HCA, Hospital Corporation of America Associate Information Security Access and Compliance Engineer in Nashville, Tennessee


The Security Controls Engineer is a technology and process focused security professional with an emphasis in information security controls, risk assessment, regulatory compliance, and security consultation. Applies information security concepts, knowledge, and skills to support a comprehensive information protection program. The Security Controls Engineer evaluates and monitors the current state of security controls across the organization related to people, process, and technology as well as with 3rd party vendors external to the organization.


• Assists in the collection of the top and most pressing IT security risks (regulatory, security of critical enterprise applications and infrastructure, vendors, etc.), analyze, monitor, and derive strategic decisions that balance risk with operation and economic costs of protective measures. • Assists in interviews with company senior management and business owners to confirm anticipated business effects resulting from the actual occurrence of any of the identified enterprise security risks. • Leverages inventory of key vendors, applications, processes, and infrastructure items and their impact to the top and most pressing IT security risks. Additionally, maps applications, processes, and infrastructure items to appropriate security risks. • Assists in activities to identify key controls (policy, procedure, practice, or organizational structure) that if implemented would provide reasonable assurance that security objectives will be achieved and undesired events will be prevented or detected and corrected • Assists in activities to review, develop, and implement security controls plans, vendor security agreements, and security exceptions to control standards. • Assists in activities to conduct technical security reviews and assessments of vendors, applications, processes, and IT infrastructure. • Assists in activities related to the analysis of data collected during security reviews and assessment of vendors, applications, processes, and IT infrastructure in order to determine current state of security risk across the company. • Assists in activities to develop remediation plans to address issues discovered as result of security reviews and/or assessments of vendors, applications, processes, and IT infrastructure. Works with management to assign remediation responsibilities, actions, and priorities. • Assists in activities to monitor and track remediation activities to address weaknesses and issues discovered through security reviews or audits of vendors, applications, processes, and IT infrastructure. • Assists in activities to develop strategies to ensure compliance with security standards as well as regulatory and audit issues. • Assists in activities to provide periodic reporting including assessment findings and recommendations for improvement to applicable constituencies (e.g., executive management, facility leadership, and governance committee). •Assists in identifying security related regulatory requirements (ie. PCI-DSS, SOX, HIPAA), and interacts with internal and external assessors and auditors to ensure ongoing compliance.


Less than 1 year of experience is needed for a successful applicant.


College graduate is preferred.


/Certifications (preferred, not required):/

• CISSP Certified Information Systems Security Professional • GSEC GIAC Security Essentials Certified • CISA Certified Information Systems Auditor • PCIP PCI Professional Training • HCISPP Healthcare Information Security and Privacy Practitioner

/Preferred areas of experience:/

• Security Technologies / Methodologies • IT Audit/Risk Management • Information Security Metrics and Reporting • Systems Control Review Process • Application/Infrastructure Control Review Process

Working knowledge of the COSO and COBIT methodologies Experience with ISO17799, HIPAA, Sarbanes-Oxley, PCI-DSS Experience with IT risk, regulatory, or compliance responsibilities Possession of excellent analytical and interpersonal skills Possession of excellent oral and written communication skills

Title: Associate Information Security Access and Compliance Engineer

Location: Tennessee-Nashville-Corporate Main Campus

Requisition ID: 10207-19224