Match score not available

DIRECTOR, INFORMATION SECURITY & DATA STEWARDSHIP

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Proven experience in conducting Security Threat and Risk Assessments (STRAs) in healthcare environments., Familiarity with Ministry of Health security policies and BC privacy legislation., Expertise in healthcare IT and medical systems, particularly in Interventional Cath Labs and Radiology., Strong communication and documentation skills for presenting findings to diverse audiences..

Key responsabilities:

  • Conducting STRAs to evaluate security risks and compliance requirements.
  • Identifying vulnerabilities and recommending appropriate mitigation strategies.
  • Collaborating with internal teams to ensure adherence to security policies and regulatory standards.
  • Documenting findings and providing detailed reports to support risk-informed decision-making.

Workiy Inc. logo
Workiy Inc. Information Technology & Services SME https://www.workiy.com/
11 - 50 Employees
See all jobs

Job description

This is a remote position.

The Client is looking for Security Consultant will be responsible for conducting Security Threat and Risk Assessments (STRAs) for net-new and addendum requests related to DPPE systems and technologies within the scope of the Interventional Cath Labs / Radiology Project at SMH.

Requirements
Proven Experience in Security Threat and Risk Assessments (STRAs):
  • Extensive experience conducting STRAs for healthcare environments, preferably within BC’s health sector.
  • Familiarity with Ministry of Health security policies, standards, and risk assessment frameworks.

Healthcare IT and Medical Systems Expertise:
  • Understanding of clinical and diagnostic systems, particularly in Interventional Cath Labs and Radiology.
  • Experience assessing security risks in integrated hospital environments and electronic health record (EHR) systems.
Regulatory and Compliance Knowledge:
  • Strong grasp of BC privacy legislation (e.g., FIPPA) and healthcare security compliance requirements.
  • Knowledge of security best practices for medical device connectivity and data protection.

Technical and Risk Management Skills:
  • Experience with network security, application security, and third-party risk management.
  • Ability to analyze system architectures, data flows, and security controls.

Project-Based Consulting Experience:
  • Ability to work within tight project timelines and collaborate with multiple stakeholders.

Communication and Documentation Skills:
  • Strong ability to document security findings, risk assessments, and mitigation strategies in a clear and actionable manner.
  • Effective communication skills to present risk findings and recommendations to both technical and non-technical audiences.


Roles and Responsibilities: 
  • Performing STRAs to assess security risks and compliance requirements.
  • Identifying vulnerabilities and recommending mitigation strategies.
  • Collaborating with internal security, clinical, and IT teams to ensure alignment with security policies and regulatory standards.
  • Documenting findings and providing detailed reports to support risk-informed decision-making.
  • Supporting the project team in addressing security concerns throughout the implementation timeline.



Required profile

Experience

Industry :
Information Technology & Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Problem Solving
  • Communication
  • Collaboration

Related jobs