Talent.com
Senior Information Risk Consultant
Senior Information Risk ConsultantHighmark Health • CT, Working at Home, Conneticut
Senior Information Risk Consultant

Senior Information Risk Consultant

Highmark Health • CT, Working at Home, Conneticut
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Description

:

JOB SUMMARY

Candidates residing within a 50-mile radius of Highmark offices in Camp Hill, Buffalo, or Pittsburgh will be required to work a hybrid schedule, with in-office attendance on Tuesdays, Wednesdays, and Thursdays at one of these locations. Candidates whose primary residence is outside this 50-mile radius will also follow a hybrid work model.

***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***

The Senior Information Risk Consultant serves as the strategic lead for M&A cybersecurity integration, driving governance and assurance across multiple concurrent acquisitions. This role establishes and manages the Cybersecurity Integration Management Office (C‑IMO), ensuring seamless alignment of security requirements during pre- and post-acquisition phases. Beyond M&A, the position provides expert leadership in policy stewardship, control assurance, and information security program maturity, guiding initiatives that strengthen compliance with HIPAA, NIST CSF 2.0, PCI DSS, and SOC frameworks. Acting as a trusted advisor, the analyst interprets complex regulatory and contractual obligations, mentors team members, and partners with cross-functional stakeholders to deliver governance excellence and executive-ready reporting.

ESSENTIAL RESPONSIBILITIES

  • Lead in conducting information risk assessments as assigned to the team. Request and analyze documentation necessary to perform appropriate assessment and conduct necessary interviews in order to collect and review relevant materials necessary to produce results of the assessment.
  • Clearly and concisely document and communicate risk assessment results with requester, security architects and management, as appropriate.
  • Conduct and formulate appropriate risk scoring, as it relates to threat, vulnerability, likelihood, impact, security controls/countermeasures, etc.
  • Understand and contribute to inventory of risk register tracking, scoring and associated risk statements.
  • Perform follow up activities related to exceptions, risk acceptance, corrective action plans and additional mitigation activities.
  • Communicate risk treatment methodology, risk avoidance, risk acceptance, risk transference and risk mitigation to appropriate groups.
  • Take lead role in partnering with multiple projects and initiatives to apply security architecture requirements, develop architecture solutions, integrate security into solution designs, access risks of security gaps, and develop architecture remediation.
  • Take lead role with HM Health Solutions teams in developing and maintaining appropriate procedural documentation which meets relevant compliance standards, such as Payment Card Industry - Data Security Standards (PCI-DSS), Health Information Trust Alliance (HITRUST), and International Organization for Standardization (ISO) 27001.
  • Prepare and present solution decks to different levels of management and varying technical experience.
  • Lead in assuring compliance to required standards, procedures, guidelines and processes.
  • Other duties as assigned or requested.

REQUIRED EDUCATION

Bachelor’s Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field

At least 10 years' experience in Information Security, Governance, Risk and/or Compliance

PREFERRED EDUCATION

Master’s Degree – Computer Science, Information Security or related field

EXPERIENCE

  • 7 - 10 years' experience in Information Security and/or Information Risk Management and/or Information Technology
  • 5 - 7 years' experience within Information Security Governance, Risk and/or Compliance functions and activities
  • 7 - 10 years’ experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
  • Familiarity with technologies such as intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
  • 10 - 15 years' experience in Information Security and/or Information Risk Management including:

  • Proven leadership in cybersecurity governance for mergers and acquisitions, including development and execution of integration playbooks and governance frameworks.
  • Demonstrated ability to drive policy lifecycle management, ensuring timely updates and alignment with HIPAA, NIST CSF 2.0 and other authoritative source requirements.
  • Experience leading control assurance and maturity improvement initiatives, with a focus on remediating gaps and strengthening the cyber security posture.
  • Strong background in interpreting and applying security policies, standards, and regulatory requirements within complex business and technical environments.
  • Expertise in coordinating cross-functional governance forums and producing executive-ready dashboards and narratives for leadership decision-making.
  • Familiarity with governance tools and platforms such as RSA Archer (GRC), Icertis CLM, and policy management systems.
  • Ability to mentor team members and contribute to the strategic direction of cybersecurity governance programs.

