The IT Security and Compliance Coordinator is responsible for organizing and managing the documentation and processes required to ensure compliance with The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and all requirements defined by applicable regulations (e.g.
HIPAA, FERPA, GLBA
), contracts, or accreditation standards. Please Note this is a Salaried Hybrid Position that will require on-site attendance. (MI residents only or willing to relocate - at their expense, to Michigan) This position is NOT eligible for employer-sponsored work authorization (visa sponsorship), now or in the future. To share this job posting, please use this link.
BENEFITS
Wellness reimbursement.
Continuing education and tuition reimbursement.
Employer-funded retirement plan.
Two medical plan options: PPO and High Deductible Health Plan (HDHP) with employer HSA contribution.
Flexible work solutions based on position and department.
Up to four weeks of PTO accrual beginning in year one.
Paid holidays.
Paid volunteer time.
Paid preferred holiday.
DUTIES AND RESPONSIBILITIES
Works with organizational and IT Leadership to create, implement, and monitor security compliance policies, procedures, and processes. Creates and maintains administrative documentation and reports required to demonstrate compliance with applicable regulations, contracts, and accreditations. Educate staff, students, faculty, and residents on security procedures and practices through multiple mediums. Collaborate with IT staff to implement new policies, procedures, or controls based on current trends and new or upcoming requirements. Support IT Leadership reviewing contracts and agreements for technical requirements and compliance with existing obligations and requirements. Initiate periodic internal assessments of organizational compliance with existing obligations and requirements. Collaborate with technical staff and system owners to remediate or mitigate gaps identified during audits. Maintain "Compliance ScoreCards" to provide leadership insight into current compliance posture and gaps. Creates and manages documentation for incident response. Act as liaison between WMed administrative teams and auditors All other duties as assigned.