Job Location: Available to
work Hybrid, Raleigh, NC
Job Description:
The Compliance Officer will be familiar with risk
management, comfortable leading internal risk assessments, and possess
knowledge of HIPAA and NIST privacy and security requirements for health
information networks.
The candidate will be allowed to work remotely but
will need to be onsite at short notice. There is a mandatory three week
training onsite at the beginning of the engagement. Once all staff return to
site the candidate will need to work onsite full time.
The NC HIEA Compliance Officer will ensure that operations follow all relevant
state and federal requirements for securely transacting health information via
the HIE Network, NC HealthConnex. The Compliance Officer will be familiar with
risk management, comfortable leading internal risk assessments, and possess
knowledge of HIPAA and NIST privacy and security requirements for health
information networks. This position will work closely with the NC HIEA
leadership team, DIT legal counsel, and DIT Privacy Team, and DIT Security and
Risk Management Team to ensure continual improvement of the NC HIEA’s security
and risk profile.
Responsibilities
Skills Set:
Skill | Required /Desired | Experience |
Knowledge of
privacy laws (state and federal such as HIPAA (preferred), PCI, CJIS); proven
risk management experience. | 3 years | |
Experience in creation of risk management strategies and policy
development to handle data breaches and other incidents | 3 years | |
Knowledge of NIST controls and experience with completing/conducting
assessments; written and verbal communication | 3 years | |
Strong conflict management skills in order to work with senior
management to ensure security and data protection rules and regulations are
in place | 3 years | |
Knowledge of
cybersecurity and privacy principles | 3 years | |
Ability to determine whether a security incident violates a privacy
principle or legal standard requiring specific legal action | 3 years | |
Ability to work
across departments and business units to implement organization’s privacy
principles and programs. | 3 years | |
Ability to develop, update, and/or maintain standard operating
procedures (SOPs) | 3 years | |
Ability to develop
clear directions and instructional materials | 3 years |