Accountable for supporting the implementation of Geisinger's cybersecurity strategy under the direction of leadership. Proactively analyzes and anticipates changes in the cyber-threat landscape and actively participates in the design of effective countermeasures.. Responsible for the centralized tracking, management and reporting of cybersecurity technical issues and business risks. Performs risk assessment and management activities in regards to technology, process, and applications.
Job Duties
Write policies, standards, procedures, guidelines, and other technical security documents.
Design, implement, and enforce security policies that protect systems and data from security risks
Maintain and manage cybersecurity GRC Metrics, risk tolerances/triggers.
Develop automated reports and use data visualization tools to visualize GRC KPIs.
Interpret audit request lists and perform evidence collection activities in support of various audits.
Minimize user disruption due to burdensome security controls or duplicative evidence collection.
Serves as a Serves as a direct contact and subject matter expert for highly technical and complex cybersecurity inquires relative to their assigned specialized areas.
Conduct security third party risk management (TPRM) for Vendors at onboarding, contract review, RFP/RFI, and annual re-assessments while managing the continuous monitoring strategy.
Provide risk consulting and/or training to business and technical partners to improve the efficacy of risk management across the enterprise
Assists the Cybersecurity Architect with development of specialized design and architecture for Geisinger's Cybersecurity Program including roadmaps, technical direction, and alignment of controls to protect and enable the business.
Implement and track measures and metrics to ensure efficiency of solutions and return on investment in assigned area of specialty.
Leads the implementation of a sustainable and effective process to monitor cyber-threat intelligence as reported by various public, IT product vendors, security analysts and government threat sources, as well as, integrate into current systems and future security designs through a continuous improvement effort.
Develops and leads assigned cybersecurity projects to implement new security services, extend, or improve existing services.
Successfully completes complex assignments on schedule with limited supervision or guidance.
Develops and proactively evaluates and assesses current processes, procedures, capabilities and execute continuous improvement activities across the organization.
Provides feedback and have direct involvement in the ongoing implementation and maintenance of the ISO's Cybersecurity Strategic Plan, monitors and analyzes security event data produced from system logs, server and web, network components, and security systems to identify threats and unauthorized activity.
Gathers, monitors, analyzes and reports observed cyber-threat activity as reported by various public, IT product vendors, security researchers and government threat sources.
Provide guidance to associate level personnel for identifying and reporting on specific threat and vulnerability topics.
Performs risk assessments on technology, processes, and applications as needed and communicates risk to proper stakeholders.
Authors organizational policies and standards, as well as, departmental procedures focusing on cybersecurity.
Work is typically performed in an office environment. Accountable for satisfying all job specific obligations and complying with all organization policies and procedures. The specific statements in this profile are not intended to be all-inclusive. They represent typical elements considered necessary to successfully perform the job.
*Relevant experience may be a combination of related work experience and degree obtained (Associate's Degree = 2 years; Bachelor's Degree = 4 years).
Position Details
Education
High School Diploma or Equivalent (GED)- (Required)
Experience
Minimum of 2 years-Relevant experience* (Required)
Certification(s) and License(s)
OUR PURPOSE & VALUES: Everything we do is about caring for our patients, our members, our students, our Geisinger family and our communities. KINDNESS: We strive to treat everyone as we would hope to be treated ourselves. EXCELLENCE: We treasure colleagues who humbly strive for excellence. LEARNING: We share our knowledge with the best and brightest to better prepare the caregivers for tomorrow. INNOVATION: We constantly seek new and better ways to care for our patients, our members, our community, and the nation. SAFETY: We provide a safe environment for our patients and members and the Geisinger family We offer healthcare benefits for full time and part time positions from day one, including vision, dental and domestic partners. Perhaps just as important, from senior management on down, we encourage an atmosphere of collaboration, cooperation and collegiality. We know that a diverse workforce with unique experiences and backgrounds makes our team stronger. Our patients, members and community come from a wide variety of backgrounds, and it takes a diverse workforce to make better health easier for all. We are proud to be an affirmative action, equal opportunity employer and all qualified applicants will receive consideration for employment regardless to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.
We are an Affirmative Action, Equal Opportunity Employer Women and Minorities are Encouraged to Apply. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of disability or their protected veteran status.
At Geisinger, our innovative ideas are inspired by the communities we serve – like our Fresh FoodFarmacy, a program that delivers life-saving healthy alternatives to patients with diabetes. With additional tools like our MyCode Community Health Initiative, one of the first health system genome sequencingprograms, and our new asthma app suite that we developed in partnership with AstraZeneca, it’s no wonder we’re ranked one of the Top 5 Most Innovative Healthcare Systems by Becker's Hospital Review. We continually work towards continuous improvement in a culture where everyone has a voice and firmly believe that better begins with all of us.Founded more than 100 years ago, Geisinger serves more than three million residents throughout central, south-central and northeastern Pennsylvania and southern New Jersey. Our physician-led system is comprised of 30,000 employees, including 1,600 employed physicians, and consists of 1...3 hospital campuses, the Geisinger Health Plan, Geisinger Commonwealth School of Medicine and two research centers. What you do at Geisinger shapes the future of health and improves lives – for our patients, communities, and you.
