Senior Information Risk Consultant
$94.2kHighmark Health
Company :
Highmark Health
Job Description :
JOB SUMMARY
This job works closely with infrastructure architecture/engineering/operations, compliance, privacy, business teams and other areas necessary to identify risks to the business and drive solutions ranging from education and awareness to the adoption of new/existing policies, standards, processes, controls and technologies. The scope of this position is to proactively test for compliance with security policies and procedures and to recommend potential new approaches. This position is required to comply with all HM Health Solutions Corporate Policies and Information Security Policies, Standards and Procedures. Mentor team members.
ESSENTIAL RESPONSIBILITIES
Lead in conducting information risk assessments as assigned to the team. Request and analyze documentation necessary to perform appropriate assessment and conduct necessary interviews in order to collect and review relevant materials necessary to produce results of the assessment.
Clearly and concisely document and communicate risk assessment results with requester, security architects and management, as appropriate.
Conduct and formulate appropriate risk scoring, as it relates to threat, vulnerability, likelihood, impact, security controls/countermeasures, etc.
Understand and contribute to inventory of risk register tracking, scoring and associated risk statements.
Perform follow up activities related to assigned risks, ensuring mitigation activities stay on track.
Communicate risk treatment methodology, risk avoidance, risk acceptance, risk transference and risk mitigation to appropriate groups.
Take lead role in partnering with multiple projects and initiatives to apply security architecture requirements, develop architecture solutions, integrate security into solution designs, access risks of security gaps, and develop architecture remediation.
Take lead role with enGen teams in developing and maintaining appropriate procedural documentation which meets relevant compliance standards, such as Payment Card Industry - Data Security Standards (PCI-DSS), Health Information Trust Alliance (HITRUST), and International Organization for Standardization (ISO) 27001.
Prepare and present solution decks to different levels of management and varying technical experience.
Lead in assuring compliance to required standards, procedures, guidelines and processes.
Other duties as assigned or requested.
REQUIRED EDUCATION
Bachelor's Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field
Substitutions
At least 10 years' experience in Information Security, Governance, Risk and/or Compliance
PREFERRED EDUCATION
Master's Degree - Computer Science, Information Security or related field
EXPERIENCE
Minimum:
7 - 10 years' experience in Information Security and/or Information Risk Management and/or Information Technology
5 - 7 years' experience within Information Security Governance, Risk and/or Compliance functions and activities
7 - 10 years' experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
Familiarity with technologies such as intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
Preferred:
10 - 15 years' experience in Information Security and/or Information Risk Management and/or Information Technology
Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits
IT / Information security risk advisory experience
Governance Risk and Compliance (GRC) tool experience such as ARCHER
In-depth understanding of network security architecture, network and networking protocols
Security industry organization participation / leadership (HITRUST, ISACA, InfraGard, ISC2, ISSA, etc.)
KNOWLEDGE, SKILLS & ABILITIES
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
Knowledge of NIST Risk Assessment methodology
Familiarity with secure SDLC best practices
Ability to work within high performance, multi-discipline teams
Strong teamwork and inter-personal skills
Familiarity with AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) and how they map to enterprise risk management and existing frameworks (NIST CSF, 800-53)
Awareness of secure AI adoption practices, including model lifecycle security, data privacy, and third-party AI/vendor risk considerations
Understanding of automation opportunities in cyber risk management, including AI-assisted risk analysis, control validation, and metric generation
REQUIRED LICENSURE
None
PREFERRED LICENSURE
Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Information Systems Auditor (CISA), Global Information Assurance Certification Security Essentials Certification (GSEC), SANS or similar industry certifications
TRAVEL REQUIREMENT:
0% - 25%
PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS
( The physical, mental demands and working conditions described here are representative of those that must be met by an employee to successfully perform the essential function of their job. Reasonable accommodations will be made when necessary to enable individuals with disabilities to perform the essential duties of the position, to the extent that they do not cause undue hardship.
