Director Information Security & Risk ManagementHighmark Health • Washington, DC, United States
Director Information Security & Risk Management
Highmark Health • Washington, DC, United States
11 days ago
Job type
Full-time
Job description
##
Company :
Highmark Health##
Job Description :
JOB SUMMARY
This job directs and manages Identity and Access Management (IAM) services for the Enterprise. Provides leadership to the Organization's IAM program, including developing and managing the related policies, standards, architectures, and controls. Partners with Information Security, IT Infrastructure, Application Development, and business units to ensure secure and appropriate access to systems and data. Develops talent, addresses resource management, cultivates capabilities of staff, plans and coordinates work, and manages performance. Actively contributes to the IAM strategic planning process to develop and implement department strategic plans and action steps that support corporate strategic objectives. Defines service levels and monitors adherence. Sets budgets and controls expenses within the operating unit. Creates a team environment that promotes cooperation, empowerment, accountability, customer focus, and effective work relationships in order to realize business goals.
ESSENTIAL RESPONSIBILITIES
Perform management responsibilities including, but not limited to : involved in hiring and termination decisions; coaching and development; rewards and recognition; performance management and staff productivity.
Plan, organize, staff, direct and control the day-to-day operations of the department; develop and implement policies and programs as necessary; may have budgetary responsibility and authority.
Communicate effectively with all levels of the organization : facilitate meetings; plan, design and provide presentations; represent HM Health Solutions with outside entities; prepare divisional procedures, policies, reports and correspondence.
Provide Leadership to the Department : lead and champion organizational change; encourage participation in activities that support relationship development; champion information security and risk management innovation; demonstrate and champion the following characteristics in fulfilling the responsibilities of the job - passion, empowerment, accountability, collaboration and ethics.
Provide oversight of all aspects of project management to ensure continuous improvement of processes : negotiate and collaborate with senior executives and staff to develop solutions and options; develop and adhere to internal standards and strategies; ensure adherence to approved methodologies; coordinate resources, time, contingency plans and risk management; provide oversight regarding metrics, funding, budgets and resources.
Other duties as assigned or requested.
EDUCATION
Required
Bachelor’s Degree in Information Security, Information Systems, Information Assurance, Computer Science or related field, or relevant experience and / or education as determined by the company in lieu of bachelor's degree
Preferred
Master's Degree in Information Security, or a related field with a focus on Identity and Access Management.
EXPERIENCE
Required
10 - 15 years in Information Security and / or Information Risk Management and / or Information Technology
10 - 15 years in developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
7 - 10 years in mentoring others in a leadership role
5 - 7 years in Staff Management
5 - 7 years in developing and executing strategic plans to realize business objectives
5 - 7 years establishing budgets and meeting fiduciary goals
Preferred
Experience managing an Identity and Access Management program using industry-standard frameworks.
Experience with cloud-based IAM solutions.
Experience with implementing and managing role-based access control (RBAC), attribute-based access control (ABAC), and policy-based access control (PBAC).
Experience with Zero Trust security models and their application to Identity and Access Management.
Experience with the application of Artificial Intelligence (AI) and Machine Learning (ML) to Identity and Access Management.
Experience with Identity Governance technologies (e.g., SailPoint).
Experience with Public Key Infrastructure (PKI).
Experience with Federated Identity Management (SAML, OAuth, OpenID Connect).
Experience with enterprise directory services such as Active Directory and LDAP.
Experience with securing APIs using IAM principles and technologies.
Experience with cloud-based identity providers like Azure AD, AWS IAM, and Google Cloud Identity.
LICENSES AND CERTIFICATIONS
Required
None
Preferred
(any of the following)
Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
Certified in Risk and Information Systems Controls (CRISC)
Information Technology Infrastructure Library (ITIL)
SKILLS
Knowledge of regulatory requirements such as Health Insurance Portability and Accountability Act (HIPPA), HITECH, Payment Card Industry Data Security Standards (PCI DSS), and FIPS-140
Strong executive communication and presenting skills
Strong teamwork and interpersonal skills
Experience in leading process improvement initiatives
Ability to motivate high performance, multi-discipline teams
Demonstrated competency in project execution
Demonstrated abilities in relationship management
Language (Other than English) :
None
Travel Requirement :
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-basedTeaches / trains others regularlyOccasionallyTravel regularly from the office to various work sites or from site-to-siteRarelyWorks primarily out-of-the office selling products / services (sales employees)NeverPhysical work site requiredYesLifting : up to 10 poundsConstantlyLifting : 10 to 25 poundsOccasionallyLifting : 25 to 50 poundsRarely
Disclaimer :
The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement
: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum :
$126,400.00
Pay Range Maximum :
$236,000.00
Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.We endeavor to make this site accessible to any and all users. If you would
#J-18808-Ljbffr
Create a job alert for this search
Director Risk Management • Washington, DC, United States
Related jobs
Director, IT Risk Management
Common Securitization Solutions • Bethesda, MD, US
Full-time
Common Securitization Solutions (CSS) is seeking an experienced Director, IT Risk Management to join our team of talented professionals.
