Talent.com
Senior Information Risk Consultant
Senior Information Risk ConsultantPhoenix Staffing • Phoenix, AZ, US
[error_messages.no_longer_accepting]
Senior Information Risk Consultant

Senior Information Risk Consultant

Phoenix Staffing • Phoenix, AZ, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Senior Information Risk Consultant

Company: enGen

Job Summary: Candidates residing within a 50-mile radius of Highmark offices in Camp Hill, Buffalo, or Pittsburgh will be required to work a hybrid schedule, with in-office attendance on Tuesdays, Wednesdays, and Thursdays at one of these locations. Candidates whose primary residence is outside this 50-mile radius will also follow a hybrid work model.

Candidate Must Be US Citizen (due to contractual/access requirements)

The Senior Information Risk Consultant serves as the strategic lead for M&A cybersecurity integration, driving governance and assurance across multiple concurrent acquisitions. This role establishes and manages the Cybersecurity Integration Management Office (C-IMO), ensuring seamless alignment of security requirements during pre- and post-acquisition phases. Beyond M&A, the position provides expert leadership in policy stewardship, control assurance, and information security program maturity, guiding initiatives that strengthen compliance with HIPAA, NIST CSF 2.0, PCI DSS, and SOC frameworks. Acting as a trusted advisor, the analyst interprets complex regulatory and contractual obligations, mentors team members, and partners with cross-functional stakeholders to deliver governance excellence and executive-ready reporting.

Essential Responsibilities

  • Lead in conducting information risk assessments as assigned to the team.
  • Clearly and concisely document and communicate risk assessment results with requester, security architects and management, as appropriate.
  • Conduct and formulate appropriate risk scoring, as it relates to threat, vulnerability, likelihood, impact, security controls/countermeasures, etc.
  • Understand and contribute to inventory of risk register tracking, scoring and associated risk statements.
  • Perform follow up activities related to exceptions, risk acceptance, corrective action plans and additional mitigation activities.
  • Communicate risk treatment methodology, risk avoidance, risk acceptance, risk transference and risk mitigation to appropriate groups.
  • Take lead role in partnering with multiple projects and initiatives to apply security architecture requirements, develop architecture solutions, integrate security into solution designs, access risks of security gaps, and develop architecture remediation.
  • Take lead role with HM Health Solutions teams in developing and maintaining appropriate procedural documentation which meets relevant compliance standards, such as Payment Card Industry - Data Security Standards (PCI-DSS), Health Information Trust Alliance (HITRUST), and International Organization for Standardization (ISO) 27001.
  • Prepare and present solution decks to different levels of management and varying technical experience.
  • Lead in assuring compliance to required standards, procedures, guidelines and processes.
  • Other duties as assigned or requested.

Required Education

Bachelor's Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field

Substitutions: At least 10 years' experience in Information Security, Governance, Risk and/or Compliance

Preferred Education

Master's Degree Computer Science, Information Security or related field

Experience

Minimum: 7 - 10 years' experience in Information Security and/or Information Risk Management and/or Information Technology

5 - 7 years' experience within Information Security Governance, Risk and/or Compliance functions and activities

7 - 10 years' experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences

Familiarity with technologies such as intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms

Preferred: 10 - 15 years' experience in Information Security and/or Information Risk Management including:

  • Proven leadership in cybersecurity governance for mergers and acquisitions, including development and execution of integration playbooks and governance frameworks.
  • Demonstrated ability to drive policy lifecycle management, ensuring timely updates and alignment with HIPAA, NIST CSF 2.0 and other authoritative source requirements.
  • Experience leading control assurance and maturity improvement initiatives, with a focus on remediating gaps and strengthening the cyber security posture.
  • Strong background in interpreting and applying security policies, standards, and regulatory requirements within complex business and technical environments.
  • Expertise in coordinating cross-functional governance forums and producing executive-ready dashboards and narratives for leadership decision-making.
  • Familiarity with governance tools and platforms such as RSA Archer (GRC), Icertis CLM, and policy management systems.
  • Ability to mentor team members and contribute to the strategic direction of cybersecurity governance programs.

