Overview
Looking to be part of something more meaningful? At HonorHealth, you'll be part of a team, creating a multi-dimensional care experience for our patients. You'll have opportunities to make a difference. From our Ambassador Movement to our robust training and development programs, you can select where and how you want to make an impact. HonorHealth offers a diverse benefits portfolio for our full-time and part-time team members designed to help you and your family live your best lives. Visit honorhealth.com/benefits to learn more. Join us. Let's go beyond expectations and transform healthcare together. HonorHealth is one of Arizona's largest nonprofit healthcare systems, serving a population of five million people in the greater Phoenix metropolitan area. The comprehensive network encompasses six acute-care hospitals, an extensive medical group with primary, specialty and urgent care services, a cancer care network, outpatient surgery centers, clinical research, medical education, a foundation, an accountable care organization, community services and more. With nearly 17,000 team members, 3,700 affiliated providers and close to 2,000 volunteers dedicated to providing high quality care, HonorHealth strives to go beyond the expectations of a traditional healthcare system to improve the health and well-being of communities across Arizona. Learn more at HonorHealth.com.
Responsibilities
Job Summary
Under the direction of Leadership, the Mitigation Specialist is responsible for mitigating and documenting medical device vulnerabilities. This role partners with Health Technology Management and Information Technology to patch medical devices based on mitigation directives, vendor information and enterprise security policies. The Mitigation Specialist has broad knowledge of medical devices, IT systems, information security and general systems infrastructure experience that includes security architecture, security products and techniques to mitigate security risk and responsible to understand and conform to HonorHealth's project and change management methodologies. In addition, this position may require facilitating off hour work functions in support of incidents, upgrades, patches, and project task fulfillment.
Essential Functions
- Perform security risk assessments, manages risk, and provides advice for the implementation of compensating security controls on health technology. Responsible for patch management of enterprise systems per policy to reduce security vulnerabilities with minimal supervision. Populates tables and database with some assistance from Vendor and/or Technical staff. Collaborates in an integrated approach to eliminate the potential for a negative impact to our customers and patients. Coordinate and installs health technology security patches and firmware updates and identifies and implements vendor/manufacturer recommended patching and update schedules. Document results of mitigation directives in the CMMS system and regularly reports on mitigation progress. Perform research, gap analysis and data collection specific to health technology security and contributes to strategy and roadmap development.
- Demonstrate excellent interpersonal, organizational and communication skills. Communicates effectively (written and oral) across all levels of the organization and has the ability to determine the appropriate forum for each method. Develop health technology security standards, policies and procedures and interfaces with other departments to ensure their implementation, performs regular verification. Assists with the design and implementation of medical device security infrastructure, IoMT solution and system integrations. Demonstrate the ability to prioritize and manage individual workload with minimal assistance. Collaborates effectively with team members to adjust priorities based on business needs. Must be willing and able to travel to any/all HonorHealth and affiliated sites.
- Assist with the change management, project management, and documentation policies and standards, established by Support Service, requests and new initiatives. May lead low to moderate complexity projects as assigned. Promote security awareness program.
- Understand and follow established change management procedures for testing, documenting, and communicating system changes.
- Perform other duties as assigned. Complies with HonorHealth policies and procedures in addition to the Mission, Vision and Values.
Education
- Bachelor's Degree in Biomedical Equipment Technology, Electronics, Computer Science, Information Systems - Preferred
- Associate's Degree or 2 years' work related experience in Biomedical Equipment Technology, Electronics, Computer Science, Information Systems, or equivalent certification - Required
Experience
- 1 to 3 years of relevant operational information security or HTM/CE/Biomed operational experience and medical device security. - Required
- 1 year of relevant operational medical device security - Preferred
Licenses and Certifications
- CISSP, SANS GSEC, CompTIA Security+, CEH, CBET, or CCE certification - Training and/or certification - Preferred
|