Proven experience in conducting Security Threat and Risk Assessments (STRAs) in healthcare environments., Familiarity with Ministry of Health security policies and BC privacy legislation., Expertise in healthcare IT and medical systems, particularly in Interventional Cath Labs and Radiology., Strong communication and documentation skills for presenting findings to diverse audiences..
Key responsabilities:
Conducting STRAs to evaluate security risks and compliance requirements.
Identifying vulnerabilities and recommending appropriate mitigation strategies.
Collaborating with internal teams to ensure adherence to security policies and regulatory standards.
Documenting findings and providing detailed reports to support risk-informed decision-making.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Workiy provides digital solutions and staffing services, utilizing our patented delivery model and a unique and flexible, client-centric approach to tackling technology's biggest challenges. We don’t have “clients” we have partners! Our mission is to enable your talented teams and amazing systems to assist your business in optimally achieving its goals. The Workiy team, brings to the table, more than 20+ years of experience in the technology industry across many verticals in both the private and public sector.
The Client is looking for Security Consultant will be responsible for conducting Security Threat and Risk Assessments (STRAs) for net-new and addendum requests related to DPPE systems and technologies within the scope of the Interventional Cath Labs / Radiology Project at SMH.
Requirements
Proven Experience in Security Threat and Risk Assessments (STRAs):
Extensive experience conducting STRAs for healthcare environments, preferably within BC’s health sector.
Familiarity with Ministry of Health security policies, standards, and risk assessment frameworks.
Healthcare IT and Medical Systems Expertise:
Understanding of clinical and diagnostic systems, particularly in Interventional Cath Labs and Radiology.
Experience assessing security risks in integrated hospital environments and electronic health record (EHR) systems.
Regulatory and Compliance Knowledge:
Strong grasp of BC privacy legislation (e.g., FIPPA) and healthcare security compliance requirements.
Knowledge of security best practices for medical device connectivity and data protection.
Technical and Risk Management Skills:
Experience with network security, application security, and third-party risk management.
Ability to analyze system architectures, data flows, and security controls.
Project-Based Consulting Experience:
Ability to work within tight project timelines and collaborate with multiple stakeholders.
Communication and Documentation Skills:
Strong ability to document security findings, risk assessments, and mitigation strategies in a clear and actionable manner.
Effective communication skills to present risk findings and recommendations to both technical and non-technical audiences.
Roles and Responsibilities:
Performing STRAs to assess security risks and compliance requirements.
Identifying vulnerabilities and recommending mitigation strategies.
Collaborating with internal security, clinical, and IT teams to ensure alignment with security policies and regulatory standards.
Documenting findings and providing detailed reports to support risk-informed decision-making.
Supporting the project team in addressing security concerns throughout the implementation timeline.
Required profile
Experience
Industry :
Information Technology & Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.