Senior Information Risk Consultant
$94.2kHighmark Health
Company :
Highmark Health
Job Description :
JOB SUMMARY
This job works closely with infrastructure architecture/engineering/operations, compliance, privacy, business teams and other areas necessary to identify risks to the business and drive solutions ranging from education and awareness to the adoption of new/existing policies, standards, processes, controls and technologies. The scope of this position is to proactively test for compliance with security policies and procedures and to recommend potential new approaches. This position is required to comply with all HM Health Solutions Corporate Policies and Information Security Policies, Standards and Procedures. Mentor team members.
ESSENTIAL RESPONSIBILITIES
Lead in conducting information risk assessments as assigned to the team. Request and analyze documentation necessary to perform appropriate assessment and conduct necessary interviews in order to collect and review relevant materials necessary to produce results of the assessment.
Clearly and concisely document and communicate risk assessment results with requester, security architects and management, as appropriate.
Conduct and formulate appropriate risk scoring, as it relates to threat, vulnerability, likelihood, impact, security controls/countermeasures, etc.
Understand and contribute to inventory of risk register tracking, scoring and associated risk statements.
Perform follow up activities related to assigned risks, ensuring mitigation activities stay on track.
Communicate risk treatment methodology, risk avoidance, risk acceptance, risk transference and risk mitigation to appropriate groups.
Take lead role in partnering with multiple projects and initiatives to apply security architecture requirements, develop architecture solutions, integrate security into solution designs, access risks of security gaps, and develop architecture remediation.
Take lead role with enGen teams in developing and maintaining appropriate procedural documentation which meets relevant compliance standards, such as Payment Card Industry - Data Security Standards (PCI-DSS), Health Information Trust Alliance (HITRUST), and International Organization for Standardization (ISO) 27001.
Prepare and present solution decks to different levels of management and varying technical experience.
Lead in assuring compliance to required standards, procedures, guidelines and processes.
Other duties as assigned or requested.
REQUIRED EDUCATION
Bachelor's Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field
Substitutions
At least 10 years' experience in Information Security, Governance, Risk and/or Compliance
PREFERRED EDUCATION
Master's Degree - Computer Science, Information Security or related field
EXPERIENCE
Minimum:
7 - 10 years' experience in Information Security and/or Information Risk Management and/or Information Technology
5 - 7 years' experience within Information Security Governance, Risk and/or Compliance functions and activities
7 - 10 years' experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
Familiarity with technologies such as intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
Preferred:
10 - 15 years' experience in Information Security and/or Information Risk Management and/or Information Technology
Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits
IT / Information security risk advisory experience
Governance Risk and Compliance (GRC) tool experience such as ARCHER
In-depth understanding of network security architecture, network and networking protocols
Security industry organization participation / leadership (HITRUST, ISACA, InfraGard, ISC2, ISSA, etc.)
KNOWLEDGE, SKILLS & ABILITIES
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
Knowledge of NIST Risk Assessment methodology
Familiarity with secure SDLC best practices
Ability to work within high performance, multi-discipline teams
Strong teamwork and inter-personal skills
Familiarity with AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) and how they map to enterprise risk management and existing frameworks (NIST CSF, 800-53)
Awareness of secure AI adoption practices, including model lifecycle security, data privacy, and third-party AI/vendor risk considerations
Understanding of automation opportunities in cyber risk management, including AI-assisted risk analysis, control validation, and metric generation
REQUIRED LICENSURE
None
PREFERRED LICENSURE
Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Information Systems Auditor (CISA), Global Information Assurance Certification Security Essentials Certification (GSEC), SANS or similar industry certifications
TRAVEL REQUIREMENT:
0% - 25%
PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS
( The physical, mental demands and working conditions described here are representative of those that must be met by an employee to successfully perform the essential function of their job. Reasonable accommodations will be made when necessary to enable individuals with disabilities to perform the essential duties of the position, to the extent that they do not cause undue hardship.
