Information Risk Consultant
Highmark Health · United States · 1 mo ago
RemoteRemoteFinance$79k/yrFull-time
About the role
This job works closely with infrastructure architecture/engineering/operations, compliance, privacy, business teams and other areas necessary to identify risks to the business and drive solutions ranging from education and awareness to the adoption of new/existing policies, standards, processes, controls and technologies.
Responsibilities
- Conduct Information Risk Assessments as assigned to the team.
- Request and analyze documentation necessary to perform appropriate assessment and conduct necessary interviews in order to collect and review relevant materials necessary to produce results of the assessment.
- Clearly and concisely document and communicate risk assessment results with requestor, security architects and management, as appropriate.
- Understand and contribute to inventory of risk register tracking, scoring and associated risk statements.
- Perform follow up activities related to exceptions, risk acceptance, corrective action plans and additional mitigation activities.
- Communicate risk treatment methodology; risk avoidance, risk acceptance, risk transference and risk mitigation to appropriate groups.
- Partner with multiple projects and initiatives to apply security architecture requirements, develop architecture solutions, integrate security into solution designs, access risks of security gaps, and develop architecture remediation.
- Aid HM Health Solutions teams in developing and maintaining appropriate procedural documentation which meets relevant compliance standards, such as Payment Card Industry - Data Security Standards (PCI-DSS), Health Information Trust Alliance (HITRUST), and International Organization for Standardization (ISO) 27001.
Requirements
- Minimum 3 - 5 years' experience in Information Security and/or Information Risk Management and/or Information Technology.
- Minimum 1 - 3 years' experience within Information Security Governance, Risk and/or Compliance functions and activities.
- Minimum 1 - 3 years’ experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences.
Qualifications
- Bachelor's Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field.
- At least 7 years' experience in Information Security, Governance, Risk and/or Compliance.
- Master’s Degree - Computer Science, Information Security or related field preferred.
Skills
- Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3.
- Knowledge of NIST Risk Assessment methodology.
- Familiarity with secure SDLC best practices.
- Ability to work within high performance, multi-discipline teams.
- Strong teamwork and interpersonal skills.
Benefits
Not specified.
Pay
$79,300.00 - $127,100.00
Schedule
Not specified.