Canadian National Railway Company Logo

Canadian National Railway Company

HIPAA SME

Posted 25 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in CAN
Expert/Leader
Remote
Hiring Remotely in CAN
Expert/Leader
Provide HIPAA privacy and security subject-matter expertise to OCR: review complaints and breach reports, evaluate technical sufficiency of security submissions (pen tests, forensics, vulnerability assessments), produce technical reports and recommendations, advise on HIPAA/NIST/ISO-based policies and security programs, and support incident response, risk analysis, and security architecture efforts.
The summary above was generated by AI

The HIPAA Subject Matter Expert supports the Health and Human Services (HHS), Office for Civil Rights (OCR) promoting the right to access health information and protection of the privacy and security of this information. These highly trained and highly skilled consultants and analysts are integral to the success and performance of OCR and to further OCR’s mission.

Chickasaw Nation Industries, Inc. serves as a holding company with multiple subsidiaries engaged in several lines of business (Technology, Infrastructure & Engineering, Health, Manufacturing, Public Safety, Consulting, and Transportation) for the federal government and commercial enterprises. A portion of our profits is used to support Chickasaw citizens. We are proud to support the economic development and long-term viability of the Chickasaw Nation and its people. CNI offers premium benefits eligible on the first day of hire to full time employees; (Medical - Dental – Vision), Company Life Insurance, Short-Term and Long-Term Disability Insurance, 401(K) Immediate Vesting, Professional Development Assistance, Legal Aid Assistance Program, Family Planning / Fertility Assistance, Personal Time Off, and Observance of Federal Holidays.

As a federal contractor, CNI is a drug-free workplace and adheres to the Federal Controlled Substance Act.   

ESSENTIAL REQUIREMENTS

  • Must be able to obtain and maintain the required customer clearance for access to systems, facilities, equipment and property. 

  • Preference will be given to candidates with relevant industry certifications from CISSP, CISM, CIPP/CIPT/CIPT.

  • Ten (10) years of relevant cybersecurity experience is preferred.

  • Experience in auditing and generating audit reports is required.

  • Fundamental knowledge of basic systems analysis.

  • Knowledge of a broad range of relevant computer systems, applications, and/or related equipment.

  • Knowledge of computer security procedures and protocol.

  • Basic knowledge of advanced operating system, network, or application management tasks.

  • Knowledge of current technological developments/trends in area of expertise.

  • Knowledge of federal copyright laws as they pertain to the use of computer software.

  • Ability to integrate emerging technologies and applications into current environment and to identify technical specifications to meet user needs including operating system and network or application configuration.

  • Ability to identify technical specifications to meet user needs including operating system and network or application configuration.

  • Skills in planning, organizing, and adapting within a multi-tasking environment.

  • Strong interpersonal skills, flexibility, and customer service orientation.

  • Ability to gather facts and data for technical proposals and to expand upon them or develop alternatives and to evaluate emerging technologies and identify their potential impact within the existing environment.

  • Ability to evaluate emerging technologies and identify their potential impact within the existing environment.

  • Ability to analyze complex computer problems and provide solutions.

  • Ability to communicate effectively, both orally and in writing.

  • Ability to communicate technical information to non-technical personnel.

  • Ability to develop and deliver presentations.

KEY DUTIES AND RESPONSIBILITIES

Essential duties and responsibilities include the following. Other duties may be assigned.

  • Reviews security and privacy complaints, data breach notification and cybersecurity incident reports and other correspondence and evidence to determine whether complaints, self-reported breaches or breach notification reports indicate non-compliance with the HIPAA Security Rule. Reviews data provided by the healthcare organizations across the nation to assess the overall impact of security and privacy incidents.

  • Evaluates and determines the technical sufficiency of submissions from HIPAA covered entities and business associates in response to data and documentation requests (i.e. Assessing reports related to security baselines, penetration tests, vulnerability assessments, and digital forensics).

  • Documents processes, standard operating procedures and system requirements; develops reports summarizing the analysis along with formulating recommendations for OCR to consider for future action.

  • Develops written reports with technical security analyses, summaries, and recommendations for action, reports on root causes of problems, efficiency, and support needs.

  • Provides expertise in the development and evaluation of health information privacy policies and technologies, specifically regarding protected health information; deidentified/re-identified health information; limited data sets.

  • Provides subject matter expert analysis, evaluation, and recommendations based on national security standards (NIST), industry best practices from the International Organization for Standardization and implementation specifications of the HIPAA

  • Security Rule.

  • Provides DIN designing, implementing, and managing information security, data protection, and risk management programs, including policies, procedures, and controls for protected health information based on HIPAA requirements.

  • Provides advisory expertise in the areas of risk analyses, vulnerability assessments, incident response, security architecture, physical security, business continuity and disaster recovery, enterprise mobility, threat intelligence and analysis, security awareness and

  • online safety, and resolution of highly complex security projects and issues.

  • Works well with programmers, developers, content managers, and other key personnel in an interactive development situation.

EDUCATION/EXPERIENCE

Minimum educational experience is a Bachelor’s degree from an accredited university with the focus on Cybersecurity, Computer Science, Information Sciences, or other comparable fields of Study.

PHYSICAL DEMANDS

Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic.

The physical demands described here are representative of those that must be met by an employee to perform successfully the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this job.

EOE including disability/vet.

*Please note, that this position is contingent upon the award or funding. The essential duties, experience, education requirements, and salary are subject to change.*

The estimated pay range for this role is $125K to $135K, with the final offer contingent on location, skillset, and experience. 

CNI offers a comprehensive benefits package that includes:

  • Medical

  • Dental

  • Vision

  • 401(k)

  • Family Planning/Fertility Assistance

  • STD/LTD/Basic Life/AD&D

  • Legal-Aid Program

  • Employee Assistance Program (EAP)

  • Paid Time Off (PTO) – (11) Federal Holidays

  • Training and Development Opportunities

Your application submission will be considered for all potential employment opportunities with Chickasaw Nation Industries (CNI).

HQ

Canadian National Railway Company Montréal, Québec, CAN Office

Montréal, Canada

Similar Jobs

8 Minutes Ago
Remote
Canada
Senior level
Senior level
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Lead full-stack development for Toast IQ, owning user experience, backend services, and product integrations. Drive architecture, mentor engineers, participate in design and code reviews, and apply ML/LLM capabilities to improve product velocity and reliability.
Top Skills: Ai ToolsDistributed SystemsDynamoDBEnterprise MessagingGraphQLJavaKotlinLarge Language ModelsMachine LearningMicroservicesReactRest
21 Minutes Ago
Easy Apply
Remote or Hybrid
Canada
Easy Apply
Senior level
Senior level
eCommerce • Healthtech • Kids + Family • Retail • Social Media
Build and maintain large-scale marketplace systems across revenue, product, and platform teams. Lead architecture and process improvements, deploy and monitor production services, mentor engineers, and drive adoption of AI-first development practices to increase velocity and code quality.
Top Skills: AWSChatgptClaudeCursorGithub CopilotJavascript/Node.JsMySQLPython/DjangoReactRedisRuby On RailsSidekiq
21 Minutes Ago
Easy Apply
Remote or Hybrid
Canada
Easy Apply
Expert/Leader
Expert/Leader
eCommerce • Healthtech • Kids + Family • Retail • Social Media
Lead full‑stack engineering for Babylist Health: architect and deliver scalable features, mentor engineers, collaborate with product, and build systems to support major revenue growth while leveraging AI to increase velocity and quality.
Top Skills: AIAndroidAWSiOSMySQLNode/ExpressPython/DjangoReactRedisRuby On RailsSidekiq

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account