Jobs

Manager, Information Security

What you’ll do

In a few words…

Abarca is igniting a revolution in healthcare.  We built our company on the belief that with smarter technology we are redefining pharmacy benefits, but this is just the beginning…

Our Information Security team handles the organization’s security strategies, architecture, and practices to ensure the security of our cloud architecture, security policies, and sensitive information including PII and PHI data. This team focuses on identifying, monitoring, investigating, and responding to events that could lead to an incident or breach. The Information Security team is involved in planning, implementing preventative security measures, and overseeing the security operations to include protecting IT Infrastructure, Networks, Data, by identifying any exploitations.

As a Manager, Information Security, you will oversee the tactical implementation and execution of the company’s security policy, standards, guidelines, and procedures designed to detect, analyze, remediate, and communicate information security challenges. This position will be responsible for the day-to-day operations of the Information Security program that supports the long-term strategic security roadmap and ensures the security of our cloud infrastructure.  The Manager, Information Security will also be responsible for hiring, training, supervising, and mentoring cyber security professionals, while overseeing a variety of initiatives and activities tied to the company’s information security program. This may include risk management, development of policies & procedures, and security standards, while supporting technology acquisition, integration activities, incident response life-cycle (Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity), and overall alignment to multiple security and compliance frameworks. 

The fundamentals for the job…

  • Manage the day-to-day tactical execution of the overall information security program.
  • Develop and manage information security policies, standards, guidelines, and procedures to assess, balance, and minimize risks and ensure the confidentiality, integrity, and availability of systems and data.
  • Provide strategic risk guidance for IT projects, including the evaluation and recommendation of technical controls.
  • Create and manage enterprise information security and risk management awareness training programs. Provide formal training for all staff on relevant security best practices.
  • Identify areas for improvement and automation. Responsible for the creation, communication, and implementation of standard operation procedures (SOPs) and run books supporting and standardizing methodologies and processes of the Security Operations Team and the SOC.
  • Provide periodic reporting on the status of the information security program, including but not limited to continuous monitoring, threat environment, audits, incident response, etc. to enterprise risk teams, senior business leaders, and other identified stakeholders.
  • Manage security tools and services for authentication, authorization and other security services.
  • Perform scheduled vulnerability scanning and assessment, patch management and reporting for servers, switches, routers, and devices.
  • Provide meaningful visibility, guidance, insight, and analysis to senior information security management and the Company’s Board of Executives (CPC) with respect to information security risks and mitigations.
  • Create and execute policy and audit plans in coordination with the Compliance Group, including review of current security policies and relevant artifacts and update security requirements.
  • Deploy and manage applications to monitor cloud infrastructure security and intrusions.
  • Manage incident triage, determine scope, urgency, and potential impact of security incidents.
  • Drive incident response, resolution, and adjust procedures as applicable.
  • Provide guidance to the infrastructure team on security best practices around OS hardening, access logging, and patching.
  • Perform security gap assessments, implement remediations, and collaborate with external auditors on compliance.
  • Perform infrastructure vulnerability scans, pen testing, and collaborate with engineering teams on identified vulnerabilities for resolution.

What you’re made of 

The bold requirements…  

  • Bachelor’s Degree or Master’s Degree in Information Security or Computer Science or related field (In lieu of a degree, equivalent relevant work experience may be considered.)
  • 2+ advanced professional security certifications (e.g. CISSP, CISM, CISA, CRISC etc.)
  • 8+ years of experience in information security in a related role.
  • 3+ years of experience within a leadership role managing direct reports.
  • Experience with information security training, awareness programs, engaging audit committees, and leading regulatory compliance.
  • Experience and technical depth in one, or more technology areas and architectures, including Networking, Data Security, Infrastructure Security, Identity, Credential, and Access Management (ICAM), Endpoint/Platform Security, Distributed Technologies, Encryption.
  • Experience with Azure security best practices and security controls utilizing Azure services (AWS, GCP, OCI experience may be considered)
  • Experience with security requirements for HIPPA/HITECH, Sarbanes-Oxley, PCI-DSS, various Data Privacy Laws, etc.
  • Experience with cyber security frameworks like NIST CSF, NIST 800-53, ISO 27001, HITRUST, FedRAMP, 23 NYCRR 500, etc.
  • Availability to work rotating or irregular shifts, including weekends and certain holidays, per business or operational needs.
  • Excellent oral and written communication skills.
  • We are proud to offer a flexible hybrid work model which will require certain on-site work days (Puerto Rico Location Only.)

Physical requirements…

  • Must be able to access and navigate each department at the organization’s facilities.
  • Sedentary work that primarily involves sitting/standing.

At Abarca we value and celebrate diversity. Diversity, equity, inclusion, and belonging are guiding principles of Abarca and ensure Abarca’s workforce reflects the communities it serves.  We are proud to provide equal employment opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, medical condition, genetic information, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

 Abarca Health LLC is an equal employment opportunity employer and participates in E-Verify.  “Applicant must be a United States’ citizen. Abarca Health LLC does not sponsor employment visas at this time”

 The above description is not intended to limit the scope of the job or to exclude other duties not mentioned. It is not a final set of specifications for the position. It’s simply meant to give readers an idea of what the role entails.

#LI-REMOTE #LI-BP1

Cyber Security Jobs by Category

Cyber Security Salaries