Senior Risk and Compliance Analyst
Highmark Health
Company :
Highmark Health
Job Description :
JOB SUMMARY
This job works collaboratively to support of all risk and compliance assessment activities of Highmark Health across a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, etc. The incumbent will partner with the organizational risk and business partners, the technology organization, and global delivery teams to meet Highmark Health's mission requirements in a manner consistent with the enterprise risk appetite. This individual must have a proactive mindset and approach, and feel comfortable working in a highly matrixed environment.
ESSENTIAL RESPONSIBILITIES
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess, prioritize, evaluate and address financial, information security, privacy, and other areas of risk.Prepare draft reports and other management reporting deliverables.Review all work prepared by less experienced team members to ensure audit quality standards are consistently met in all forms of documentation.
Review and interpret inherent risk assessment results, engagement risks, and developassurance plans (e.g., on-site audit, contract review, financials assessment, purchasing data analysis) to address relevant risk areas and to ensure proper controls are implemented.Accountable for the review and interpretation of authoritative guidance (including, but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO reports) and performs qualitative and quantitative impact assessments based on physical, technical, and administrative safeguards as well as contractual requirements; conducts additional information gathering and risk assessments as-needed; documents and reports results.
Lead development of project plans to support risk assessment and decisioning in coordination with business owners and other stakeholders within task-based budgets.Collaborate and communicate with Information Security, Privacy, Procurement, Audit, Compliance, and other teams across the Enterprise to align risk management objectives, practices and procedures.
Interface with business areas, technical staff, project teams, and third parties to execute cross-functional risk assurance projects. Lead the communication of assessment results and findings with multiple stakeholder groups and provides consultation and direction throughout.
Interpret complex data flow/ information sharing activities, customer integrations, and information safeguards into simplified and high-level terminology and/or process/data flows.Maintains risk management reporting dashboards in RSA Archer applications in order to keep information complete, accurate, and current.Prepare and assist with the delivery of risk assurance reports to management.
Ensure risk questionnaires and other risk assessments are distributed and completed on-time and prepares initial impact assessments.Ensure compliance requirements are met across the Enterprise.Assist in training and mentoring team members on multi-faceted engagements, platform customer dependencies, and interpretation of complex contract agreements.
Collaborate with lead in providing input and consultation on risk and assurance reporting.Collaborate and consult with other areas (e.g., Procurement, Privacy, Information Security, Legal) throughout the engagement lifecycleAssist in providing timely feedback on interpretations regarding authoritative guidance.
Proactively reviews updates made to departmental desk-level procedures, risk assessment methodology, assessment procedures, questionnaires, training, etc. and is responsible for monitoring compliance with departmental metrics, internal control activities, contractual obligations, regulatory requirements, and responding to customer inquiries / audits.
Other duties as assigned or requested
EDUCATION
Required
- Bachelor's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Substitution s
- 6 years of related and progressive experience in lieu of Bachelor's degree
Preferred
- Master's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
EXPERIENCE
Required
- 5 years in Audit and Compliance
To Include:
3 years of Business Process Design
3 years of Project Management
?
Preferred
- None
LICENSES or CERTIFICATIONS
Required
- None
Preferred (any of the following)
Certified Public Accountant (CPA)
Certified Information Systems Analyst (CISA)
Certified Information Privacy Professional (CIPP)
Certified Information Systems Security Professional (CISSP)
SKILLS
Demonstrate expert knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes.
Knowledge of relevant regulatory guidelines, vendor management, sourcing and procurement, and completing assessments of vendors
Excellent resource and project planning capabilities, decision making skills, history of results-oriented delivery, and effective team building across a cross-campus and diverse team of management and staff.
Strong written and verbal communication skills for diverse audiences (senior management, board, peer, and team).
Strong relationship building skills and ability to influence with and without authority in a matrixed organization.
Leadership qualities with an ability to motivate and inspire a group of individuals to achieve superior results.
High capacity to think analytically, interpret information / observations, apply judgment and make effective, strategic decisions.
