Asurion Flashcards

1
Q

The Technology Audit & Compliance Architect will design and implement programs to ensure compliance with regulatory and contractual requirements and industry standards (to include HIPAA and PCI) for Asurion, globally. Responsibilities include leading security-related technology audits to drive compliance and alignment of technology resources.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

As part of our Trust Office team, you will work to ensure that our systems and services are designed, operated, and protected to maintain customer trust and regulatory compliance.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

You will partner with stakeholders across Asurion to execute a risk management approach, identify risks, and act as a thought leader who recommends and leads risk mitigation strategies with cross-functional teams across Asurion.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You will work independently with the ability to prioritize workloads, remain flexible, and maintain a strong attention to detail in a fast-paced environment while supporting multiple, simultaneous programs.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Essential duties & responsibilities:

A

Use your in-depth knowledge of regulatory compliance, IT security, and strong customer skills to act as the subject matter expert to internal technology and operations teams in a Trusted Advisor capacity to assist their understanding of requirements (i.e. HIPAA, PCI, etc) related to their applications.
Develop the HIPAA compliance program from risk identification to executive reporting.
Conduct and complete pro-active HIPAA assessments on behalf of the company to ensure the company’s ability to protect PHI data.
Lead regulatory remediation projects and risk mitigation efforts. Track and manage action plans for remediation of audit findings. Perform analysis and reporting of compliance gaps.
Provide subject matter expertise related to PCI, HIPAA or client security requirements to internal technology and operations teams to ensure Company’s ability to maintain compliance when modifying or implementing applications involving sensitive data.
Implement best in class Risk & Compliance Management practices with minimal impact to the business.
Lead Asurion’s response to client audit requests and coordinate collection of audit artifacts.
Monitor issues to provide assurance reporting of how Company is complying with specific country and industry regulatory requirements and the internal control framework in order to maintain a compliant, audit-ready posture.
Coordinate and represent Asurion in negotiations with external auditors.
Train audit participants in audit preparation and response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Education and/or formal training:

A

BS/BA Computer Science or equivalent work experience
Must currently hold one or more of the following security certifications:
o CISSP or CISM

Must currently hold one or more of the following audit certifications:
o CISA, GSNA, IRCA, ISMS Auditor, or Certified ISO 27001 Lead/Internal Auditor

PCI QSA or ISA certification desirable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Here’s what you’ll bring to the team:

A

5+ years progressive experience in information security or technology audit, including experience with issue resolution and leading teams in a cross-functional setting.
Experience in technology audit, risk analysis, and compliance testing.
Good working knowledge of security regulations and industry best practices.
In-depth knowledge of HIPAA and demonstrated experience with HIPAA program development
5+ years leading global regulatory compliance efforts (e.g. HIPAA, PCI, SOX, Privacy).
Experience evaluating the design and effectiveness of IT controls.
Knowledge of auditing frameworks and international standards, such as ISO 27001/27002, PCI DSS, HIPAA/HITRUST, SSAE 18, COBIT and ITIL.
Experience or familiarity with governance, risk and compliance (GRC) tools such as ServiceNow.
Strong analytical and problem resolution skills. Exceptional business judgment, with the ability to think strategically and give practical advice by balancing business needs with risks.
Broad and deep technical knowledge across multiple, diverse technical configurations, technologies and processing environments.
Exceptional interpersonal skills in areas such as teamwork, collaboration, facilitation, negotiation, and persuasiveness.
Excellent communication (oral, written, presentation) skills. Ability to communicate effectively at all levels of the organization.
A practiced ability to influence peers, customers and project teams to make security-minded decisions and changes.
Must be self-directed, organized and have excellent time management skills.
Ability to work in a fast-paced, dynamic environment while maintaining high quality output and a positive working relationship with peers and management.
Ability to operate under ambiguous circumstances, address uncomfortable issues, and leverage data to make informed decisions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Other position considerations:

A

Required to read and follow all company policies and procedures.
Ability to handle proprietary and sensitive information in a confidential manner.
While the schedule is generally a Monday through Friday daily schedule, this position may require some weekend and evening assignments as well as availability during off-hours for participation in scheduled and unscheduled activities.
May involve travel up to 10% of the time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Our aim is to continually evolve our privacy program by finding strategies, processes and mechanisms that scale across geographies and our various businesses and functions in a manageable, repeatable way.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Asurion’s privacy team focuses on delivering sound risk management and outputs that demonstrate compliance and accountability.

A
  1. “Is the corporation’s compliance program well designed?“
  2. “Is the program being applied earnestly and in good faith?“ In other words, is the program adequately resourced and empowered to function effectively?
  3. “Does the corporation’s compliance program work“ in practice?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Serve as a privacy, compliance, and data protection expert and a primary point of contact for customers and colleagues.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Collaborate with the Privacy Team, Trust Office, legal department, and multiple partners in other business functions to build a resilient, scalable privacy program that works for a fast-growing, innovative company.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Develop a deep understanding of data usage across Asurion products and business functions.

A

Data Map

HIPAA map
Healthcare data map

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Identify legal and operational privacy and data protection concerns and furnish efficient solutions.

A
HIPAA
HITECH
GDPR
CCPA
HR 8?