Knowledge, Skills & Abilities

Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3

Knowledge of NIST Risk Assessment methodology

Familiarity with secure SDLC best practices

Knowledge of OCTAVE or OCTAVE Allegro risk methodology

Ability to work within high performance, multi-discipline teams

Strong teamwork and inter-personal skills

Required Licensure

None

Preferred Licensure

Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), SANS or similar industry certifications

Travel Requirement:

0% - 25%

Language Requirement (other than English):

0% - 25%

Physical, Mental Demands and Working Conditions

The physical, mental demands and working conditions described here are representative of those that must be met by an employee to successfully perform the essential function of their job. Reasonable accommodations will be made when necessary to enable individuals with disabilities to perform the essential duties of the position, to the extent that they do not cause undue hardship.

Position Type: Office-Based

Office-Based Positions: An employee in this position works in an office environment. The position frequently requires the employee to communicate effectively with others both inside and outside the workplace (e.g., in person, via telephone, via email). The employee must be able to understand, interpret and analyze data, solve problems, concentrate, and research, use available technological resources and systems (e.g., computers and computer programs), multi-task, prioritize, and meet multiple deadlines to complete essential tasks. The employee generally works in a fast-paced and frequently stressful environment, must attend work on a regular and reliable basis as well as adhere to all workplace policies, and may be called upon to work outside regular business hours. Teaches/Trains others regularly Frequently Travels regularly from the office to various work sites or from site-to-site Rarely Works primarily out-of-the office selling products/services (Sales employees) Does Not Apply Physical Work Site Required Yes

Additional Information

Changes Approved By: Kathleen Thompson

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Pay Range Minimum: $78,900.00

Pay Range Maximum: $147,500.00 Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on

[job_alerts.create_a_job]

Senior Information Risk Consultant • Phoenix, AZ, US

[internal_linking.similar_jobs]
Senior Manager, Information Security Operations

Senior Manager, Information Security Operations

Benchmark Electronics • Tempe, AZ, United States
[job_card.full_time]
The Senior Manager, Information Security Operations leads the operational execution of the organizations cybersecurity program.This role is accountable for security monitoring, incident response, t...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
CrowdStrike Consultant

CrowdStrike Consultant

Zortech Solutions • Phoenix, AZ, United States
[job_card.full_time]
Implementation experience (5 plus years preferably) of CrowdStrike Identity module and how it integrates with Ping Fed and LDAP.Experience in configuring, deploying & troubleshooting CrowdStrike Id...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Director, Product Management - Cloud Workload Security

Senior Director, Product Management - Cloud Workload Security

Cisco • Phoenix, AZ, United States
[job_card.full_time]
The application window is expected to close on: 03/05/2026.Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.Preference will be giv...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Business Continuity Lead

Business Continuity Lead

PNC Financial Services Group, Inc. • Phoenix, AZ, United States
[job_card.full_time] +1
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve.We are all united in delivering the best experience for our customers.We work ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Strategic IT Director - Healthcare Lab & Data Security

Strategic IT Director - Healthcare Lab & Data Security

Clinpath Diagnostics • Tempe, AZ, United States
[job_card.full_time]
A leading diagnostics company in Arizona seeks a Director of Information Technology to deliver strategic leadership and manage all IT functions.The role includes overseeing IT systems for clinical ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Sr. Security Consultant - Cyber Threat Intelligence

Sr. Security Consultant - Cyber Threat Intelligence

SHI GmbH • Phoenix, AZ, United States
[job_card.full_time]
Since 1989, SHI International Corp.We've grown every year since, and today we're proud to be a $16 billion global provider of IT solutions and services.Over 17,000 organizations worldwide rely on S...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Sr. Director, Product Management Data Security & Data Protection Services

