About the Role
This job supports risk and compliance assessment activities for Highmark Health across various frameworks like NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, and JCAHO. The role involves partnering with organizational risk, business partners, and technology teams to meet Highmark Health's mission requirements within the enterprise risk appetite, requiring a proactive mindset and comfort in a highly matrixed environment.
Responsibilities
- Plan and conduct risk assessment activities according to appropriate frameworks to identify, assess, prioritize, evaluate, and address financial, information security, privacy, and other risk areas.
- Prepare draft reports and other management reporting deliverables.
- Review work prepared by less experienced team members to ensure audit quality standards.
- Review and interpret inherent risk assessment results and engagement risks.
- Develop assurance plans to address relevant risk areas and ensure proper controls are implemented.
- Review and interpret authoritative guidance and perform qualitative and quantitative impact assessments.
- Conduct additional information gathering and risk assessments as needed.
- Document and report risk assessment results.
- Lead the development of project plans for risk assessment and decisioning in coordination with business owners and stakeholders.
- Collaborate and communicate with various teams across the Enterprise to align risk management objectives, practices, and procedures.
- Interface with business areas, technical staff, project teams, and third parties to execute cross-functional risk assurance projects.
- Lead the communication of assessment results and findings with multiple stakeholder groups.
- Provide consultation and direction throughout the assessment process.
- Interpret complex data flow/information sharing activities, customer integrations, and information safeguards into simplified terminology or process/data flows.
- Maintain risk management reporting dashboards in RSA Archer applications.
- Ensure risk questionnaires and other risk assessments are distributed and completed on time.
- Prepare initial impact assessments.
- Ensure compliance requirements are met across the Enterprise.
- Assist in training and mentoring team members on multi-faceted engagements, platform customer dependencies, and interpretation of complex contract agreements.
- Provide input and consultation on risk and assurance reporting.
- Consult with other areas throughout the engagement lifecycle.
- Assist in providing timely feedback on interpretations regarding authoritative guidance.
- Proactively review updates to departmental desk-level procedures, risk assessment methodology, assessment procedures, questionnaires, and training.
- Monitor compliance with departmental metrics, internal control activities, contractual obligations, and regulatory requirements.
- Respond to customer inquiries and audits.
- Perform other duties as assigned or requested.
Requirements
- 5 years in Audit and Compliance
- 3 years of Business Process Design
- 3 years of Project Management
Skills
- Expert knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes.
- Knowledge of relevant regulatory guidelines, vendor management, sourcing and procurement, and completing assessments of vendors.
- Excellent resource and project planning capabilities.
- Decision making skills.
- History of results-oriented delivery.
- Effective team building across a cross-campus and diverse team of management and staff.
- Strong written and verbal communication skills for diverse audiences (senior management, board, peer, and team).
- Strong relationship building skills.
- Ability to influence with and without authority in a matrixed organization.
- Leadership qualities with an ability to motivate and inspire a group of individuals to achieve superior results.
- High capacity to think analytically, interpret information/observations, apply judgment, and make effective, strategic decisions.
Location
- Office-based
Work Type
- Office-based
Experience Level
- 5 years in Audit and Compliance
- 3 years of Business Process Design
- 3 years of Project Management
Education Level
- Bachelor's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
- 6 years of related and progressive experience in lieu of Bachelor's degree
- Master's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Salary/Compensations
- $79,300.00
- $127,100.00
About the Company
- Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
- We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
- For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
- California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Equal Opportunity
- Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
