Talent.com
Director Information Security & Risk Management
Director Information Security & Risk ManagementHighmark Health • Washington, DC, United States
Director Information Security & Risk Management

Director Information Security & Risk Management

Highmark Health • Washington, DC, United States
10 days ago
Job type
  • Full-time
Job description

##

  • Company :
  • Highmark Health##
  • Job Description :
  • JOB SUMMARY
  • This job directs and manages Identity and Access Management (IAM) services for the Enterprise. Provides leadership to the Organization's IAM program, including developing and managing the related policies, standards, architectures, and controls. Partners with Information Security, IT Infrastructure, Application Development, and business units to ensure secure and appropriate access to systems and data. Develops talent, addresses resource management, cultivates capabilities of staff, plans and coordinates work, and manages performance. Actively contributes to the IAM strategic planning process to develop and implement department strategic plans and action steps that support corporate strategic objectives. Defines service levels and monitors adherence. Sets budgets and controls expenses within the operating unit. Creates a team environment that promotes cooperation, empowerment, accountability, customer focus, and effective work relationships in order to realize business goals.
  • ESSENTIAL RESPONSIBILITIES
  • Perform management responsibilities including, but not limited to : involved in hiring and termination decisions; coaching and development; rewards and recognition; performance management and staff productivity.
  • Plan, organize, staff, direct and control the day-to-day operations of the department; develop and implement policies and programs as necessary; may have budgetary responsibility and authority.
  • Communicate effectively with all levels of the organization : facilitate meetings; plan, design and provide presentations; represent HM Health Solutions with outside entities; prepare divisional procedures, policies, reports and correspondence.
  • Provide Leadership to the Department : lead and champion organizational change; encourage participation in activities that support relationship development; champion information security and risk management innovation; demonstrate and champion the following characteristics in fulfilling the responsibilities of the job - passion, empowerment, accountability, collaboration and ethics.
  • Provide oversight of all aspects of project management to ensure continuous improvement of processes : negotiate and collaborate with senior executives and staff to develop solutions and options; develop and adhere to internal standards and strategies; ensure adherence to approved methodologies; coordinate resources, time, contingency plans and risk management; provide oversight regarding metrics, funding, budgets and resources.
  • Other duties as assigned or requested.
  • EDUCATION
  • Required
  • Bachelor’s Degree in Information Security, Information Systems, Information Assurance, Computer Science or related field, or relevant experience and / or education as determined by the company in lieu of bachelor's degree
  • Preferred
  • Master's Degree in Information Security, or a related field with a focus on Identity and Access Management.
  • EXPERIENCE
  • Required
  • 10 - 15 years in Information Security and / or Information Risk Management and / or Information Technology
  • 10 - 15 years in developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
  • 7 - 10 years in mentoring others in a leadership role
  • 5 - 7 years in Staff Management
  • 5 - 7 years in developing and executing strategic plans to realize business objectives
  • 5 - 7 years establishing budgets and meeting fiduciary goals
  • Preferred
  • Experience managing an Identity and Access Management program using industry-standard frameworks.
  • Experience with cloud-based IAM solutions.
  • Experience with implementing and managing role-based access control (RBAC), attribute-based access control (ABAC), and policy-based access control (PBAC).
  • Experience with Zero Trust security models and their application to Identity and Access Management.
  • Experience with the application of Artificial Intelligence (AI) and Machine Learning (ML) to Identity and Access Management.
  • Experience with Identity Governance technologies (e.g., SailPoint).
  • Experience with Public Key Infrastructure (PKI).
  • Experience with Federated Identity Management (SAML, OAuth, OpenID Connect).
  • Experience with enterprise directory services such as Active Directory and LDAP.
  • Experience with securing APIs using IAM principles and technologies.
  • Experience with cloud-based identity providers like Azure AD, AWS IAM, and Google Cloud Identity.
  • LICENSES AND CERTIFICATIONS
  • Required
  • None
  • Preferred
  • (any of the following)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Controls (CRISC)
  • Information Technology Infrastructure Library (ITIL)
  • SKILLS
  • Knowledge of regulatory requirements such as Health Insurance Portability and Accountability Act (HIPPA), HITECH, Payment Card Industry Data Security Standards (PCI DSS), and FIPS-140
  • Strong executive communication and presenting skills
  • Strong teamwork and interpersonal skills
  • Experience in leading process improvement initiatives
  • Ability to motivate high performance, multi-discipline teams
  • Demonstrated competency in project execution
  • Demonstrated abilities in relationship management
  • Language (Other than English) :
  • None
  • Travel Requirement :
  • 0% - 25%
  • PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
  • Position Type
  • Office-basedTeaches / trains others regularlyOccasionallyTravel regularly from the office to various work sites or from site-to-siteRarelyWorks primarily out-of-the office selling products / services (sales employees)NeverPhysical work site requiredYesLifting : up to 10 poundsConstantlyLifting : 10 to 25 poundsOccasionallyLifting : 25 to 50 poundsRarely
  • Disclaimer :
  • The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
  • Compliance Requirement
  • : This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
  • As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
  • Pay Range Minimum :
  • $126,400.00
  • Pay Range Maximum :
  • $236,000.00
  • Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
  • Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.We endeavor to make this site accessible to any and all users. If you would

#J-18808-Ljbffr

Create a job alert for this search

Director Risk Management • Washington, DC, United States

Related jobs
Director, IT Risk Management

Director, IT Risk Management

Common Securitization Solutions • Bethesda, MD, US
Full-time
Common Securitization Solutions (CSS) is seeking an experienced Director, IT Risk Management to join our team of talented professionals. CSS built and operates the largest and most advanced mortgage...Show more
Last updated: 30+ days ago • Promoted
Information Systems Security Manager (ISSM)

Information Systems Security Manager (ISSM)