Sr. Director, Product Management Data Security & Data Protection Services

Teradata • Phoenix, AZ, United States
[job_card.permanent]
At Teradata, we believe that people thrive when empowered with better information.That's why we built the most complete cloud analytics and data platform for AI.By delivering harmonized data, trust...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Audit Advisory Director: Risk Strategy & AI Enablement

Audit Advisory Director: Risk Strategy & AI Enablement

Axon • Scottsdale, AZ, United States
[job_card.full_time]
A leading technology firm is seeking a Director of Corporate Audit Advisory in Scottsdale, AZ.The role involves advancing audit strategies, leading a disciplined framework, and enhancing risk manag...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Manager, Info Security Operations

Senior Manager, Info Security Operations

Benchmark Electronics, Inc • Tempe, Arizona, United States
[job_card.full_time]
Salary: $80,000 - 120,000 per year.Bachelors degree in Cybersecurity, Computer Science, or a related field (Masters preferred).Demonstrated experience in managing Security Operations Centers (SOC),...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Compliance Consulting Director(Commercial P&C Underwriting)

Compliance Consulting Director(Commercial P&C Underwriting)

CNA • Scottsdale, AZ, United States
[job_card.full_time]
You have a clear vision of where your career can go.And we have the leadership to help you get there.At CNA, we strive to create a culture in which people know they matter and are part of something...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Health Information Specialist I - 6007

Health Information Specialist I - 6007

Datavant • Phoenix, Arizona, United States
[job_card.full_time]
Datavant is the data collaboration platform trusted for healthcare.Guided by our mission to make the world’s health data secure, accessible and actionable, we provide critical data solutions for or...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Senior Product Manager, Incident Analysis

Senior Product Manager, Incident Analysis

PagerDuty • Phoenix, AZ, United States
[job_card.full_time]
Fortune 500 and the Forbes AI 50, as well as approximately two-thirds of the Fortune 100.At PagerDuty, you'll address complex challenges, collaborate with ambitious individuals, and contribute to b...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Associate Director, IT Compliance & Governance

Associate Director, IT Compliance & Governance

Sumitomo Pharma • Phoenix, AZ, United States
[job_card.full_time]
Japan with operations in the U.With several marketed products and a diverse pipeline of early- to late-stage investigational assets, we aim to accelerate discovery, research, and development to bri...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Partner Solutions Architect – Cloud Security Enablement

Partner Solutions Architect – Cloud Security Enablement

Wiz • Phoenix, AZ, United States
[job_card.full_time]
A leading cloud security firm is seeking a Regional Partner Solutions Architect to empower their partner ecosystem and support the West Region.In this role, you'll work with regional managers to sc...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
General Counsel - Cybersecurity and Artificial Intelligence

General Counsel - Cybersecurity and Artificial Intelligence

Honeywell • Phoenix, AZ, United States
[job_card.full_time] +1
General Counsel - Cybersecurity and Artificial Intelligence.Phoenix, AZ, United States and 1 more.Serve as the leader on all aspects of the cybersecurity law and artificial intelligence law practic...[show_more]
[last_updated.last_updated_1_hour] • [promoted] • [new]
Enterprise Risk Transformation Leader

Enterprise Risk Transformation Leader

Early Warning® • Scottsdale, AZ, United States
[job_card.full_time]
A financial services firm is seeking an experienced Principal, Risk Management Consultant to lead risk transformation initiatives.The role involves developing risk frameworks, managing process risk...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Specialist - CyberSecurity

Senior Specialist - CyberSecurity

Futran Tech Solutions Pvt. Ltd. • Phoenix, AZ, United States
[job_card.full_time]
A dedicated person is required to support data loading in Saviynt 100 applications and manage access review campaigns via Saviynt EIC.The IAM Governance Analyst will be responsible for core aspects...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
SaaS Assessor

SaaS Assessor

Cynet Systems • Phoenix, AZ, United States
[job_card.full_time]
SaaS applications and third-party vendors for security, risk, and compliance posture.Evaluate and document the Shared Responsibility Model between SaaS providers and the organization.Perform third-...[show_more]
[last_updated.last_updated_variable_days] • [promoted]