Information Risk Consultant

3 days ago

Apply Now
Logo of Highmark Health

Highmark Health

health care

10,000+

πŸ’° $5M Grant on 2021-05

Description

β€’ This job works closely with infrastructure architecture/engineering/operations, compliance, privacy, business teams and other areas necessary to identify risks to the business. β€’ Drive solutions ranging from education and awareness to the adoption of new/existing policies, standards, processes, controls and technologies. β€’ Proactively test for compliance with security policies and procedures and recommend potential new approaches. β€’ Conduct Information Risk Assessments as assigned to the team. β€’ Request and analyze documentation necessary to perform appropriate assessment and conduct necessary interviews. β€’ Document and communicate risk assessment results with requestor, security architects and management. β€’ Conduct and formulate appropriate risk scoring, as it relates to threat, vulnerability, likelihood, impact, security controls/counter-measures, etc. β€’ Understand and contribute to inventory of risk register tracking, scoring and associated risk statements. β€’ Perform follow up activities related to exceptions, risk acceptance, corrective action plans and additional mitigation activities. β€’ Communicate risk treatment methodology to appropriate groups. β€’ Partner with multiple projects and initiatives to apply security architecture requirements. β€’ Assist HM Health Solutions teams in developing and maintaining appropriate procedural documentation.

Requirements

β€’ Bachelor's Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field β€’ At least 7 years' experience in Information Security, Governance, Risk and/or Compliance β€’ 3 - 5 years' experience in Information Security and/or Information Risk Management and/or Information Technology β€’ 1 - 3 years' experience within Information Security Governance, Risk and/or Compliance functions and activities β€’ 1 - 3 years’ experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences β€’ Familiarity with technologies such as intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms β€’ 5 - 7 years' experience in Information Security and/or Information Risk Management and/or Information Technology (preferred) β€’ Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework (preferred) β€’ Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits (preferred) β€’ IT/information security risk advisory experience (preferred) β€’ Governance Risk and Compliance (GRC) tool experience such as ARCHER (preferred) β€’ In-depth understanding of network security architecture, network and networking protocols (preferred) β€’ Security industry organization participation / leadership (HITRUST, ISACA, InfraGard, ISC2, ISSA, etc.) (preferred)

Apply Now

Similar Jobs

3 days ago

Join Centene as a Risk Adjustment Coder reviewing medical records for HCCs and ICD-10 guidelines.

3 days ago

Stripe

1001 - 5000

Manage User Policy Operations team at Stripe to uphold compliance with Terms of Service. Lead investigators to ensure business practices align with supportability standards.

4 days ago

KeyBank

10,000+

As a Risk Analyst, manage fraud risks and support oversight processes within KeyCorp's Fraud Risk Management team.

4 days ago

Seeking an Inside Broker focused on Executive Risk, Cyber, and Professional Liability at Anzen. Join a leading team leveraging technology in the insurance market.

November 16

AAA

5001 - 10000

Join CSAA Insurance Group as a Model Risk Advisor, overseeing AI governance and compliance.

Built byΒ Lior Neu-ner. I'd love to hear your feedback β€” Get in touch via DM or lior@remoterocketship.com