Job Summary
The Security Risk Assessor will provide advanced information security consultation across information security, compliance, policy, risk management, and remediation. The role is responsible for conducting risk assessments across applications, systems, infrastructure, cloud environments, and third-party arrangements; identifying security risks and process improvements; documenting findings; and communicating complex security matters effectively to technical and business leadership. The position requires a self-directed professional capable of independently addressing security control gaps, troubleshooting issues, and driving remediation and security best-practice improvements.
Key Responsibilities
• Provide advanced information security consultation across information security, compliance, policy, risk management, and remediation activities.
• Identify process improvements and develop plans to meet or exceed security best practices.
• Help ensure the confidentiality, integrity, and availability of information residing on or transmitted through enterprise devices, servers, systems, and data repositories.
• Conduct risk assessments for applications, systems, infrastructure, cloud environments, and third-party arrangements.
• Document identified risks through detailed risk reports and effectively communicate findings to business and technical leadership.
• Represent the Cyber & Information Security risk assessment services function when reviewing contracts, application designs, integration plans, and related materials.
• Create documentation supporting the risk assessment services team.
• Independently identify and lead efforts to remediate security control deficiencies and implement process improvements.
• Explain complex technical and security issues to non-technical colleagues and business executives.
• Troubleshoot and independently resolve security and risk-related problems as they arise.
Required Qualifications
• 5+ years of experience in at least four relevant disciplines, such as IT governance and operations, access control analysis, incident response, data analysis and control auditing, data protection, advanced threat protection, identity and access management, or integrated technologies with cross-functional impact.
• 5+ years of experience with risk assessment frameworks.
• Broad knowledge of commonly used information security concepts, best practices, and standards.
• Strong collaboration, facilitation, and negotiation skills.
• Strong written and verbal communication skills.
• Familiarity with HIPAA Security Rule and other applicable regulatory requirements.
• Proven analytical and problem-solving abilities.
• Strong project and program management planning and organizational skills.
• Customer service-focused approach with the ability to work effectively with stakeholders.
• Strong time management and prioritization skills.
Preferred Qualifications
• Hands-on experience with information security tools.