Health Care Service Corporation

Sr IT/IS GRC Consultant - Information Security Policy Mgt. -

Health Care Service Corporation$112K — $202K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree and 5 years of IT/IS experience
  • Strong knowledge of IT/IS concepts related to risk management
  • Ability to translate business issues into IT policy requirements
  • Familiarity with laws like HIPAA and frameworks such as NIST and COBIT
  • Experience with audit and compliance controls, including IT audits
  • Creative problem-solving skills with an outside-in perspective
  • Effective collaboration skills across business and IT departments

Responsibilities

  • Serve as a thought leader in governance, risk, and compliance
  • Plan, design, enforce, and audit IT and information security policies
  • Analyze and track IT or security policy exceptions and audits
  • Provide risk assessments and briefings to management
  • Identify areas for policy development or revision as technology evolves
  • Evaluate IT and security products to reduce risk and ensure compliance
  • Implement and provide training on security awareness programs

Benefits

  • Health and wellness benefits
  • 401(k) savings plan and pension plan
  • Paid time off and paid parental leave
  • Disability and supplemental life insurance
  • Employee assistance program and paid holidays
  • Tuition reimbursement and various other incentives
Full Job Description
Job Summary

This position is responsible for serving as a thought leader in the governance, risk and compliance space; planning, designing, enforcing and auditing information technology and information security policies, standards and procedures which safeguard the integrity of and access to enterprise systems, files and data elements; analyzing, tracking and acting on information technology or information security policy exceptions, audits and assessments; maintaining knowledge of changing technologies, and provides recommendations for adaptation of new technologies, processes or policies; recognizing and identifying potential areas where existing information technology or information security policies, standards and procedures require change, or where new ones need to be developed, especially as a result of future business expansion and technology advances; providing management with analysis via risk assessments and briefings / reports to advise them of critical information technology / information security issues that may affect the company's business objective and / or compliance; collaborating with and feeds it risk information into the enterprise risk management program; evaluating and recommending information technology and information security products, services and/or processes to reduce risk and maintain compliance with applicable policies, mandates, laws and regulations; implementing the activities associated with the information technology and information security awareness programs and provides education and training on information technology and information security policies, standards and practices; performing control assessments and works with appropriate subject matter experts (SME's) to document remediation plans; serving as a project lead and mentor to junior GRC team members.

NOTE: This hybrid role can be located in CHICAGO IL or RICHARDSON TX ~ relocation will not be offered; sponsorship is not available including if you are currently on OPT.

Required Job Qualifications:
* Bachelor Degree and 5 years of IT / IS work experience with a broad range of exposure to systems analysis, application development, database design and administration.
* Understanding of IT / IS concepts and how to artciulate those in terms of risk.Can recommend and develop strategic responses to issues and risks.
* Interpret internal or external business issues and concepts and and can translate those into IT concepts that must be addressed via policy.
* Understanding of key IT / IS laws and regulations, such as the Health Insurance Portability and Accountability Act, as well as governance and compliance frameworks (e.g. NIST, COBIT, ITIL, HITRUST).
* Understanding of and experience with audit and compliance controls. This could include previous IT auditing experience and / or technical controls implementation, as well as the ability to respond apprpriately to audit and assessment findings.
* Initiate and invoke creativity to solve complex problems; takes an "outside -in"perspective to identify innovative solutions.
* Collaborate well with individuals across the business and IT, as well as at all levels of the organization.
* Verbal and written communication skills, including the ability to articulate complex concepts to various technical and non-technical audience.
* Experience with and understanding of overall GRC concepts.
* Work independently, with guidance in only the most complex situations.
* May lead functional teams and / or projects.

Preferred Job Qualifications:
* Bachelor Degree in Computer Science, Information Systems, or other related field.
* Experience with a GRC solution would be preferred.

#LI-BS1

#LI-Remote

Are you being referred to one of our roles? If so, ask your connection at HCSC about our Employee Referral process!

Pay Transparency Statement:

At Health Care Service Corporation, you will be part of an organization committed to offering meaningful benefits to our employees to support their life outside of work. From health and wellness benefits, 401(k) savings plan, pension plan, paid time off, paid parental leave, disability insurance, supplemental life insurance, employee assistance program, paid holidays, tuition reimbursement, plus other incentives, we offer a robust total rewards package for employees. Learn more about our benefit offerings by visiting https://careers.hcsc.com/totalrewards.

The compensation offered will vary depending on your job-related skills, education, knowledge, and experience. This role aligns with an annual incentive bonus plan subject to the terms and the conditions of the plan.

Base Pay Range
$112,200.00 - $202,600.00

Exact compensation may vary based on skills, experience, and location.

About Health Care Service Corporation

Health Care Service Corporation (HCSC) is the largest customer-owned health insurer in the United States. HCSC offers a wide variety of health insurance products and related services, through its operating divisions and subsidiaries in Illinois, Montana, New Mexico, Oklahoma and Texas. HCSC's headquarters is located in Chicago, Illinois.
Learn more about Health Care Service Corporation
Size
24,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Health Care Service Corporation

More Information Technology Jobs

Find similar Sr IT/IS GRC Consultant - Information Security Policy Mgt. - jobs: