Abbott is a global healthcare leader that helps people live more fully at all stages of life. Our portfolio of life-changing technologies spans the spectrum of healthcare, with leading businesses and products in diagnostics, medical devices, nutritionals and branded generic medicines. Our 103,000 colleagues serve people in more than 160 countries.
Senior Specialist Cybersecurity
Primary Function -
Contribute to the support of cybersecurity operations by designing, developing or recommending secure technical solutions, including policy, standards, applications, systems, architectures, and infrastructure that are operationally viable and efficient. Perform responsibilities to ensure that the appropriate application of security products and technologies are in place to protect the organization's systems and information and enable achievement of the organization's objectives. Contribute to the design of cybersecurity toolsets to enable more automated discovery, remediation, and alerting of network and device vulnerabilities, as a means of improving the security posture. Perform analysis of emerging technologies and design and build architectures and solutions to enable secure implementation of new technologies.
Core Job Responsibilities -
Contribute to the development of a risk-based cyber security program which meets regulatory requirements and aligns with industry leading information security practices.
Perform threat identification and mitigation activities using industry leading security controls and tools sets.
Support the advancement of the Company's cyber threat and vulnerability management program to ensure consistent identification, analysis, response, and monitoring of cyber security threats, events, and vulnerabilities.
Assess threats to the business and deploy countermeasures for those threats.
Guide business units, application development teams, and third-party vendors to achieve program requirements while enabling the business.
Apply technical knowledge to protect the Company against cyber threats (e.g., knowledge of firewalls, intrusion detection and prevention systems, data loss prevention solutions, endpoint protections, log aggregation technology and other leading-edge security technologies).
Participate in cross-team coordination to achieve defined security goals as well as meet technical requirements in support of detailed implementation plans for security projects.
Contribute subject matter expertise on security projects to ensure the timely, on budget, and effective implementation of cyber security improvements that are operationally supported with validation methods in place to measure effectiveness.
Perform assessment of cyber security incidents to identify the root cause, respond, and recover the environment.
Support management in the development of strategies, policy and standards to protect company information and technology assets.
Source intelligence information from related industry and regulatory bodies, and other security intelligence sources
Compose intelligence report briefs to key stakeholders
Collaborate with Incident Response team to inform and enhance the threat intelligence program
Create processes for continuous dissemination of research of emerging security threats to key stakeholders
Collaboration with external organizations to gain a better understanding of the current state of their security posture to leverage that information to provide focused intelligence coverage
Position Accountability / Scope
Reports to the Sr. Manager of Attack Surface Management The scope of this position is Abbott wide and considers the information security implications unique to all Abbott divisions when developing governance and risk management strategies. May have direct budget responsibility.
Minimum Experience/Training Required -
Possess expertise in valuing and implementing industry standards such as the ISO 27001/2, SOC 2, HITRUST and FedRAMP Information Security standard and the ISO 22301 Business Continuity Standard.
Experience with implementation and operational use of GRC toolsets (Governance Risk and Compliance)
Possess CISSP certification (or similar) and be knowledge of national and international regulatory compliance and frameworks such as ISO, SOX, BASEL II, EU DPD, HIPAA, and PCI DSS.
Information Risk & Quality Assurance
GIS Global Information Services
United States > Minnesota > St. Paul > Lillehei : One Lillehei Plaza
United States > Waukegan : J46 Floor-1
Yes, 20 % of the Time
SIGNIFICANT WORK ACTIVITIES:
Continuous sitting for prolonged periods (more than 2 consecutive hours in an 8 hour day), Keyboard use (greater or equal to 50% of the workday)
Abbott is an Equal Opportunity Employer of Minorities/Women/Individuals with Disabilities/Protected Veterans.
EEO is the Law link
EEO is the Law link