To use our talent, technique and technology to maximize the value of our clients’ receivables through respect for the debtor, effective collection/call center management, high ethical standards and strict adherence to applicable laws, regulations and policies.
“At CCH, you are in control of your job. Essentially, you are running your own business and it is up to you to make the most of it. The company provides the tools to be successful and lets you take the reins. I enjoy taking charge and the company encourages its people to do so.”
Rich Ryder Account Manager CCH
Position Details
Title:
Information Security Officer
Location:
Renton, WA
Time:
Full-time
Description:
The ERS Information Security Officer position is responsible for the development, implementation and management of an information security management program for the entire company. The individual will research and evaluate procedural and technical solutions that can be applied to ERS, manage the company’s response to security incidents, audits, implementation, and compliance with all systems and methodologies regarding information security.
Duties:
o Identify protection goals and objectives consistent with corporate strategic plan.
o Coordinate and perform all corporate audits including SAS70, ISO, and PCI DSS.
o Travel to all locations and perform internal security audits to insure compliance.
o The ISO will maintain knowledge of the ERS infrastructure both procedurally and technically so that they may understand the risk of system exposure, recommend realistic preventive measures, respond to security incidents and audits, and manage introduction of new security related systems and policies to the ERS environment.
o The individual will assign tasks, instruct, educate, and follow up with ERS staff to ensure that business requirements are met.
o On a daily basis, the ISO will review logs, trouble tickets and audits relating to security based issues and apply appropriate management techniques to resolve issues surrounding information security requirements in a timely and efficient manner.
o The ISO is expected to continually review and develop information security documentation as well as develop reports to keep IT and management apprised of information security threats and active attacks, incident response activities and planned system changes that can impact the production environment.
o The ISO must work with security vendors to facilitate risk analysis, vulnerability assessments, scans, penetration tests, and report back to management results and resolution requirements to resolve any security risks.
o The ISO must perform regular audits of all vendors that have any connectivity or access to ERS data.
o The ISO should provide technical advice and coordinate with management to schedule and review periodic audits of the information security policy. They will also be in front of all external audits as the primary liaison between clients, vendors, and ER Solutions, coordinating, documenting and presenting all required related materials to complete an audit.
o The ISO should possess the following skill set:
- Excellent documentation skills
- Project management
- IT background relating to IT security and it’s systems
- Proficiency in MS Project
- Can function as a representative of ERS in a professional fashion
- Interpersonal skills when relating to the needs of different areas and departments of the company
Requirements:
- BS in Information Systems, Computer Science, or IT equivalent
- Background in IT security systems
- 3 years experience with Information Security documentation
- 3 years CISSP Certification
- Experience with disaster recovery planning, testing, auditing, risk analysis, business resumption planning, contingency planning; TCP/IP firewalls, VPNs and other security devices; as well as contract and vendor negotiation experience.