Language (Other than English):
None
Travel Requirement:
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-based
Teaches / trains others regularly
Occasionally
Travel regularly from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement : This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on click.appcast.io
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J281828
- ...Senior Compliance Analyst (MS), AML (Anti-Money Laundering) The Opportunity: The AML/KYC Senior Analyst supports the day-to-day execution of... ...responsibility for identifying documentation gaps, escalating risk triggers, and maintaining high-quality case documentation...SeniorSummer workWork at officeFlexible hours
$48k - $115.5k
...Consumer Compliance Analyst Function: Assists the Consumer Compliance Manager with ensuring S&T Bank operates in conformity with federal... ...is accomplished through performing Regulatory and Third-Party Risk Assessments, regulatory research, Complaint Management, and providing...SeniorFor contractors- ...Compliance Analyst - Supervision This position uses independent judgement and discretion to ensure all Registered Representatives adhere... ...Insurance. About ACA: ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We empower...SuggestedWork experience placementSummer workWork at officeFlexible hours
- ...Compliance Analyst - Registration This position is responsible for processing initial and ongoing registration requirements for registered... ...Insurance. About ACA: ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We...SuggestedWork experience placementSummer workWork at officeFlexible hours
- DICK'S Sporting Goods is seeking a Compliance Analyst to support the Corporate Compliance Program. In this role, you will manage policy governance, track regulatory activities, and support the operationalization of compliance programs. The ideal candidate will have a Bachelor...Suggested
- ...management, oversight of safety programs, and relevant certifications. Responsibilities include reviewing safety programs and ensuring compliance with safety regulations. The position offers comprehensive medical, dental, vision benefits, a retirement plan, and professional...Senior
- ...You will be responsible for managing project delivery as well as assisting clients with all aspects of air quality permitting and compliance requirements. If hired, you can expect up to 25% short-term and extended travel. Qualifications: ~ B.S. or M.S. degree...SeniorTemporary workFor contractorsRemote workFlexible hours
- ...projects and initiatives related to the risk case management and intake activities of... ...Guidance team;. Translate and communicate compliance requirements into business and technical... ...the organization.During an audit, engage senior Business Unit leadership and removing barriers...SeniorFor contractorsWork at officeLocal area
- ...Sr. Compliance Officer Duration: 12+ months (possible extension) Location: Pittsburgh, PA 15258 Onsite role (4 days a week) Responsibilities... ...audit ready evidence, and partnering with business, legal, and risk teams to ensure sustained compliance without slowing delivery....Contract workFor subcontractor
- ...Description They key responsibilities of the Senior Regulatory Affairs Specialist are:... ...guidance on regulatory requirements, risks, and timelines. Interface with regulatory... ..., and formal correspondence. Ensure compliance with applicable U.S. and international regulations...SeniorLocal area
- ...build and advance a strong foundation in internal audit, risk management, and SOX compliance while contributing to meaningful work that drives... ...The Internal Audit & Advisory Services Associate/Senior Associate will be responsible for supporting, and at the...SeniorInternshipWork at officeLocal area
- ...BANK INVESTMENT RISK SPECIALIST SENIOR The PNC Financial Services Group, Inc. seeks a Bank Investment Risk Specialist Senior in Pittsburgh... ...methods to evaluate risk exposures and support compliance with risk-based capital framework; (6) managing and reconciling...Senior
- ...Senior Vice President, Counsel - Asset Servicing At BNY, our culture allows us to run our company better and enables employees... ...in an advisory or oversight capacity, such as those in Risk, Audit, Compliance, etc. Manage outside counsel, reviewing work for appropriateness...SeniorContract workWorldwideFlexible hours
- ...Senior Vice President, Counsel - Asset Servicing At BNY, our culture allows us to run our company better and enables employees... ...in an advisory or oversight capacity, such as those in Risk, Audit, Compliance, etc. Manage outside counsel, reviewing work for appropriateness...SeniorContract workWorldwideFlexible hours
- ...Consulting company, is looking for a Senior Business Analyst for their Philadelphia, PA/Hybrid location... ...systems including core banking, risk, reconciliation, and reporting platforms... ...environment Collaborate with risk, compliance, and security teams to ensure payment...SeniorDay shift
$104k - $147k
