Manager - Cyber Resilience
About the role
Defines operational activities and executes on strategic direction related to Cyber Resiliency for CVS Health’s Digital, Data, Analytics & Technology (DDAT) Cybersecurity GRC team, guiding colleagues in facilitating cyber resiliency activities across the enterprise.
Responsibilities
- Manages, develops and implements procedures, controls, and reporting to ensure compliance with NIST Cyber resiliency frameworks.
- Consults on efforts to continuously improve internal controls, processes, and systems to enhance the effectiveness and efficiency for the program.
- Partners with IT and business colleagues to educate on cyber resiliency and provide actionable metrics that measure the effectiveness of controls.
- Collaborate with key stakeholders, including senior management, Legal, Internal Audit, and external assessors, to ensure alignment and support of the cyber resiliency Program.
- Managing and executing procedures to facilitate and support various cybersecurity resiliency activities.
- Establishes schedules and plans to ensure deadlines are being met.
- Develops efficient processes to facilitate and support regulatory, internal audit and industry standard assessments and audits.
- Provides coaching, feedback, and educates stakeholders and colleagues relative to cyber resiliency requirements and industry best practices.
- Defines or develops risk management policies and procedures to support the implementation of cyber resiliency processes and controls across the enterprise.
- Oversees preparation and submission of cyber resiliency metrics and reports to management, Audit Services, external auditors/assessors, and regulators.
- Oversees assessments to measure the effectiveness of cyber resiliency controls and provides results back to responsible party/owner.
- Communicates and contributes to broad secure architectural solutions for Cyber Resiliency functions such as Incident Response, Disaster Recovery, and Business Continuity.
Requirements
- 5+ years of experience in cyber resiliency related activities, internal audit, external assessments, risk management, regulatory compliance, healthcare industry program management and/or information security in a corporate environment.
- 3+ years of experience in understanding of cyber security compliance frameworks including its requirements, regulations, and implications for financial reporting, program management and internal controls.
- 3+ years of experience in audit methodologies, internal control frameworks, risks assessments, project management and control testing techniques.
- 1+ years of technical experience in cloud technologies.
- 1+ years of program management including strategic planning, decision-making, and project management.
Preferred Qualifications
- Strong understanding of relevant regulations and frameworks aligning to NIST and ISO.
- Exceptional interpersonal skills with the ability to collaborate across departments and influence stakeholders at all levels.
- Demonstrated ability to collaborate effectively with cross-functional teams, build relationships with key stakeholders, and influence others to achieve compliance objectives.
Education
Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience)
Pay Range
The Typical Pay Range For This Role Is $83,430.00 - $222,480.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.