BTI • Washington, DC, United States
Full-time
Information Systems Security Manager (ISSM).Business Technology Integrators (BTI) is seeking an Information Systems Security Manager (ISSM) to lead a team in executing risk management efforts again...Show more
Last updated: 30+ days ago • Promoted
Director Business Information Security Officer

Director Business Information Security Officer

Surescripts • Arlington, VA, United States
Full-time
We deliver insights at critical points of care for better decisions - from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between provid...Show more
Last updated: 21 days ago • Promoted
Sr. Informations Systems Security Officer 3

Sr. Informations Systems Security Officer 3

Power3 Solutions and Partnering Companies • Howard County, Maryland, USA
Full-time
We are looking to hire a ISSO for a great opportunity in the Annapolis Junction area.TS / SCI Clearance with a Poly required. No CCAs will be accepted at this time.Provides support for a program organ...Show more
Last updated: 13 days ago • Promoted
IT & Security Director

IT & Security Director

Govini • Arlington, VA, United States
Full-time
Govini transforms Defense Acquisition from an outdated manual process to a software-driven strategic advantage for the United States. Our flagship product, Ark, supports Supply Chain, Science and Te...Show more
Last updated: 8 days ago • Promoted
Director, Incident Response & Cybersecurity Leadership

Director, Incident Response & Cybersecurity Leadership

FTI Consulting, Inc • Washington, DC, United States
Full-time
A global consulting firm is seeking a Director for Incident Response in Cybersecurity.The role involves leading complex engagements, managing cybersecurity strategies, and mentoring junior staff.Ca...Show more
Last updated: 17 hours ago • Promoted • New!
FLEX Senior Manager Information Security Incident Command

FLEX Senior Manager Information Security Incident Command

Marriott Hotels Resorts • Bethesda, Maryland, USA
Full-time +1
The Senior Manager supports and manages Red and Red / Blue Team (Red Team) testing as a part of the Global Information Security (GIS) PMO Incident Command team. Triages coordination and updates of iss...Show more
Last updated: 20 days ago • Promoted
Information Systems Security Officer (ISSO) 23

Information Systems Security Officer (ISSO) 23

Avid Technology Professionals • Howard County, Maryland, USA
Full-time
Education / Certification / Training : .Bachelors degree in Computer Science or related discipline from an accredited college or university is required. DoD 8570 compliance with Information Assurance ...Show more
Last updated: 12 days ago • Promoted
Capture Director, DNS

Capture Director, DNS

eSimplicity Inc • Columbia, MD, United States
Full-time
Simplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to childre...Show more
Last updated: 3 days ago • Promoted
Information Systems Security Manager

Information Systems Security Manager

Via Logic LLC • Bethesda, MD, United States
Full-time
Leidos’ High Fidelity Simulation Business Area is responsible for architecting and implementing large-scale System of Systems solutions in support of world class simulation, training, and analysis ...Show more
Last updated: 16 days ago • Promoted
Information Security Manager

Information Security Manager

Howard Community College • Columbia, MD, United States
Full-time
Howard Community College (HCC) is an exciting place to work, learn, and grow! We are proud to have received the Great Colleges to Work For honor for 12 consecutive years, 2009-2020.Howard Community...Show more
Last updated: 10 days ago • Promoted
Cyber and Data Security Manager

Cyber and Data Security Manager

ERG • Alexandria, Virginia, USA
Full-time +1
ERG is a research and consulting firm that provides a wide range of support to federal state and commercial clients.ERG offers multidisciplinary teams with nationally recognized skills in engineeri...Show more
Last updated: 18 days ago • Promoted
Information Security Manager

Information Security Manager

SG2 Recruiting • Alexandria, VA, United States
Full-time
IC client in the Washington DC Metro area.The information security manager (ISM) will apply their proactive approach to safeguarding organizational data and systems. Key responsibilities will includ...Show more
Last updated: 30+ days ago • Promoted
Information Assurance Engineer / Security Manager

Information Assurance Engineer / Security Manager

C2 Labs, Inc. • Washington, DC, United States
Full-time
Information Assurance Engineer / Security Manager.C2 Labs partners with clients on their IT transformation journey via our industry-leading capabilities in full stack development, hyper-automation / ...Show more
Last updated: 30+ days ago • Promoted
Director - Cybersecurity

Director - Cybersecurity

Five Guys • Alexandria, VA, United States
Full-time
The Director - Cybersecurity is responsible for leading Five Guys cybersecurity strategy, governance, and operations to protect critical assets, data, and infrastructure. This executive-level role o...Show more
Last updated: 16 days ago • Promoted
Senior Information Systems Security Officer (ISSO)

Senior Information Systems Security Officer (ISSO)

Belay Technologies • Howard County, Maryland, USA
Full-time
Belay Technologies has been voted Baltimore Business Journals (BBJ) Best Places to Work 2019 runner up in 2020 and a finalist in 2021!. Belay Technologies is seeking an experienced Information Syste...Show more
Last updated: 19 days ago • Promoted
Information Security Compliance Manager (INDG)

Information Security Compliance Manager (INDG)

Bloomberg Industry Group • Arlington, VA, United States
Full-time
As a Manager of Information Security Compliance, you will support Bloomberg Industry Group's Governance, Risk, and Compliance (GRC) programs. You will be part of a team that delivers customer trust,...Show more
Last updated: 9 days ago • Promoted
Director of Cyber Security

Director of Cyber Security

ABBTECH Professional Resources • Silver Spring, MD, United States
Full-time
This program requires US Citizenship or Green Card (Lawful Permanent Residents).Location : Wheaton, MD (must go onsite Mon-Fri). The Cybersecurity Lead will oversee the organization's cybersecurity i...Show more
Last updated: 12 days ago • Promoted