Health Care Service Corporation

Sr IT/IS GRC Consultant - Information Security Policy Mgt. -

Health Care Service Corporation$112K — $202K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 5 years of IT/IS experience in systems analysis, application development, database design and administration.
  • Ability to articulate IT/IS concepts in terms of risk management and develop strategic responses.
  • Knowledge of IT/IS laws and regulations, including HIPAA, and governance frameworks like NIST and COBIT.
  • Experience with audit and compliance controls, including responding to audit findings.
  • Strong problem-solving creativity and an innovative approach to complex issues.
  • Excellent collaboration skills across various business and IT levels.
  • Effective communication skills for conveying complex ideas to technical and non-technical audiences.
  • Familiarity with GRC concepts and systems.

Responsibilities

  • Lead the planning and design of information technology and security policies and procedures.
  • Analyze and act on IT/security policy exceptions and audit findings.
  • Maintain current knowledge of technology changes and provide recommendations for policy adaptations.
  • Identify and propose changes to existing policies or develop new ones for future business expansions.
  • Provide management with risk assessment analysis and reports on IT/security issues.
  • Integrate risk information into the enterprise risk management program.
  • Implement IT/security awareness programs and deliver training to staff.
  • Mentor junior GRC team members and lead project teams.

Benefits

  • Health and wellness benefits, including medical, dental, and vision coverage.
  • 401(k) savings plan along with a pension plan.
  • Paid time off and parental leave.
  • Disability insurance and supplemental life insurance.
  • Employee assistance program and paid holidays.
  • Tuition reimbursement and other educational incentives.
Full Job Description
Job Summary

This position is responsible for serving as a thought leader in the governance, risk and compliance space; planning, designing, enforcing and auditing information technology and information security policies, standards and procedures which safeguard the integrity of and access to enterprise systems, files and data elements; analyzing, tracking and acting on information technology or information security policy exceptions, audits and assessments; maintaining knowledge of changing technologies, and provides recommendations for adaptation of new technologies, processes or policies; recognizing and identifying potential areas where existing information technology or information security policies, standards and procedures require change, or where new ones need to be developed, especially as a result of future business expansion and technology advances; providing management with analysis via risk assessments and briefings / reports to advise them of critical information technology / information security issues that may affect the company's business objective and / or compliance; collaborating with and feeds it risk information into the enterprise risk management program; evaluating and recommending information technology and information security products, services and/or processes to reduce risk and maintain compliance with applicable policies, mandates, laws and regulations; implementing the activities associated with the information technology and information security awareness programs and provides education and training on information technology and information security policies, standards and practices; performing control assessments and works with appropriate subject matter experts (SME's) to document remediation plans; serving as a project lead and mentor to junior GRC team members.

NOTE: This hybrid role can be located in CHICAGO IL or RICHARDSON TX ~ relocation will not be offered; sponsorship is not available including if you are currently on OPT.

Required Job Qualifications:
* Bachelor Degree and 5 years of IT / IS work experience with a broad range of exposure to systems analysis, application development, database design and administration.
* Understanding of IT / IS concepts and how to artciulate those in terms of risk.Can recommend and develop strategic responses to issues and risks.
* Interpret internal or external business issues and concepts and and can translate those into IT concepts that must be addressed via policy.
* Understanding of key IT / IS laws and regulations, such as the Health Insurance Portability and Accountability Act, as well as governance and compliance frameworks (e.g. NIST, COBIT, ITIL, HITRUST).
* Understanding of and experience with audit and compliance controls. This could include previous IT auditing experience and / or technical controls implementation, as well as the ability to respond apprpriately to audit and assessment findings.
* Initiate and invoke creativity to solve complex problems; takes an "outside -in"perspective to identify innovative solutions.
* Collaborate well with individuals across the business and IT, as well as at all levels of the organization.
* Verbal and written communication skills, including the ability to articulate complex concepts to various technical and non-technical audience.
* Experience with and understanding of overall GRC concepts.
* Work independently, with guidance in only the most complex situations.
* May lead functional teams and / or projects.

Preferred Job Qualifications:
* Bachelor Degree in Computer Science, Information Systems, or other related field.
* Experience with a GRC solution would be preferred.

#LI-BS1

#LI-Remote

Are you being referred to one of our roles? If so, ask your connection at HCSC about our Employee Referral process!

Pay Transparency Statement:

At Health Care Service Corporation, you will be part of an organization committed to offering meaningful benefits to our employees to support their life outside of work. From health and wellness benefits, 401(k) savings plan, pension plan, paid time off, paid parental leave, disability insurance, supplemental life insurance, employee assistance program, paid holidays, tuition reimbursement, plus other incentives, we offer a robust total rewards package for employees. Learn more about our benefit offerings by visiting https://careers.hcsc.com/totalrewards.

The compensation offered will vary depending on your job-related skills, education, knowledge, and experience. This role aligns with an annual incentive bonus plan subject to the terms and the conditions of the plan.

Base Pay Range
$112,200.00 - $202,600.00

Exact compensation may vary based on skills, experience, and location.

About Health Care Service Corporation

Health Care Service Corporation (HCSC) is the largest customer-owned health insurer in the United States. HCSC offers a wide variety of health insurance products and related services, through its operating divisions and subsidiaries in Illinois, Montana, New Mexico, Oklahoma and Texas. HCSC's headquarters is located in Chicago, Illinois.
Learn more about Health Care Service Corporation
Size
24,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Health Care Service Corporation

More Information Technology Jobs

Find similar Sr IT/IS GRC Consultant - Information Security Policy Mgt. - jobs: