IT Security Risk and Compliance Manager

Remote Full-time
About the position Responsibilities β€’ Provide supervision, guidance, and oversight of the WAHBE IT Security Risk and Compliance Team, ensuring effective execution of responsibilities and alignment with organizational goals. β€’ Develop, maintain, and implement cybersecurity compliance deliverables, ensuring they are regularly updated to meet evolving Centers for Medicare & Medicaid Services (CMS), the Internal Revenue Service (IRS) and WAHBE requirements. Deliverables include but are not limited to System Security Plan, Safeguard Security Report, and Annual Attestation. β€’ Conduct comprehensive and complex cybersecurity risk assessments to identify and evaluate potential threats and vulnerabilities. β€’ Independently perform thorough risk analysis, leveraging advanced technical expertise to evaluate vulnerabilities, cyber threats, and the effectiveness of security controls. β€’ Ensure security controls align with WAHBE IT Security standards and policies, while maintaining compliance with applicable federal regulations, including Centers for Medicare & Medicaid Services (CMS) and the Internal Revenue Service (IRS). β€’ Develop and implement an Information security risk management framework including gap analysis, remediation timelines, regular reviews and updates. β€’ Develop risk management metrics and reports to effectively communicate remediation efforts, risk treatment progress, and enhancements to WAHBE's overall security posture. β€’ Develop, track, and coordinate risk mitigation plans for federal reporting including Corrective Action Plan, Plan of Action and Milestones. β€’ Develop and implement processes to validate and verify the completion of remediation activities and reevaluate control effectiveness as needed to ensure ongoing risk mitigation. β€’ Collaborate with Compliance Officer, Information Security Manager, Cloud/Infrastructure Manager, Lead Product Owner, Tech Ops and other IT stakeholders for risk mitigation and control implementation. β€’ Manage Center for Medicare and Medicaid Services (CMS) and Internal Revenue Service (IRS) security audits and safeguard reviews. β€’ Manage and support third party security risk assessment as mandated by federal regulations. Develop, track, maintain and coordinate resulting risk mitigation plans for any findings. β€’ Maintain and update WAHBE's Information Security policies and procedures with evolving CMS, IRS and WAHBE requirements. β€’ Review laws, regulations and legal agreements for security and privacy language to permit authorized, collection, use, maintenance, and sharing of Personally Identifiable Information (PII) and Federal Tax Information (FTI). β€’ Foster innovation and manage risks during major transformations. β€’ Provide regular briefings and updates to CISO and engage with Enterprise Risk and Compliance Committee. β€’ Communicate any obstacles that hinder successful and timely completion of compliance deliverables to the CISO promptly. β€’ Collaborate with external partners in alignment of technology, processes and procedures to meet WAHBE policy, state and federal regulations. β€’ Work as liaison for technical, business and external partners for audits, assessments and reviews. β€’ Recruit, hire, lead, mentor, and retain talented risk and compliance staff. β€’ Other duties as assigned by the CISO. Requirements β€’ Bachelor's degree in engineering or technology-related major and ten years of experience with increasing management responsibilities (minimum of 5 years' experience in staff management). β€’ Five years of experience leading and managing staff and contractor resources within IT risk and compliance domains. β€’ Excellent understanding of standards and guidelines to include CMS standards such as Minimal Acceptable Risk Standards for Exchanges (MARS-E 2.2) and Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE) and/or Internal Revenue Service (IRS) standards such as Publication 1075. β€’ Excellent understanding of audit processes, standards, and procedures. β€’ Strong understanding of best practices in testing methods and metrics. β€’ Upholds the highest ethical standards, demonstrating honesty, transparency, and consistency in words and actions. Takes responsibility for decisions, maintains confidentiality, and adheres to organizational policies and regulatory requirements. β€’ Motivated self-starter with initiative to take independent action and accept responsibility for your actions. β€’ Excellent project management skills and able to set clear timelines, defined roles, and practice effective change management. β€’ Ability to prioritize and manage multiple projects simultaneously and follow-through on issues in a timely manner. β€’ Strong interpersonal skills; ability to work with all levels of internal management and staff, as well as outside clients, vendors, diverse populations, stakeholder groups, and customers. β€’ Skilled in resolving conflicts and addressing disagreements among team members by utilizing active listening and fostering open dialogue. β€’ Creative and proactive problem solver; must possess the ability to make independent decisions and judgments about work priorities. β€’ Well organized, flexible, proactive, resourceful, and efficient with strong attention to detail. β€’ Strong understanding of contracting processes and procedures and contract management. β€’ Ability to maintain a high level of confidentiality. Nice-to-haves β€’ Excellent understanding of National Institute of Standards and Technologies (NIST) security guidelines, outlined in SP 800-53 Rev 5 and NIST Risk Management Framework (RMF), outlined in SP 800-37 Rev., β€’ Proven ability to develop and implement change management strategies, including stakeholder engagement, communication plans, and training programs, to ensure smooth transitions and sustainable adoption of new processes or technologies. β€’ Excellent verbal and written communication skills. β€’ Demonstrates remarkable composure and resilience in fast-paced, high-pressure environments, consistently maintaining focus and delivering results. β€’ Foster a positive and collaborative approach to risk management within a dynamic, fast-paced organizational culture. Apply tot his job Apply tot his job
Apply Now β†’

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Medical Management Nurse

Remote

IT SUMMER INTERN, BIO MEDICAL ENGINEERING

Remote

Remote Overnight Live Chat Support Specialist – Part‑Time Flexible Hours, $25‑$35/hr at Skillora

Remote

Experienced Customer Service Representative – Remote Work Opportunity with arenaflex – Immediate Hiring for Dynamic and Customer-Focused Individuals

Remote

**Experienced Full Stack Data Entry Specialist – Remote Work Opportunity for Teenagers at arenaflex**

Remote

Controller (m/w/d) Projekte und Softwareentwicklung

Remote

Special Collections/University Archives Assistant

Remote

**Experienced Data Entry Operator – Remote Opportunity with arenaflex**

Remote

Infrastructure Advisor

Remote

Travel Clinical Research Assistant, US Based (Los Angeles, CA) (ON-SITE) – Los Angeles, CA

Remote
← Back