KNOWLEDGE, SKILLS & ABILITIES

  • Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
  • Knowledge of NIST Risk Assessment methodology
  • Familiarity with secure SDLC best practices
  • Knowledge of OCTAVE or OCTAVE Allegro risk methodology
  • Ability to work within high performance, multi-discipline teams
  • Strong teamwork and inter-personal skills

REQUIRED LICENSURE

None

PREFERRED LICENSURE

Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), SANS or similar industry certifications

TRAVEL REQUIREMENT:
0% - 25%

LANGUAGE REQUIREMENT ()?
0% - 25%

PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS
(

Office-Based

An employee in this position works in an office environment. The position frequently requires the employee to communicate effectively with others both inside and outside the workplace (e.g., in person, via telephone, via email). The employee must be able to understand, interpret and analyze data, solve problems, concentrate, and research, use available technological resources and systems (e.g., computers and computer programs), multi-task, prioritize, and meet multiple deadlines to complete essential tasks. The employee generally works in a fast-paced and frequently stressful environment, must attend work on a regular and reliable basis as well as adhere to all workplace policies, and may be called upon to work outside regular business hours.

Teaches/Trains others regularly

Frequently

Travels regularly from the office to various work sites or from site-to-site

Rarely

Works primarily out-of-the office selling products/services (Sales employees)

Does Not Apply

Physical Work Site Required

Yes

An employee in this position may work in a home or company office environment but is also frequently driving to and from various locations to perform the work off-site. The position frequently requires the employee to communicate effectively with others both inside and outside the workplace (e.g., in person, via telephone, via email). The employee must be able to understand, interpret and analyze data, solve problems, concentrate, and research, use available technological resources and systems (e.g., computers and computer programs), multi-task, prioritize, and meet multiple deadlines to complete essential tasks. The employee generally works in a fast-paced and frequently stressful environment, must attend work on a regular and reliable basis as well as adhere to all workplace policies, and may be called upon to work outside regular business hours.

An employee in this position is frequently required to move throughout the workplace, sit, stand and walk, use hands and fingers to hold objects, tools or controls, possess fine motor skills (e.g., to write and operate a computer or to steer transportation equipment), possess gross motor skills (e.g., to carry items), reach with hands and arms, climb stairs and ladders, balance, stoop, kneel crouch and crawl, communicate effectively, and talk and hear. Specific vision abilities required by the job include close vision, distance vision, color vision, peripheral vision, depth perception, and the ability to adjust focus. The employee must be able to work in a busy environment where decisions often must be made quickly, must attend work on a regular and reliable basis, must adhere to all workplace policies, and may be called upon to work outside regular business hours. This work occurs in a [example: warehouse, hospital or provider’s office or mailroom].

Lifting: up to 10 pounds

Does Not Apply

Lifting: 10 to 25 pounds

Does Not Apply

Lifting: 25 to 50 pounds

Does Not Apply

ADDITIONAL INFORMATION

Changes Approved By:

Kathleen Thompson

As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Pay Range Minimum:

$78,900.00

Pay Range Maximum:

$147,500.00

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.

We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.

For accommodation requests, please contact HR Services Online at

[job_alerts.create_a_job]

Senior Information Risk Consultant • CT, Working at Home, Conneticut

[internal_linking.similar_jobs]

Senior IT Director - Cheshire, CT

The Lane Construction CorporationCheshire, CT, United States
[job_card.full_time]

Lane Construction is one of America's leading construction companies, specializing in large, complex civil infrastructure.For 135 years, it has contributed to the development of the country's trans...[internal_linking.show_more]

 • [job_card.promoted]

Network Pricing Consultant - Remote2346031 | Shelton, CT | Remote

UnitedHealthcare At HomeShelton, CT, United States
[filters.remote]
[job_card.full_time]

At UnitedHealthcare, we're simplifying the health care experience, creating healthier communities and removing barriers to quality care.The work you do here impacts the lives of millions of people ...[internal_linking.show_more]

 • [job_card.promoted]

Senior Claim Quality Assurance Director

ChubbNew Haven, CT, United States
[job_card.full_time]

Claims Quality Assurance Team Member.As a member of the Claims Quality Assurance Team, a person in this position is responsible for supporting continuous improvement by measuring aggregate reviews ...[internal_linking.show_more]

 • [job_card.promoted]

Network Pricing Consultant - Remote2346031 | Shelton, CT | Remote

UnitedHealthcareShelton, CT, United States
[filters.remote]
[job_card.full_time]

At UnitedHealthcare, we're simplifying the health care experience, creating healthier communities and removing barriers to quality care.The work you do here impacts the lives of millions of people ...[internal_linking.show_more]

 • [job_card.promoted]

Remote Digital Investigative Analyst

Lemieux & AssociatesNorth Haven, CT, United States
[filters.remote]
[job_card.full_time]

Job Description Digital Investigative AnalystJob Classification :Non-ExemptNote :Nothing in this job description restricts managements right to assign or reassign duties and responsibilities to thi...[internal_linking.show_more]