Position Type:
Remote
Lifting: up to 10 pounds
Does Not Apply
Lifting: 10 to 25 pounds
Does Not Apply
Lifting: 25 to 50 pounds
Does Not Apply
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$94,200.00
Pay Range Maximum:
$151,000.00
Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on click.appcast.io
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J281017
$87.8k - $160.9k
...opportunity The objective of our consulting risk services is to provide clients with a candid... ...to assist clients in employing proper information systems, resources, and controls to... ...present risk reports and dashboards to senior management and the board of directors....SeniorContract workSummer holidayWork at officeFlexible hours$87.8k - $160.9k
...The opportunity The objective of our consulting risk services is to provide clients with a candid... ...to assist clients in employing proper information systems, resources, and controls to... ...present risk reports and dashboards to senior management and the board of directors....SeniorContract workSummer holidayWork at officeFlexible hours$100.2k - $164.1k
...Senior Risk Engineering Consultant 130237 Zurich's Middle Markets Risk Engineering team is seeking a Risk Engineering Consultant with Property... ...origin, sex, gender expression, gender identity, genetic information, age, disability, protected veteran status, marital...SeniorFull timeTemporary workApprenticeshipWork at officeLocal areaRemote workWork from homeVisa sponsorship- Elevance Health is looking for a Documentation Analyst Senior (Information Mapping) to research and document complex projects and work processes. This hybrid role requires in-office attendance 1-2 days a week while allowing for virtual work, promoting flexibility and work...SeniorWork at office2 days per week1 day per week
- ...financial technology firm based in Atlanta is seeking a Senior Analyst for IT Internal Control. In this role, you will develop... ...a Bachelor's degree in a related field. Strong skills in risk assessment and information security management are required, along with attention to...Senior
$62.04k - $93.06k
...Documentation Analyst Senior (Information Mapping) Hybrid 1 : This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines...SeniorTemporary workWork experience placementWork at officeLocal area2 days per week1 day per week- ...guidance to less experienced Collateral Risk Analysts in Collateral Services department... ...policies. Conducts exit meetings with senior management of member institutions summarizing... ...of member financial data and collateral information. This description provides general...SeniorFor contractorsWork experience placementWork at officeRemote workVisa sponsorshipWork visaNight shift
- ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Atlanta, GA The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer... ...or other documentation. - Complete external information security assessments, remediation efforts and...SeniorWork experience placement
- ...Business Insurance Sr. Risk Control Consultant Our not-so-secret sauce. Award-winning, inclusive, top workplace culture doesn't happen... ...control activities between client and carrier Monitor loss information and analyze trend development; develop effective overview...SeniorWork at officeLocal areaNight shift3 days per week
$100k - $130k
...Senior Vendor Risk Analyst Location: Hybrid – Candidates must be based in one of the following areas Naperville, IL / Birmingham, AL /... ...changes to customer Program policy/practice to ensure a risk-informed approach to vendor/supply chain management Collaborate across...SeniorFull timeTemporary workWork at officeLocal areaRemote workFlexible hours3 days per week- 4p-Consulting-Inc. is looking for an experienced Information Systems Analyst IV to support and administer enterprise Network Attached Storage (NAS) platforms, particularly Dell EMC PowerScale/Isilon. The role requires a strong understanding of both Microsoft and Linux environments...Senior
$62.04k - $93.06k
Documentation Analyst Senior (Information Mapping) Hybrid 1 : This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured...SeniorWork at officeLocal area2 days per week1 day per week- Citizen Trust Bank in Atlanta, GA is seeking an Information Systems Analyst to ensure critical applications are interconnected and automated. The role includes overseeing database management, generating custom reports, and providing technical support. The ideal candidate...Senior
- ...Senior GRC Analyst Location: Atlanta, GA Need local with availibilty of onsite interview... ...(ISO 27001, NIST, GDPR, CMMC), risk assessment, compliance audits, cybersecurity... ...risk management. Prepare and present information security and compliance metrics to leadership...SeniorContract workLocal area
- A global consulting firm is seeking a Senior Consultant for their Risk Technology practice. You will use your expertise with ServiceNow IRM to help clients optimize their risk and compliance programs. Candidates should have relevant degrees and at least 2 years of experience...SeniorFlexible hours
