Jobs · Information Technology

Sr IT/IS GRC Consultant – Information Security Policy Mgt. -

Health Care Service Corporation · Richardson, TX · Yesterday
RemoteRemoteInformation Technology$112k–$203k/yrFull-time

About the role

This position serves as a thought leader in the governance, risk and compliance space; planning, designing, enforcing and auditing information technology and information security policies, standards and procedures which safeguard the integrity of and access to enterprise systems, files and data elements. Responsibilities include analyzing, tracking and acting on information technology or information security policy exceptions, audits and assessments; maintaining knowledge of changing technologies and providing recommendations for adaptation of new technologies, processes or policies; identifying areas where existing policies require change or new ones need to be developed; providing management with analysis via risk assessments and briefings/reports to advise them of critical information technology/information security issues that may affect the company’s business objectives and/or compliance; collaborating with and feeding risk information into the enterprise risk management program; evaluating and recommending information technology and information security products, services and/or processes to reduce risk and maintain compliance with applicable policies, mandates, laws and regulations; implementing information technology and information security awareness programs and providing education and training on policies, standards and practices; performing control assessments and working with subject matter experts to document remediation plans; serving as a project lead and mentor to junior GRC team members.

Responsibilities

  • Plan, design, enforce and audit IT and information security policies, standards and procedures.
  • Analyze, track and act on IT or information security policy exceptions, audits and assessments.
  • Maintain knowledge of changing technologies and recommend adaptations of new technologies, processes or policies.
  • Identify areas where existing policies require change or new policies need to be developed, especially due to business expansion and technology advances.
  • Provide management with risk assessments and briefings/reports on critical IT/information security issues affecting business objectives and/or compliance.
  • Collaborate with and feed risk information into the enterprise risk management program.
  • Evaluate and recommend IT and information security products, services and/or processes to reduce risk and maintain compliance.
  • Implement IT and information security awareness programs and provide education and training on policies, standards and practices.
  • Perform control assessments and work with subject matter experts to document remediation plans.
  • Serve as a project lead and mentor to junior GRC team members.

Requirements

  • Bachelor Degree.
  • 5 years of IT/IS work experience with a broad range of exposure to systems analysis, application development, database design and administration.
  • Understanding of IT/IS concepts and ability to articulate those in terms of risk.
  • Ability to recommend and develop strategic responses to issues and risks.
  • Ability to interpret internal or external business issues and translate them into IT concepts that must be addressed via policy.
  • Understanding of key IT/IS laws and regulations, such as the Health Insurance Portability and Accountability Act, as well as governance and compliance frameworks (e.g., NIST, COBIT, ITIL, HITRUST).
  • Understanding of and experience with audit and compliance controls, including previous IT auditing experience and/or technical controls implementation, as well as the ability to respond appropriately to audit and assessment findings.
  • Initiate and invoke creativity to solve complex problems; takes an “outside-in” perspective to identify innovative solutions.
  • Collaborate well with individuals across the business and IT, as well as at all levels of the organization.
  • Strong verbal and written communication skills, including the ability to articulate complex concepts to various technical and non-technical audiences.
  • Experience with and understanding of overall GRC concepts.
  • Ability to work independently, with guidance in only the most complex situations.
  • May lead functional teams and/or projects.

Preferred Qualifications

  • Bachelor Degree in Computer Science, Information Systems, or other related field.
  • Experience with a GRC solution.

Pay

$112,200.00 - $202,600.00. Exact compensation may vary based on skills, experience, and location.

Similar jobs