Healthpartners - Saint Paul, MN

posted 4 months ago

Full-time
Saint Paul, MN
Professional, Scientific, and Technical Services

About the position

HealthPartners is currently seeking a Cyber Security Analyst/Role-Based Access Control Specialist (RBAC) to join our team. This position is critical to the overall security of the HealthPartners organization and plays a pivotal role in creating and maintaining application and business roles within our Identity and Access Management (IAM) system. The RBAC Specialist will be responsible for efficiently creating user accounts (Identities) and provisioning them with the appropriate access so that users can perform the necessary functions of their roles. This role requires a strong understanding of RBAC principles, excellent communication skills, and the ability to collaborate effectively with cross-functional teams. The ideal candidate will have a solid background in Information Technology and Information Security, with a focus on role-based access control. The RBAC Specialist will develop and maintain application and business roles within the RBAC framework to ensure effective access control across our systems and applications. This includes mapping entitlements and permissions to appropriate roles based on job functions and organizational requirements, as well as enforcing RBAC policies and standards to ensure compliance with regulatory requirements and organizational security policies. In addition to technical skills, the role requires strong analytical and critical thinking abilities, with a keen attention to detail. The RBAC Specialist will also provide support for RBAC-related inquiries, troubleshoot access issues, and perform role modifications as needed. Collaboration with IAM team members, application owners, and other stakeholders is essential to integrate RBAC into existing and new systems. Furthermore, the specialist will provide training and education to end users and stakeholders on RBAC principles, best practices, and procedures.

Responsibilities

  • Develop and maintain application and business roles within the RBAC framework to ensure effective access control across our systems and applications.
  • Map entitlements and permissions to appropriate roles based on job functions and organizational requirements.
  • Enforce RBAC policies and standards to ensure compliance with regulatory requirements and organizational security policies.
  • Provide support for RBAC-related inquiries, troubleshooting access issues, and performing role modifications as needed.
  • Collaborate with IAM team members, application owners, and other stakeholders to integrate RBAC into existing and new systems.
  • Provide training and education to end users and stakeholders on RBAC principles, best practices, and procedures.

Requirements

  • Bachelor's degree or equivalent experience
  • 5+ years' experience in Information Technology
  • 3+ years' experience in Information Security
  • Excellent communication and people skills to collaborate with stakeholders to gather requirements for role creation, ensuring that roles accurately reflect the access needs of different user groups.
  • Proven experience in role-mining; discover, analyze, define, and design using SailPoint Identity IQ or something similar.
  • Strong understanding of IAM principles, including authentication, authorization, and access control.
  • Experience with RBAC tools and technologies, such as identity governance platforms and access management solutions.
  • Desktop tool proficiency including Microsoft products (e.g., Word, Excel, Access, and PowerPoint)
  • Knowledge of the security aspects of multiple system platforms, operating systems, software communications, and network protocols.
  • Experience coordinating projects.

Nice-to-haves

  • 5+ years' cyber security experience strongly preferred.
  • 2+ years' RBAC experience strongly preferred.
  • CISSP or CISA Certification
  • Knowledge of structured methodologies and standards such as ISO 27000, NIST, PMI, ITIL, CMMI, OWASP, and CoBit
  • Knowledge of federal and state security-related legislation including HIPAA, PCI, JCAHO, NCQA
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service