CSS built and operates the largest and most advanced mortgage...Show more
Last updated: 30+ days ago • Promoted
Information Systems Security Manager (ISSM)
BTI • Washington, DC, United States
Full-time
Information Systems Security Manager (ISSM).Business Technology Integrators (BTI) is seeking an Information Systems Security Manager (ISSM) to lead a team in executing risk management efforts again...Show more
Last updated: 30+ days ago • Promoted
Director Business Information Security Officer
Surescripts • Arlington, VA, United States
Full-time
We deliver insights at critical points of care for better decisions - from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between provid...Show more
Last updated: 22 days ago • Promoted
IT & Security Director
Govini • Arlington, VA, United States
Full-time
Govini transforms Defense Acquisition from an outdated manual process to a software-driven strategic advantage for the United States.
Our flagship product, Ark, supports Supply Chain, Science and Te...Show more
Last updated: 9 days ago • Promoted
Information Systems Security Manager
Slope • Washington, DC, United States
Full-time
Anduril Industries is a defense technology company with a mission to transform U.By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the def...Show more
Last updated: 30+ days ago • Promoted
Director Consulting, Cloud Security
Gartner • Arlington, VA, United States
Full-time
Join Gartner Consulting, where insights meet execution.We partner with leaders across industries to address their most critical priorities and achieve measurable results.
As a Director, Cloud Cybers...Show more
Last updated: 30+ days ago • Promoted
Director of Offensive Security Engineering
NightDragon Acquisition Corp. • Washington, DC, US
Full-time
A leading cybersecurity firm is seeking a Director of Software Engineering – Offensive Security to lead the development of innovative security solutions.
The ideal candidate will have a strong backg...Show more
Last updated: 1 day ago • Promoted
Capture Director, DNS
eSimplicity Inc • Columbia, MD, United States
Full-time
Simplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to childre...Show more
Last updated: 4 days ago • Promoted
Information Security Manager
Howard Community College • Columbia, MD, United States
Full-time
Howard Community College (HCC) is an exciting place to work, learn, and grow! We are proud to have received the Great Colleges to Work For honor for 12 consecutive years, 2009-2020.Howard Community...Show more
Last updated: 11 days ago • Promoted
Managing Director, Cybersecurity, Information Governance
Ankura • Washington, DC, United States
Full-time
Ankura is a team of excellence founded on innovation and growth.Ankura's fast-growing global Cybersecurity and Data Privacy Practice offers a full-service suite of cybersecurity and data privacy so...Show more
Last updated: 5 hours ago • Promoted • New!
Information Security Manager
SG2 Recruiting • Alexandria, VA, United States
Full-time
IC client in the Washington DC Metro area.The information security manager (ISM) will apply their proactive approach to safeguarding organizational data and systems.
Key responsibilities will includ...Show more
Last updated: 30+ days ago • Promoted
Information Assurance Engineer / Security Manager
C2 Labs, Inc. • Washington, DC, United States
Full-time
Information Assurance Engineer / Security Manager.C2 Labs partners with clients on their IT transformation journey via our industry-leading capabilities in full stack development, hyper-automation / ...Show more
Last updated: 30+ days ago • Promoted
Senior Director, Cybersecurity Programs
The Aspen Institute • Washington, DC, United States
Full-time
The Aspen Institute is a global nonprofit organization committed to realizing a free, just, and equitable society.Since its founding in 1949, the Institute has been driving change through dialogue,...Show more
California, US residents click here (https : / / www.UNITHER%20Applicant%20Notice%20-%20%2812-22-23%29%20Final%202.The job details are as follows.
Who we are We are the first publicly-traded biotech or ...Show more
Last updated: 3 hours ago • Promoted • New!
Director - Cybersecurity
Five Guys • Alexandria, VA, United States
Full-time
The Director - Cybersecurity is responsible for leading Five Guys cybersecurity strategy, governance, and operations to protect critical assets, data, and infrastructure.
This executive-level role o...Show more
Last updated: 17 days ago • Promoted
Sr. Manager, Information Security Administration
The American Institute of Architects • Washington, DC, United States
Full-time
The American Institute of Architects (AIA).AIA will provide you with the opportunity to advocate for the value of architecture and give architects and design professionals the resources they need t...Show more
Last updated: 1 day ago • Promoted
Information Security Compliance Manager (INDG)
Bloomberg Industry Group • Arlington, VA, United States
Full-time
As a Manager of Information Security Compliance, you will support Bloomberg Industry Group's Governance, Risk, and Compliance (GRC) programs.
You will be part of a team that delivers customer trust,...Show more
Last updated: 10 days ago • Promoted
Director of Cyber Security
ABBTECH Professional Resources • Silver Spring, MD, United States
Full-time
This program requires US Citizenship or Green Card (Lawful Permanent Residents).Location : Wheaton, MD (must go onsite Mon-Fri).
The Cybersecurity Lead will oversee the organization's cybersecurity i...Show more