Position Type:
Remote
Lifting: up to 10 pounds
Does Not Apply
Lifting: 10 to 25 pounds
Does Not Apply
Lifting: 25 to 50 pounds
Does Not Apply
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$94,200.00
Pay Range Maximum:
$151,000.00
Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on click.appcast.io
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J281017
- ...Fraud Risk Management Senior Consultant I Fraud Risk Management Senior Consultant I sits in the Fraud Insights & Risk Management (FIRM) team—a... ...component. Equal Employment Opportunity and Fair Chance Information To view the EEO Know Your Rights poster click here....SeniorVisa sponsorshipWork visa
$96.5k - $110.1k
...Senior Risk Associate, Investigations Quality As a Senior Associate on Capital One's Anti-Money Laundering (AML) Investigations Quality... ...are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of...SeniorFull timePart timeWork at officeLocal area- ...data and advanced AI to surface risk, automate compliance, and... ...the federal government. Senior SCRM Analyst - Healthcare Supply... ...recommendations that directly inform operational and strategic decisions... ...analysis, risk analysis, consulting, intelligence analysis, or a related...SeniorWork at officeWork from homeFlexible hours
$87.7k - $100.1k
...Senior Risk Associate, Capital Markets - Regulatory Onboarding Are you looking for a challenging... ...for accuracy and regulatory compliance Consult Front Office and external customers on... ...have visited our website in search of information on employment opportunities or to apply...SeniorFull timeTemporary workPart timeLocal areaWork from homeHome office- ...Senior Analyst, Risk Intelligence What part will you play? If you're looking for a place where you can make a meaningful difference, you... ...Pace: Proven ability to manage complex, multi-stakeholder information gathering while meeting rigorous deadlines in a high-volume...SeniorFull timeLocal areaWork from home
$96.5k - $110.1k
...Senior Risk Associate, Enterprise Data Risk Management Do you want to be part of an organization that’s dedicated to helping Capital... ...are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of...SeniorFull timePart timeLocal areaImmediate start- ...Tuckahoe Creek Parkway, Richmond, Virginia, 23238 CarMax, the way your career should be! We are looking for an Analyst II, Information Risk Management to maintain and enhance the Information Risk Management posture of an innovative and fast paced company that is...Full timeWork experience placementWork at office
- A leading global consulting firm is seeking a Senior Consultant for its Risk Technology practice, focusing on ServiceNow IRM solutions. The role involves assessing and implementing risk management strategies, leading project teams, and supporting business development activities...Senior
$96.5k - $110.1k
...Senior Associate Risk Specialist, HR Business Risk Office As a Senior HR Risk Specialist in Capital... ...business partners to identify and consult on potential risks to Capital One, applying... .... Please note that this salary information is solely for candidates hired to perform...SeniorFull timePart timeWork at officeLocal area- ...A dynamic consulting firm in the United States seeks a Senior Associate for its Cyber Security & Data Privacy (CSDP) group. This role involves leading client engagements to implement cybersecurity programs and managing daily compliance operations. Ideal candidates will...Senior
- ...A cybersecurity firm is seeking a Senior Virtual Information Security Officer to provide CISO-level advisory services. In this non-implementational... ...executives. Strong expertise in NIST frameworks and prior consulting experience are essential. The position promises a dynamic...Senior
$96.5k - $110.1k
Senior Risk Associate, Upmarket & Discover Card - Card Risk(Hybrid) Capital One is seeking highly motivated Senior... ...models and relationships to collaborate and consult with key stakeholders. Collect data and information and use analytics and reporting to develop risk transparency...SeniorFull timePart timeLocal area$130k - $160k
...Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer... ...& Policy: Maintain and improve information security policies, standards, procedures, control...SeniorFull timeWork at officeRemote workWork from homeFlexible hours$87.7k - $100.1k
Senior Risk Specialist | Retail Bank We’re looking for a strategic, forward thinking Senior... ...well as support other controls related consultation and improvement initiatives. This could... ...Contribute to reporting necessary to inform the Accountable Executives and other key...SeniorFull timePart timeWork at officeLocal area$135k - $190k
...all of the time. About your role As a Senior GRC Analyst, you are responsible for supporting the organizations governance, risk management, and compliance (GRC) program.... ...Qualifications Bachelors degree in information systems, engineering, business, risk management...SeniorFull timeWork at officeLocal areaRemote workWork from homeFlexible hours- The Fair Banking Oversight & Senior Risk Advisor is responsible for serving as a Second Line of Defense (2LOD) Fair and Responsible Banking... ...or a discretionary profit sharing bonus program. General information on our comprehensive benefits package can be found by...SeniorWork experience placementWork at officeFlexible hours
$90.9k - $129.9k
...A leading technology company is seeking an Experienced Information Security professional. In this remote role, youll design audits to... ...system security, investigate breaches, and provide technical consultation. The ideal candidate will have at least nine years in the field...SeniorRemote workFlexible hours$96.5k - $110.1k
...Senior Risk Associate, Upmarket & Discover Card - Card Risk (Hybrid) Capital One is seeking highly motivated... ...interaction models and relationships to collaborate and consult with key stakeholders Collect data and information and use analytics and reporting to develop risk...SeniorFull timePart timeLocal area- ...:** 3-5 years of experience in insurance risk, actuarial, or strategy, or other analytical... .... The national average salary for the Senior Analyst, Risk Intelligence position is $9... ...seeking employment in order to steal personal information. Frequently, the scammer will reach out...SeniorFull timeLocal areaWork from home
$119k - $170k
...the future of cybersecurity. Role We are looking for a Senior Governance, Risk & Compliance Specialist to join our Technology Risk & Compliance... ...and Milestone deliverable, keeping relevant stakeholders informed on risks to the system Monitor relevant laws,...SeniorFull timeWork at officeLocal areaRemote work- CarMax is seeking an Analyst II for Information Risk Management at the Richmond, VA Technology Innovation Center. The essential duties include coordinating data subject access requests and implementing privacy risk management programs. Ideal candidates will have a relevant...
