Make a difference and advance your career with Chong Hua Hospital, the Philippines’ premier healthcare destination!
Chong Hua Hospital is lookinf to hire an Information Security Engineer who provides the vision and strategies necessary to ensure the confidentiality, integrity, and availability of CHH electronic information by communicating risk to senior administration, creating and maintaining enforceable policies, supporting processes, and ensuring compliance with regulatory requirements. S/he makes these possible through coordinating activities with all CHH hospital staff, including the evaluation, procurement, deployment of security-related products, develops and coordinates information security awareness programs. Additionally, s/he ensures the hospital system-wide disaster recovery and incident response plans are in place
Job Duties & Responsibilities
Creates and implements information security policies, strategies, both short-term and long-range, in support of the CHH hospital management goals.
- Directs an ongoing, proactive risk assessment program for all new and existing systems and remains familiar with the CHH’s goals and business processes so effective controls can be put in place for those areas presenting the greatest information security risk.
- Communicates risks and recommendations to mitigate risks to the senior leadership team by communicating in non-technical, cost/benefit terms so decisions can be made to ensure the security of information systems and information entrusted to both Chong Hua Hospital Cebu and Mandaue.
- Oversees all ongoing activities related to the development, implementation, and maintenance of the CHH’s information security policies and procedures by ensuring these policies and procedures encompass the overall security of electronic information at rest or in motion within the hospital in process and procedure development, ensuring they are not in conflict with CHH policies.
- Assists CHH hospital staff to ensure regulatory compliance in areas such as the Electronic Payment- Data Security Standards (PCI-DSS) or the Health Insurance Portability and Accountability Act (HIPAA), and works with CHH Data Privacy Officer to ensure full compliance in securing Protected Health Information (PHI).
- Ensures vulnerabilities are managed by directing periodic vulnerability scans of servers connected to CHH Cebu and Mandaue networks
- Develops information security awareness training programs, and works with CHH departments to present them to hospital staff as appropriate, ensuring adherence to best practices.
- Acts proactively to prevent potential disaster situations by ensuring that proper protections are in place, such as intrusion detection and prevention systems, firewalls, and effective physical safeguards, and provides for the availability of computer resources by ensuring a business continuity/disaster recovery plan is in place to offset the effects caused by intentional and unintentional acts.
- Contributes to a work environment that encourages knowledge of, respect for, and development of skills to engage with those of other cultures or backgrounds.
- Continuously monitor security events, using security information and event management (SIEM) or any monitoring tools available to detect suspicious activities.
Qualifications
Must possess at least a bachelor’s degree in engineering (Computer/Telecommunications), Computer Science, Information Technology or equivalent.
- With at least five (5) years of relevant work experience Information Technology in a business environment.
- Healthcare industry experience is a plus.
- Professional Certification: (CEH, Certified Cyber Security Analyst, NSE Certified, Certified CompTIA Security + etc.) One of the security certifications is required.
- Experience with information systems in a 24×7, “real-time” environment supporting a service delivery organization.
- Experience in virtualization technologies (VMWare & Hyper-V) to apply to hardware, software, memory, storage, data and network, an advantage.
- Ability to work with the technical resources, understand customers’ needs and translate these needs into efforts to deliver the final solution; customer service driven with a problem resolution focus.
- Knowledge of applicable data privacy practices and laws as they relate to technology issues
- Must be able to lift 35 lbs. of equipment unassisted
- Basic understanding of hospital standards (JCI, DOH Bench book, etc.); Knowledge of privacy regulations, ability to maintain patient privacy in daily role and other healthcare standards, an advantage.
- Demonstrated understanding of basic corporate office software, including Microsoft Office 365 applications.
- Excellent communication skills. Proficiency in the Visayan dialect and/or Tagalog is required.