 • [job_card.promoted]

Technology Fund - Senior Associate

Connecticut InnovationsNew Haven, CT, United States
[job_card.full_time]

Come join Connecticut Innovations (CI) as a.Technology Fund with opportunities to support other CI Venture Funds!.As Connecticut's strategic venture capital arm and one of the most active investors...[internal_linking.show_more]

 • [job_card.promoted]

Remote Finance AI Investment Director (Flexible Hours)

DataAnnotationCT, United States
[filters.remote]
[job_card.full_time]

A leading AI company is seeking an Investment Director to enhance AI understanding of financial principles.This role offers the flexibility of working remotely full‑time or part‑time, allowing you ...[internal_linking.show_more]

 • [job_card.promoted]

Cyber Compliance Manager (Remote)

RaytheonNew Haven, CT, United States
[filters.remote]
[job_card.full_time]

Compliance Services ManagerRTX Corporation is an Aerospace and Defense company that provides advanced systems and services for commercial, military and government customers worldwide.It comprises t...[internal_linking.show_more]

 • [job_card.promoted]

Launch Director Consultant – Connecticut

Business Networking InternationalCT, United States
[job_card.full_time]

Launch Director Consultant – Connecticut.Launch Director Consultants (“Launch DCs”) are enthusiastic and driven outside sales representatives that generate leads and drive sales by coaching prospec...[internal_linking.show_more]

 • [job_card.promoted]

Senior Clinical Pharmacy Leader: Safety, Policy & Analytics

Yale NewHaven HealthWest Haven, Connecticut, United States
[job_card.full_time]

A healthcare organization in West Haven, Connecticut, seeks a Sr Clinical Pharmacy Specialist to enhance clinical quality and safety in medication use.Ideal candidates will have a Pharm.Connecticut...[internal_linking.show_more]

 • [job_card.promoted]

Senior Actuary Strategic Analytics Remote Impact Leader

Centene CorporationCT, United States
[filters.remote]
[job_card.full_time]

A leading healthcare organization is seeking a Senior Actuary to drive strategy and valuation for key initiatives.The role requires advanced technical skills and substantial actuarial experience, o...[internal_linking.show_more]

 • [job_card.promoted]

Senior Regulatory Compliance Consultant

WipfliMiddlebury, CT, United States
[job_card.full_time]

Senior Regulatory Compliance Consultant.Our people are core to everything we dothe catalyst behind our ability to create exceptional impact and extraordinary results.We encourage each individual to...[internal_linking.show_more]

 • [job_card.promoted]

Internal Audit Senior Consultant - Trust Focused

WipfliMiddlebury, CT, United States
[job_card.full_time]

Internal Audit Senior Consultant - Trust Focused.Our people are core to everything we dothe catalyst behind our ability to create exceptional impact and extraordinary results.We encourage each indi...[internal_linking.show_more]

 • [job_card.promoted]

High Net Worth BSA Analyst

Patriot Bank, N.A.Orange, CT, United States
[job_card.full_time]

The High Net Worth (HNW) Bank Secrecy Act Analyst plays a critical role in safeguarding the bank from financial crime risks by performing comprehensive Customer Due Diligence (CDD) and Enhanced Due...[internal_linking.show_more]

 • [job_card.promoted]

Network Pricing Consultant - Remote2346031 | Shelton, CT | Remote

United Health GroupShelton, CT, United States
[filters.remote]
[job_card.full_time]

At UnitedHealthcare, we're simplifying the health care experience, creating healthier communities and removing barriers to quality care.The work you do here impacts the lives of millions of people ...[internal_linking.show_more]

 • [job_card.promoted]

Network Pricing Consultant - Remote

UMRShelton, CT, United States
[filters.remote]
[job_card.full_time]

At UnitedHealthcare, we're simplifying the health care experience, creating healthier communities and removing barriers to quality care.The work you do here impacts the lives of millions of people ...[internal_linking.show_more]

 • [job_card.promoted]

Healthcare IT Director — Service & Security Leader

PennantCT, United States
[job_card.full_time]

A leading healthcare services provider is looking for an experienced IT Director to oversee IT operations at their Service Center in Connecticut.This role entails managing a team, improving IT proc...[internal_linking.show_more]

 • [job_card.promoted]

AVP, Information Security

VerinextNorth Haven, CT, US
[job_card.full_time]
[filters_job_card.quick_apply]

The Assistant Vice President of Information Security Operations is a proactive leadership position responsible for the design, execution, planning, budgeting, protection, monitoring, and integratio...[internal_linking.show_more]