|
|
 |
 |
|
|
|
|
|
|
Job Summary
|
Salary Range: $76,111-$109,409/year. The starting salary for this position would be determined with consideration of the successful candidate’s relevant education and experience, and would be in alignment with the provincial compensation reference plan. Salary will be prorated accordingly for part time roles.
Job Summary:
In accordance with the Mission, Vision and Values, and strategic directions of Provincial Health Services Authority patient safety is a priority and a responsibility shared by everyone at PHSA, and as such, the requirement to continuously improve quality and safety is inherent in all aspects of this position. The Technical Security Analyst reports to the Manager, Security, and provides technical security leadership and expertise as well as supports the privacy and security auditing capability for clinical applications within Provincial Digital Health and Information Services (PDHIS) that provides services in the Lower Mainland to Provincial Health Services Authority (PHSA), Vancouver Coastal Health (VCH) and Providence Health Care (PHC). In addition to demonstrating general security-related knowledge, the Technical Security Analyst is a proven expert in at least one core technical competency (such as boundary controls, antivirus, intrusion detection/prevention, monitoring/reporting) and consults on projects that require those skills. Responsibilities include conducting system audits and reviews to determine and investigate system breaches, analyzing networks, systems and applications using a variety of Risk Management and Security Audit methodologies, and developing comprehensive reports detailing findings. Analyzes findings and produces recommendations to correct unmitigated risks. Works with management staff across the three health organizations to design and implement secure system solutions and works closely with Privacy team to investigate cases of internal and/or external network access attempts and breaches.
Duties/Accountabilities:
- Provides technical leadership in the design, development, implementation and operations of core information technology and security technologies. Provides technical configuration support for audit and logging solutions. Maintains and configures central audit and logging solutions, including the facilitation of onboarding new log sources.
- Provides focused, information-security-related advice and expertise to various PDHIS projects and acts as a resource for information security issues for stakeholders both internal and external to PDHIS (VCH, PHC, and PHSA). Acts as the subject matter expert for the privacy and security logging requirements.
- Develops and documents technical standards, processes, procedures, baselines and guidelines for information security to ensure the integrity and privacy of clinical and business information.
- Conducts risk assessments, security assessments and technical audits, and assists in application security assessments using a variety of approved methodologies, standards and best practices. Produces related reports and recommendations.
- Leads access attempt and breach investigations through audit report generation; identifies potential inappropriate accesses; assists stakeholders in conducting privacy and security investigations, threat investigations and incident response; and recommends follow-up disciplinary action as necessary.
Qualifications:
- A level of education, training, and experience equivalent to a Bachelor’s degree in Computer Science/Engineering, and five to seven (5-7) years’ of recent related experience in an information technology role that included information security, incident response and security threat analysis, preferably in a public sector and/or health care environment.
- Certification in a cyber security discipline (CISSP, CEH, SCF, CISA, SANS) is desirable.
- Active CISSP or SANS GIAC certification is preferred.
- Strong knowledge of Microsoft and Linux based operating systems and technologies along with the use of complex regex are required.
- Uses broad knowledge of a wide range of information security technologies such as firewall, Intrusion Detection/Prevention systems, Security Information Management solutions, and managed antivirus solutions to provide technical information security leadership.
- Applies strong knowledge of information security concepts and security technologies.
- Uses exceptional written communication skills and analytical abilities to conduct assessments, document and analyze finding and prepare related recommendations.
- Proactively interacts with stakeholders at all levels to creatively achieve results in a dynamic environment.
- Ability to translate business and technical requirements.
- Uses strong oral communication skills to present technical information to a variety of audiences.
|
|
|
 |
|
|
|
|