...Senior Vice President, Operational Risk Coverage We're seeking a future team member for the role of Senior Vice President, Operational Risk Coverage to join our Risk & Compliance team. This role is located in New York City, NY. About the team: BNY Corporate Trust...SeniorTemporary workWork experience placement- ...Senior Angular Engineer Date: May 26, 2026 Location: Durham, NC, US Pittsburgh, PA, US Company: ACA Group ACA Group ("ACA") is the leading governance, risk, and compliance (GRC) advisor in financial services. We empower our clients to reimagine GRC and protect...SeniorWork at office
$136.5k - $300k
..., and CI/CD templates) that accelerate delivery while ensuring compliance and quality. Streamline and modernize architecture governance... ...AI-driven tools for pattern recommendation, design validation, risk identification, and documentation generation; define safe,...SeniorTemporary workWorldwideFlexible hours$90.4k - $168.2k
...passionate about your future as we are, join our team. KPMG is currently seeking a Sr. Associate, Security Governance, Risk and Compliance (Audit) to join our Enterprise Security Services organization. This is a remote work opportunity team. Responsibilities:...SeniorH1bLocal areaRemote work- ...Job Title : IT Risk Compliance Specialist Department: Information Technology Location: Pittsburgh, PA Reports To: CIO Company Statement: Montauk Renewables, Inc. (NASDAQ: MNTK) is a renewable energy company specializing in the management, recovery,...Full timeFlexible hours
$91k - $321.5k
...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector: Not Applicable... ...to 20% At PwC, our people in risk and compliance focus on maintaining regulatory compliance... ...Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise...SeniorFull timeContract workH1b- ...contribute to the company's success. As a Compliance Program Analyst within PNC's Human Resources... ...necessary data to identify compliance risks. Under supervision, may assist in suggesting... ...resolutions. Escalates identified risks to senior team members. Assesses activity for...Full timeTemporary workPart timeWork experience placementWork at office
$113k - $200k
...extraordinary. We’re seeking a future team member for the role of Senior Vice President, Counsel to support BNY’s FX and Derivatives... ...closely with business partners and BNY control functions (Compliance, Credit, Risk, Legal) to complete documentation and remediation projects....SeniorTemporary workWorldwideFlexible hours- ...sports team, apply to join our team today! OVERVIEW: The Compliance Analyst will assist the Director of Global Compliance with the... ...Insights • Assist in identifying and containing compliance risks and proactively fostering a compliance culture. Assist with industry...
$105.79k - $141.05k
...AI‑ready connectivity, join us today. The Role The CMMC Compliance Analyst must have advanced practical experience in managing all... ...certification activities Track and report compliance status, risks, and metrics to leadership Assist in updating SSPs, network...Full timeTemporary workFor contractorsRemote work- ...Responsibilities We are seeking a highly experienced Senior Principal Digital Engineer to join our team supporting the modernization of Digital Engineering (DE) and Model-Based Systems Engineering (MBSE) for Naval Nuclear Laboratory (NNL) programs in either the Albany...SeniorFor contractors
- ...Responsibilities Data Aggregation and Analysis Coordinate the collection, preparation, cleaning, verification, and aggregation of compliance and compliance-related data from cross-functional sources. Synthesize structured and unstructured data to identify trends and...Flexible hours
- ...annually / $38 - $43 hourly The HRIS Payroll Reporting and Compliance Analyst owns end-to-end payroll processing while ensuring the... ...payroll and workforce data to surface trends, variances, and risks for leadership Support leadership reporting needs related...Hourly payPermanent employmentFull timeContract workTemporary workWork at officeLocal areaRemote workWorldwideRelocation2 days per week
- Comfort Keepers - JobID: f1de4623224a1e39debab98092d7e305 [Nursing Assistant / Health Aide] As a Senior Home Caregiver at Comfort Keepers, you'll: Provide compassionate and personalized care to elderly clients in their homes; Assist with daily activities such as bathing...SeniorImmediate start
$100k - $172.5k
...processes engineering teams leverage throughout the product development lifecycle. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you. Primary Duties and...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Risk and Compliance Analyst. Be the first to apply!
- it risk analyst Pittsburgh, PA
- risk analyst Pittsburgh, PA
- risk officer Pittsburgh, PA
- risk consultant Pittsburgh, PA
- information security compliance analyst Pittsburgh, PA
- compliance associate Pittsburgh, PA
- compliance analyst Pittsburgh, PA
- cybersecurity policy and compliance analyst Pittsburgh, PA
- regulatory officer Pittsburgh, PA
- coding compliance specialist Pittsburgh, PA




