Information Security Specialist
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Location: Dandridge
Dandridge - 207 W Main - Dandridge, TN 37725
Salary Range: $45,000.00 - $45,000.00 Salary/year
Position Type: Full Time
Education Level: 2 Year Degree
Category: Information Technology
OverviewPosition Summary: The Information Security Specialist is a core member of the Information Security Department (Info Sec) within West Care’s Information Services Division (iServ). This position collaboratively designs, implements, operates, and continuously improves technical and administrative security controls to protect the confidentiality, integrity, and availability of West Care’s information assets. The role requires professional judgment, technical analysis, and proactive ownership of security outcomes, including after‑hours incident monitoring through a rotating on‑call schedule.
EssentialJob Functions
- Works with the Director of Information Security and Chief Information Officer (CIO) to build a team‑oriented environment that promotes dependability and fairness and rewards collaboration, information sharing, tolerance, and open‑mindedness.
- Ensures that West Care’s information security program complies with relevant laws/regulations (HIPPA, 42 CFR Part 2, Red Flags Rule, various state data protection laws, etc.), accreditation standards (The Joint Commission and CARF) and internal policies and standards.
- Adheres to all West Care’s policies, plans, standards, and procedures and helps enforce those related to information security, vendor risk management, business continuity, and record retention and management.
- Performs the following primary responsibilities under the oversight of the Director of Information Security:
- Manages, monitors, and enhances the controls for a strategic, comprehensive information security program.
- Evaluates staff submissions of suspicious emails, determines containment or escalation steps, and communicates outcomes and lessons learned.
- Designs and delivers phishing simulations, awareness surveys, and role‑based security training, using results to drive measurable improvement in organizational security posture.
- Develops, updates, distributes, and presents security awareness materials and communications tailored to technical and non‑technical audiences.
- Performs information security facility reviews and track issues until resolved.
- Mentors and trains members of the Security Champions program.
- Develops, updates, distributes, and presents security training and awareness materials.
- Supports the primary responsibilities of Information Security Analysts when needed, including:
- Monitoring various information security systems, including those for asset inventory, data loss prevention, endpoint protection, security incident & event management, and vulnerability management.
- Analyzing data from various information security systems and reports findings when appropriate.
- Performing forensics investigations and associated tracking related to information security concerns and incidents. When necessary, assisting with the implementation of relevant incident response plans and emergency procedures.
- Performing access control reviews, configuration management reviews, security risk assessments, and vulnerability assessments.
- Monitoring threat intelligence and other industry information sources. Alerting the IT Department and/or management when necessary and appropriate.
- Remains knowledgeable of trends and developments in information security through ongoing training and professional development.
- Acts as a West Care representative and liaison with external partners/collaborators.
- Embraces/embodies the mission, vision, guiding principles, and goals of West Care.
- Performs other relevant duties as assigned.
- Must be honest and ethical, verifiable through character references.
- Must have the demonstrated ability to exercise good judgment and discretion.
- Must have adequate verbal and written communication skills, including effectively explaining complex technical concepts and issues to non‑technical and business audiences.
- Must have demonstrated proficiency with applicable technologies, including operating systems, network infrastructure, security monitoring tools, and Microsoft Office applications.
- Must learn…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).