$81.8k - $177.1k
...Risk Engineering Consultant (Mid-Senior) 120008 Zurich’s Middle Markets Risk Engineering team is seeking a Risk Engineering Consultant with Property and Casualty Risk Engineering experience to support the Middle Market Underwriting Business Unit. This role reports to the...SeniorFull timeApprenticeshipWork at officeRemote workWork from homeVisa sponsorship- An established industry player is seeking a Senior Manager in Information Security to lead initiatives that enhance security protocols. This role... ...You will leverage your expertise in cloud technologies and risk management to provide strategic guidance and support. The...SeniorWork at office
$175k - $190k
...Prairie Consulting Services provided pay range This range is provided by Prairie Consulting... ...poster from Prairie Consulting Services Senior Technical Recruiter at Prairie Consulting... ...Employment type Full‐time Job function Information Technology Industries Retail #J-18808-Ljbffr...SeniorPermanent employmentFull timeRemote work- Apex Systems in Glen Allen, Virginia is seeking a Senior Director Information Security, CISO. This role is responsible for safeguarding the computer systems and networks, implementing effective security measures, and leading a collaborative security team. The ideal candidate...Senior
- ...underwriting team, supporting large, complex risks where sound actuarial judgment is... ...directly with experienced underwriters to inform high impact decisions. The successful candidate... ...national average salary range for the Senior Actuarial Analyst is $108,800 - $181,400...SeniorFull timeWork experience placementLocal areaWork from home
- ...certifications: PMP Agile Certification Summary: Maintains information technology strategies by managing staff; researching and... ...to team effort by accomplishing related results as needed. Seniority level Mid‑Senior level Employment type Contract Job...SeniorContract workLocal areaRemote work
$3,600 per month
...Senior Actuary Kinsale Insurance is an excess and surplus (E&S) lines insurance company located in Richmond, VA. We pride ourselves... ...sound judgement, trustworthiness, or access to sensitive information. Equal Opportunity Employer This employer is required to notify...Senior$138.15k - $168.85k
...Facilities/Security ☐ Outdoor Exposure This senior level position is responsible for... ...optimization, forecasting support, benchmarking, risk adjustment optimization, provider payment... ...actuaries to facilitate access to plan information necessary to support their work and...SeniorContract workWork experience placementLocal areaWork from homeFlexible hours$212k - $318k
...We are seeking a Partner, Senior Health Actuary to join our Actuarial... ...What you need to have: Consulting experience with large clients... ...: MRSH), a global leader in risk, reinsurance and capital,... ...power of perspective. For more information about Mercer, visit mercer....SeniorMinimum wageWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Information Risk Consultant. Be the first to apply!
- it risk analyst Richmond, VA
- senior quantitative risk analyst Richmond, VA
- risk analyst Richmond, VA
- operational risk specialist Richmond, VA
- third party risk analyst Richmond, VA
- operational risk consultant Richmond, VA
- risk officer Richmond, VA
- risk consultant Richmond, VA
- senior development executive Richmond, VA
- senior technical manager Richmond, VA