45 CFR § 164.504 - Uses and disclosures: Organizational requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Our best work enables Asurion to nimbly and confidently adapt to the fast-coming changes in privacy laws around the world. This requires comfort with stepping into complex problems that lack easy “by the book” solutions and finding practical paths forward both legally and operationally.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Work with key business stakeholders to complete Privacy Impact Assessments and other privacy reviews related to products, technologies, and vendors.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Guide product and development teams to ensure that their data collection and usage practices are transparent, protect user privacy, and mitigate risk.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Identify and escalate potential privacy and data protection concerns based upon risk and operational impact.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Engage and support the legal department in negotiation of privacy and data protection-relevant contract terms for both clients and vendors.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Support the Trust Office, security and legal teams in driving effective and risk-minimizing responses to information security events.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Support response to individuals exercising their rights under global data privacy laws.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Facilitate compliance with privacy and data protection laws by Asurion’s global affiliates.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Provide timely and accurate responses to customer and internal queries related to privacy and data protection.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Seek to identify synergies and “force multipliers” with the Data Governance and Audit & Compliance arms of the Trust Office.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Support vendor risk management functions with emphasis on privacy, compliance, and data ethics.

A
26
Q

Collaborate on development of education and engagement strategy and actively engage business stakeholders with practical, actionable information that multiplies the impact of our program.

A
27
Q

Continuously seek to develop, improve and streamline efficient, scalable and resilient privacy and data protection processes, tools and procedures, including maintaining useful documentation of them.

A
28
Q

Monitor legal and regulatory developments, the privacy practices of peer companies, relevant privacy and data protection frameworks and best practices in general.

A
29
Q

Identify evolving privacy risks inherent in Asurion’s operations and in the development of new products and services.

A
30
Q

Must be comfortable getting “elbow-to-elbow” with other business functions understand intersection of our products, services and business functions to develop deep grasp of how privacy and data protection requirements apply to Asurion.

A
31
Q

This position will report to the Asurion Privacy Team and the Asurion Trust Office of which the Privacy Team is a part. Because job responsibilities will include being a key liaison and partner with the Asurion legal team, we are seeking an attorney with approximately 2-4 years of privacy and/or security experience for the role.

A
32
Q

Must be comfortable multi-tasking and working in a fast-paced dynamic environment.

A
33
Q

Collaborative, humble team-first approach to innovate and solve problems at a pace that keeps up with Asurion’s innovation and growth, sometimes in areas where there is no clear, well-defined path.

A
34
Q

Ability to communicate technical and legal concepts to laypeople with impact and effect without relying on legal and technical jargon.

A
35
Q

Must maintain composure under pressure and have a high degree of perseverance.

A
36
Q

High integrity and ethical standards are non-negotiable.

A
37
Q

Excellent communication skills, both written and oral.

A
38
Q

Comfort with public speaking and educating non-specialists in privacy and data protection matters.

A
39
Q

Strong analytical and problem-solving skills.

A
40
Q

Must be energized by taking on big challenges and have fun doing it.

A
41
Q

The Technology Audit & Compliance Architect will design and implement programs to ensure compliance with regulatory and contractual requirements and industry standards (to include HIPAA and PCI) for Asurion, globally.

A
42
Q

Responsibilities include leading security-related technology audits to drive compliance and alignment of technologyresources.

A
43
Q

As part of our Trust Office team, you will work to ensure that our systems and services are designed, operated, and protected to maintain customer trust and regulatory compliance.

A
44
Q

You will leverage your background in audit, security, risk, and compliance to evaluate and assess systems and services against Asurion policies and standards.

A
45
Q

You will partner with stakeholders across Asurion to execute a risk management approach, identify risks, and act as a thought leader who recommends and leads risk mitigation strategies with cross-functional teams across Asurion.

A
46
Q

A data classification policy describes the data classification categories; level of protection to be provided for each category of data; and roles and responsibilities of potential users, including data owners.

A
47
Q

You will work independently with the ability to prioritize workloads, remain flexible, and maintain a strong attention to detail in a fast-paced environmentwhilesupportingmultiple, simultaneous programs.

A
48
Q

Use your in-depth knowledge of regulatory compliance, IT security, and strong customer skills to act as the subject matter expert to internal technology and operations teams in a Trusted Advisor capacity to assist their understanding of requirements (i.e. HIPAA, PCI, etc) related to their applications.

A
49
Q

Develop the HIPAA compliance program from risk identification to executive reporting.

A
50
Q

Conduct and complete pro-active HIPAA assessments on behalf of the company to ensure the company’s ability to protect PHI data.

A
51
Q

Lead regulatory remediation projects and risk mitigation efforts.

A
52
Q

Track and manage action plans for remediation of audit findings.

A
53
Q

Perform analysis and reporting of compliance gaps.

A
54
Q

Provide subject matter expertise related to PCI, HIPAA or client security requirements to internal technology and operations teams to ensure Company’s ability to maintain compliance when modifying or implementing applications involving sensitive data.

A
55
Q

Implement best in class Risk & Compliance Management practices with minimal impact to the business.

A
56
Q

Lead Asurion’s response to client audit requests and coordinate collection of audit artifacts.

A
57
Q

Monitor issues to provide assurance reporting of how Company is complying with specific country and industry regulatory requirements and the internal control framework in order to maintain a compliant, audit-ready posture.

A
58
Q

Coordinate and represent Asurion in negotiations with external auditors.

A
59
Q

Train audit participants in audit preparation and response.

A
60
Q

5+ years progressive experience in information security or technology audit, including experience with issue resolution and leading teams in a cross-functional setting.

A
61
Q

Experience in technology audit, risk analysis, and compliance testing.

A