Job Summary: Collaborate with key stakeholders and customers in the execution of the processes and controls related to information security third party risk and compliance in order to protect business interests and achieve business goals. Essential Functions:
- Collaborate with key stakeholders and customers in the execution of the processes and controls related to IT risk and compliance in order to protect business interests and achieve business goals
- Establish a baseline of information security (IS) related risk, identify areas of potential exposure, develop and align IT Risk management strategies with CareSource goals and objectives, and execute program ensuring consistency
- Design and implement a common and consistent information security IT risk management program to effectively manage risk in accordance with internal policy, Federal/ State Regulatory requirements, and NIST RMF.
- Maintain a structured internal governance framework, to ensure effective oversight of IS IT risk compliance related to information security
- Provide guidance to the business, executive leadership and other stakeholders to ensure risks are fully understood
- Identify and communicate IS related IT risk findings to key stakeholders (Business/IT/Leadership) and collaborate to determine reasonable solutions to mitigate and/or manage risk to acceptable levels
- Provide and maintain IS IT risk reporting mechanisms, and track and report outcomes from IS IT risk management activities
- Collect, organize, and distribute reports and documents and recommend enhancements to reporting and audit tools
- Stay informed about the latest developments in the IT Risk Management field
- Responsible for leading, developing, coaching direct reports; in collaboration with HR, conduct performance reviews, and disciplinary action
- Perform any other job duties as requested
Education and Experience:
- Bachelor of Science/Arts degree or equivalent work experience is required. Master's or JD is preferred.
- Five (5) or more years of IT experience preferably in a medium to large technical operating environment required
- Three (3) years of experience in the practice of risk management such as assessment of risk, risk-to-business decision making, and maintenance of an effective and comprehensive IT Risk management framework required
- Five (5) years of experience in IT Management is preferred
- Experience supporting complex projects and programs strongly preferred
Competencies, Knowledge and Skills:
- Exceptionally self-motivated and directed (Required)
- Effective oral and written communication skills
- Strong PowerPoint and presentation skills
- Knowledge of contemporary information security risk management and control techniques and frameworks
- Knowledge of management information systems terminology, concepts, and practices
- Considerable knowledge of industry program policies, procedures, regulations, and laws as they relate to security
- Strong decision making/problem solving skills
- Strategic management skills
- Organization skills with strong attention to detail
- Ability to set and manage priorities judiciously
- Ability to present ideas in business-friendly and user-friendly language
- Superior analytical, evaluative, and problem-solving abilities
- Ability to motivate in a team-oriented, collaborative environment
Licensure and Certification:
- Certifications in Information Security Management, such as CISSP, CRISC, CISA, CISM preferred
Working Conditions:
- General office environment; may be required to sit or stand for extended periods of time
Compensation Range: $92,300.00 - $161,600.00 CareSource takes into consideration a combination of a candidate's education, training, and experience as well as the position's scope and complexity, the discretion and latitude required for the role, and other external and internal data when establishing a salary level. In addition to base compensation, you may qualify for a bonus tied to company and individual performance. We are highly invested in every employee's total well-being and offer a substantial and comprehensive total rewards package. Compensation Type: Salary Competencies: - Create an Inclusive Environment - Cultivate Partnerships - Develop Self and Others - Drive Execution - Influence Others - Pursue Personal Excellence - Understand the Business This job description is not all inclusive. CareSource reserves the right to amend this job description at any time. CareSource is an Equal Opportunity Employer. We are dedicated to fostering an inclusive environment that welcomes and supports individuals of all backgrounds. #LI-GB1
|