- ...enhancing our customer's experience. Position Summary: The Senior Risk Analyst, Business Analytics, will be responsible for... ...position involves regular access to sensitive consumers personal information, including, but not limited to, Social Security numbers and...SeniorWork at officeMonday to FridayWeekend work
- ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning... ...Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields ~3-4+ years working specifically...SeniorFor contractorsImmediate startFlexible hours
- ...of-defense (LoD2) Technology Risk team responsible for independent... .... The Technology Risk Senior Specialist - TEMPO Cost & Supplier... ...and Risk Type Owners within Information Risk Oversight (IRO) to... ...Truist Technology and related consult to Truist Business Units through...SeniorFull timeContract workPart timeWork at officeShift workDay shift
- A leading consultancy firm is seeking a Senior Consultant in Risk Technology to support SAP Security and GRC solutions in Atlanta. The role involves designing and implementing SAP Security measures across diverse platforms while collaborating with experienced teams. Candidates...SeniorFlexible hours
- ...Job Description Role & Responsibilities: The information security engineer is expected to constantly scan and analyze data and access logging software to help maintain the integrity of all information technology (IT) assets within the company. They are expected...Senior
- A government contracting firm based in Atlanta, GA is seeking an experienced Records Information Manager to provide technical and management support for a large Federal agency initiative. Candidates should have at least seven years of experience in records management and...SeniorContract work
$77k - $202k
...Requirements: Up to 60% At PwC, our people in risk and compliance focus on maintaining... ...address development areas. Interpret data to inform insights and recommendations. Uphold and... ...frameworks and methodologies. As a Senior Associate you are expected to analyze complex...SeniorFull time$115k
...Engineering & Operations Overview GovCIO is currently hiring for Senior Information Security Analyst with an active Secret clearance to plan and... ...documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages...SeniorFull timeCurrently hiringRemote workFlexible hours- NLB Services is seeking a Sr. Instructional Designer in Atlanta, Georgia, to create engaging learning experiences focused on information security. The ideal candidate will utilize their storytelling and instructional design skills to develop a world-class training program...Senior
- ...Transaction Fraud Analytics (Senior Fraud Risk Analyst) Atlanta, GA Description Job Description Title: Senior Analyst/Associate... .... Collaborate with cross-functional teams, including IT, Information Security, and Customer Service, to enhance fraud management...Senior
$93k - $189k
Huntington National Bank is seeking an experienced Information Classification Senior Lead to design and mature their enterprise information classification program. This role involves establishing classification framework requirements, partnering with governance teams, and...SeniorRemote job- Piedmont Healthcare Inc. in Atlanta is seeking a VP of Information Security responsible for safeguarding the organization’s information assets... ...demands strategic leadership in cybersecurity policy and risk management to defend against sophisticated threats while supporting...Senior
- ...own future. KPMG is currently seeking an Actuarial P&C Senior Associate to join our Audit practice.... ...federal, state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment...SeniorH1bLocal area
$91.66k - $120.3k
...Hi, we're Oscar. We're hiring a Senior Actuarial Analyst to join our Actuarial team.... ...valuation function, focusing specifically on risk adjustment across all Affordable Care Act... ...accommodation known. California Residents: For information about our collection, use, and disclosure...SeniorFull timeWork at officeRemote work$212k - $318k
...Senior Leader, Government Health Actuary We are seeking a talented... ...clinicians and health policy consultants supporting a portfolio of... ...complex capitation rate setting, risk adjustment and related... ...power of perspective. For more information about Mercer, visit mercer.com...SeniorMinimum wageWork at officeLocal areaFlexible hours3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Information Risk Consultant. Be the first to apply!
- transaction risk analyst Atlanta, GA
- operational risk consultant Atlanta, GA
- governance risk & compliance analyst Atlanta, GA
- it risk analyst Atlanta, GA
- risk compliance officer Atlanta, GA
- operational risk specialist Atlanta, GA
- risk analyst Atlanta, GA
- third party risk analyst Atlanta, GA
- senior quantitative risk analyst Atlanta, GA
- risk officer Atlanta, GA

