dotted line accountability to the CIO. It will manage the staff and budget for IT Security, which operates within the Infrastructure and Operations Division of BSC's Information Technology Department. This position has the authority to address all IT security implications and concerns throughout the organization as described below; and legislative/regulatory directions must be monitored to anticipate the best use of resources and to modify priorities to meet the changing market.
Critical responsibilities for this role will include:
Development and implementation of a Security Strategy. A new high level architecture was drafted in 2008, and has been approved by the BSC Technology Committee. Development of a roadmap needs to be completed and maintained; and the annual and multi-year investment recommendations, prioritization and tradeoffs are the responsibility of this position.
Development and ownership of the Security Architecture which incorporates applications, data, network and operations. Participates in the Enterprise Architecture Review Board and BSC Technology Committee. Providing a security view of technical choices, and assessing operational impact and supportability of those choices.
Oversees the IT security operations function, including the security monitoring of IT systems under the corporation's control and delegates; leading security solutions implementations.
Threat & Vulnerability Management, including analysis, supports the security incident response team, penetration and vulnerability testing, malware and malicious code management, IP content monitoring, and data loss prevention.
Oversight of 3rd party security which includes vendor security program certification, and network access agreements.
Working with Internal Audit Services ensures compliance with policies, and development of specific IT policies if required. Ensures compliance and monitoring of all company services and systems to assure IT Security practices and policies are implemented.
Working with Legal, Internal Audit and the Privacy Office, assists in retrieving, monitoring and/or recording activities of individuals or groups who are involved in incidents that violate corporate polices, HIPAA requirements, and applicable laws.
Participating in monitoring of all trading partner and business associate agreements to ensure all IT security concerns, requirements, and responsibilities are addressed. Providing consultation to the Privacy office in this area.
Company Information
Blue Shield of California is a 8.9 Billion dollar revenue not-for-profit company, We have over 3.4 Million members and 4,800 Employees in California. The company contributes $30 million annually to the Blue Shield of California Foundation to fund nonprofit organizations that improve access to quality health care in California.
Requirements
The Director of IT Security will have a degree in Computer Science and 15+ years of demonstrated experience in IT security at increasing level of authority including at least 7 years at the management level, or the equivalent combination of education and experience. Experience in providing IT security in a heavily regulated environment required; insurance, financial services or health care is required. This position will have a high-level of visibility with BSC'ss IT executive team, company executives, and occasionally the Board Audit Committee.
This position will prefer appropriate industry standard certifications (e.g. CISSP), and preferred vendor certifications (e.g. Cisco).
Extensive expertise on IT security laws and regulations including but not limited to HIPAA, Medicare, Sarbanes-Oxley, DMHC, CMS, DOI and various California privacy laws.
Working familiarity with information technology systems and more than one domain of security architecture or technology
Prior IT security work with a health plan or in another regulated field, specifically including service as a Director of IT Security strongly preferred.
Previous experience in managing a small staff and demonstrated ability to drive toward achievement of results by establishing accountabilities and ensuring staff meets performance objectives.
Demonstrated ability to effectively communicate with senior level executives, and ability to successfully interact with and influence business partners in the achievement of the organization's business results
Reviewing ongoing HIPAA and other regulatory developments, as well as other new or revised laws and regulations pertaining to IT security, to determine if new or modified policies are needed.
Blue Shield of California is an Equal Opportunity Employer.
Contact
Eric Principe
E-Mail: eric.principe@blueshieldca.com
For more information, visit our website
This job was posted on:
Oct 07, 2009
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.
- More Headlines
- Change Topic
Data Protection
- Cisco's Free IPhone App Grabs Security Feeds
- Security Pro Says New SSL Attack Can Hit Many Sites
- 3 Basic Steps to Avoid Joining a Botnet
- Security Vendor Fortinet Sparkles in IPO
- NSA Helped with Windows 7 Development
- The Mass. 201 CMR 17 Survival Guide
- 64-Bit Windows Safer, Claims Microsoft
- Firefox 3.6 Locks Out Rogue Add-Ons
- How to Hack China for Just $1,800
- The Cloud Security Survival Guide