We’re here to answer your product-related questions
NAHQ wants to partner with you and your organization as you explore how to elevate the profession and advance the discipline of healthcare Quality & Safety.
Need customer service assistance?
For customer service issues, contact us at info@nahq.org or call us at (847) 375-4720. The team is available Monday-Friday from 8 AM-4:30 PM CT.
Important Information for CPHQ Recertification
The recertification process has been streamlined. Unlike previous years, you don’t need to list out your CE activities at the time of completing your application. Instead, you will be asked to attest to having met the requirements, further aligning with the honor-based system of recertification. In the event that your application is randomly selected for audit, you may be required to list your CE activities and submit supporting documentation.
While you may participate in NAHQ learning opportunities (Learning Labs, JHQ articles, etc.), you can only claim CE credit once for each activity. Therefore, if you’ve previously earned CE from a NAHQ learning opportunity, you can’t claim it again, nor will you see the repeat CE appear in your “My Learning� tab. This includes activities used in previous recertification cycles.
Remember, if you’re recertifying during the grace period (1/1/24-1/31/24), you already had to earn your CE hours by Dec 31, 2023.
You still have time! Register today for a multi-day virtual event that addresses the most urgent and important issues facing healthcare today that offers a full schedule of educational sessions organized around NAHQ’s twice-validated healthcare quality competency framework.
We are excited to announce the release of the book “UNSTOPPABLE: Inspiring Stories of Perseverance, Triumph and Joy from Trailblazing Women in Healthcare“.
Be inspired by nine leading healthcare trailblazers, including our own CEO Stephanie Mercado, who empower us all with their vision and passions.
You’ll notice we’ve simplified the application process to recertify. You will not have to list your CE activities at the time of applying*. Simply attest that you met the requirements to complete the application.
*In the event of an audit, CPHQs may need to list activities and upload documentation in their NAHQ account.
Quality Education Resources
Join this informative session, “Quality Education Resources� Thursday, June 22 from 11-11:30 a.m. CT. You will learn about the range of NAHQ quality education resources available to you and hear directly from universities about the benefits they realized from implementing NAHQ’s content within their courses.
Maintain a Pulse on the Latest Quality & Safety Benchmarking Data
Learn more about NAHQ’s enhanced Quality and Safety Benchmarking Program, which provides timely insights to help U.S. hospitals and health systems create data-driven business cases for their quality and safety resourcing.
Understand the Variability Among Your Quality Team Through Workforce Accelerator
Join us Tuesday, May 2, at 11 a.m. CT, to learn more about the different options available to engage with NAHQ’s enterprise-wide solution, Workforce Accelerator®. Options range in size and scope and are designed to meet the various budgetary and timing needs of health systems as they embark on their quality journeys. Register today!
Healthcare Quality and Safety Workforce Report: New Imperatives for Quality and Safety Mean New Imperatives for Workforce Development
The National Association for Healthcare Quality® (NAHQ) has conducted groundbreaking research on the advancement of the quality and safety agenda and has published the results in a new workforce report. NAHQ’s Healthcare Quality and Safety Report answers the question: “Is today’s healthcare workforce doing the work that will advance critical priorities of quality, safety, equity, value, and system sustainability?� The answer is no.
Updated Maintenance Dates: Sunday, February 5, 2023
Maintenance is planned for Sunday, February 5, from 11 p.m.-4 p.m. CT. During this time, you will not have access to the “My Learning” section of your NAHQ account. We apologize for any inconvenience this may cause and thank you for your patience.
NAHQ’s Organizational Membership Subscription will serve as a one-stop shop for healthcare quality and safety training and education. Attend the February 2, at 11 a.m. CT, info session to further understand the new offering that will continue NAHQ’s focus of “Quality in Action.�
NAHQ has published an updated version of the CPHQ exam content outline.
The new exam content will take effect on March 15, 2023. Candidates planning to take the exam before March 15, 2023, can access the current CPHQ exam content outline and related resources on our website.
Missed NAHQ Next? Don’t worry, you can purchase NAHQ Next on-demand and receive access to all content for 60 days from purchase. Benefit from actionable content that addresses issues head-on and features “how-tos” and results. Buy now and have the opportunity to receive 40+ CEs.
Healthcare Quality and Safety Workforce Report: New Imperatives for Quality and Safety Mean New Imperatives for Workforce Development
Member Briefing Workshop and Healthcare Quality Week Webinar
October 7, at 12 p.m. CT
NAHQ will host an exclusive member briefing workshop where NAHQ CEO Stephanie Mercado and NAHQ President-Elect Nidia Williams will review the workforce report in-depth and prepare you to discuss it with your team and leadership during Healthcare Quality Week.
October 17, at 12 p.m. CT
To kick off Healthcare Quality Week, (HQW) NAHQ will host a complimentary webinar with NAHQ leaders to discuss the report, its impact and how you can leverage the report to your advantage.
You still have time! Register today for a multi-day virtual event that addresses the most urgent and important issues facing healthcare today that offers a full schedule of educational sessions organized around NAHQ's twice-validated healthcare quality competency framework.