Jobs · Information Technology · Michigan

Manager, Information Security Risk and Consulting (REMOTE)

Trinity Health · Livonia, MI · 3 wk ago
On-siteInformation TechnologyFull-time

About the Role

The Manager, Information Security Risk and Consulting plays a critical role in executing and maturing the organization’s third-party and integrated risk management program. This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open source, and internally developed applications, as well as associated system integrations. The role is responsible for identifying, assessing, and prioritizing security risks, ensuring appropriate controls are implemented, and driving continuous monitoring and risk-informed decision-making across the organization.

This position leads the development and reporting of key risk indicators (KRIs) and key performance indicators (KPIs) to provide actionable insights to leadership and support effective governance. Additionally, the role oversees the design and execution of scalable risk management processes, leveraging GRC tools and automation to enhance efficiency and consistency. As a people leader, the Manager builds, develops, and leads a highly engaged, high-performing team of security risk professionals, fostering a culture of accountability, collaboration, and continuous improvement within a complex and evolving security environment.

Responsibilities

  • Develops and leads Trinity Health’s Information Security Third Party Risk and Integrated Risk Management Program, defining team goals, scope of work, and deliverables aligned to Enterprise Information Security (EIS) priorities.
  • Partners with stakeholders to ensure initiatives support the organization’s mission, values, and operational goals while maintaining compliance with regulatory, legal, and contractual obligations.
  • Leads the team’s engagement in regulatory audit and investigation activities, including coordination and production of evidence.
  • Provides hands-on leadership and direct supervision of team members, ensuring effective recruitment, performance management, training, and clear accountability for individual and team productivity.
  • Designs and maintains a structured leadership development framework with clear competencies, promotion criteria, and aligned role expectations.
  • Provides ongoing coaching, mentorship, and development planning to prepare employees for advancement while promoting psychological safety and open communication.
  • Oversees and actively contributes to third-party and integrated risk management activities within Trinity Health GRC platforms, driving continuous process improvement.
  • Performs and reviews vendor tiering and risk assessments, taking ownership of complex or high-risk cases.
  • Defines and maintains the third-party cyber risk lifecycle, including intake, inherent risk scoring, due diligence, control assessment, remediation, risk acceptance, ongoing monitoring, renewal review, material change review, and offboarding.
  • Evaluates vendor controls across identity and access management, network security, cloud security, application security, data protection, encryption, vulnerability management, endpoint protection, logging and monitoring, incident response, disaster recovery, secure SDLC, privacy, and governance.
  • Reviews and advises on contractual clauses related to security controls, breach notification, incident cooperation, right to audit, data protection, encryption, access control, regulatory compliance, cyber insurance, subcontractors, business continuity, data retention, and secure data destruction.
  • Facilitates and leads offshore security risk compliance program.
  • Translates technical findings into business risk language for senior leaders and business owners.
  • Prepares materials for audit, regulatory inquiries, board reporting, and internal governance reviews.
  • Tracks deviations from security procedures and standards, documents risk implications, drives risk remediation, and routes risk acceptance for approvals.
  • Works with Strategy and Planning and Enterprise Information Security Leadership to define and report on key risk indicators (KRIs) and key performance indicators (KPIs).
  • Assigns, manages, and oversees team assessment work, ensuring alignment with standards through coordinated intake and stakeholder engagement.
  • Validates team members’ risk assessments to ensure compliance with Trinity Health information security requirements.
  • Builds and sustains effective relationships with executives and key stakeholders through clear, authentic, risk-informed communication.
  • Synthesizes and communicates enterprise security risk insights to executives and stakeholders in a clear, actionable manner.
  • Serves as a representative of the Director of Strategy and Planning, providing risk-informed insights and actionable recommendations.
  • Leads and coordinates engagement with Enterprise Information Security leadership to ensure aligned execution of security and risk management activities.
  • Maintains a working knowledge of applicable Federal, State, and local laws and regulations, as well as industry developments and regulatory changes.
  • Provides leadership and oversight of security risk initiatives, ensuring successful delivery and alignment with organizational standards.
  • Develops and manages relationships to ensure stakeholders are actively engaged throughout project, program, or initiative lifecycles.
  • Works with stakeholders to ensure business process workflows, training, and communication plans are completed.
  • Provides tools, training, guidance, and resources to resolve problems, avert risks, and maintain engagement to support risk avoidance and remediation.

Requirements

  • Bachelor’s degree in Information Security or an equivalent combination of education and experience.
  • One or more security certifications: Certified Information Systems Security Professional (CISSP), International Social Security Association (ISSA), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified in Governance, Risk and Compliance (GRCP) or equivalent.
  • Minimum of seven (7) years of progressive experience in information services, including three (3) years working in cybersecurity governance, risk, and compliance (GRC).
  • Minimum of three (3) years of management experience with demonstrated leadership effectiveness and emotional intelligence.
  • Proven ability to lead, develop, and retain high-performing, highly engaged teams in complex security environments.
  • Minimum of three (3) years of progressively responsible experience in healthcare and/or other regulated industries.
  • Strong knowledge of the HIPAA Security Rule and applicable industry security regulations, with the ability to rapidly build and sustain expertise.
  • Proven knowledge of enterprise security principles and practices, with hands-on experience or demonstrated capability in implementing, integrating, and managing security solutions across enterprise environments.
  • Working knowledge of one or more information security regulations and/or frameworks: HIPAA, ISO 27001/2, FISMA, FIPS, HITRUST, and NIST security.
  • Experience with GRC platforms (e.g., ServiceNow GRC, RSA Archer, OneTrust, or similar) supporting risk and compliance programs.
  • Ability to serve as a leadership representative and interface with executives, team members, and end users, exercising effective facilitation skills, judgment, and decision-making.
  • Demonstrated courageous, authentic leadership through clear, human-centered communication with senior leaders and stakeholders.
  • Excellent oral and written communication skills, with the ability to facilitate meetings between diverse groups and prepare independent advisory recommendations.

Similar jobs