Demo

Manager Information Security & Risk Management - Vulnerability Management

Highmark Health
Highmark Health Salary
Providence, RI Full Time
POSTED ON 1/15/2025
AVAILABLE BEFORE 4/9/2025

Company : enGen

Job Description : JOB SUMMARY

This job provides Information Security and Risk Management services for the Organization. Works with peers within security, EnGen customers and application teams to ensure alignment with current and future security needs. Manages activities of various Information Security personnel. Makes decisions on personnel actions (promotions, hiring, terminations, etc.). Develops talent, addresses resource management, cultivates capabilities of staff, planning and coordination of work, and managing performance. Conducts the oversight of security technology products for network, systems, and data. Controls expenses within the operating unit and is responsible for meeting budget goals. Actively contributes to the Information Security ans Risk Management (ISRM) strategic planning process by working with the Directors to develop and implement department strategic plans and action steps that support the corporate strategic objectives. Actively involved in the coordination, implementation, problem solving, communication, and training of new technologies and processes, as they are developed and moved into the environment. Develops and presents Information Security awareness and training programs.

ESSENTIAL RESPONSIBILITIES

Perform management responsibilities including, but not limited to : involved in hiring and termination decisions; coaching and development; rewards and recognition; performance management and staff productivity.

Plan, organize, staff, direct and control the day-to-day operations of the department; develop and implement policies and programs as necessary; may have budgetary responsibility and authority.

Provide oversight of all aspects of project management to ensure continuous improvement of processes : negotiate and collaborate with leadership and staff to develop security solutions and options; develop and adhere to internal standards and strategies; ensure adherence to approved methodologies; coordinate resources, time, contingency plans and risk management.

Provide leadership to the department : lead and champion organizational change; encourage participation in activities that support relationship development; champion information security innovation; encourage and enforce proper training in regards to security issues.

Ensure compliance to Corporate and Information Security policies, standards and procedures.

Communicate effectively with all levels of the organization : facilitate meetings; plan, design and provide presentations; represent EnGen Solutions with outside entities; prepare divisional procedures, policies, reports and correspondence; spread awareness of new and existing security threats; provide oversight regarding metrics, funding, budgets and resources.

Other duties as assigned or requested.

EDUCATION

Required

  • Bachelor’s Degree in Information Security, Information Systems, Information Assurance, Computer Science or related field

Substitutions

  • 6 years of relevant experience substitution for a Bachelor's Degree
  • Preferred

  • Master’s Degree in Computer Science, Information Security or related field
  • EXPERIENCE

    Required

    7 - 10 years in Information Security and / or Information Risk Management and / or Information Technology

    7 - 10 years in developing, communicating and presenting Information Security and Risk Management concepts to varying audiences

    1 - 3 years in mentoring others in a leadership role

    1 - 3 years in Staff Management

    1 - 3 years in developing and executing strategic plans to realize business objectives

    Preferred

    10 - 15 years in Information Security and / or Information Risk Management and / or Information Technology

    3 years of experience in vulnerability management, including conducting vulnerability assessments, developing and implementing vulnerability management policies, and tracking and remediating vulnerabilities

    Experience with specific vulnerability management tools (e.g., Nessus, Qualys, Tenable) and knowledge of common vulnerability databases (e.g., CVE, NVD)

    LICENSES AND CERTIFICATIONS

    Required

  • None
  • Preferred

    Certified Information Systems Security Professional (CISSP) OR

    Certified Information Security Manager (CISM) OR

    Certified in Risk and Information Systems Controls (CRISC) OR

    Information Technology Infrastructure Library (ITIL)

    Relevant security certifications such as GIAC, OSCP, or similar certifications demonstrating expertise in vulnerability management

    SKILLS

    Vulnerability Assessment & Scanning : Deep understanding of vulnerability scanning tools (e.g., Rapid7 Nexpose), methodologies, and best practices

    Exploitation & Penetration Testing : Familiarity with penetration testing techniques, exploit development, and common attack vectors

    Security Analysis & Reporting : Ability to analyze vulnerability data, prioritize risks, and generate comprehensive reports for stakeholders

    Security Frameworks & Standards : Knowledge of industry standards like NIST Cybersecurity Framework, ISO 27001, and PCI DSS

    Network Security : Understanding of network protocols, firewalls, intrusion detection systems (IDS), and other network security technologies

    Operating Systems & Applications : Familiarity with various operating systems (Windows, Linux, macOS) and common applications to identify vulnerabilities

    Cloud Security : Knowledge of cloud security principles, services (AWS, Azure, GCP), and vulnerability management in cloud environments

    Knowledge of regulatory requirements such as Health Insurance Portability and Accountability Act (HIPPA), Payment Card Industry Data Security Standards (PCI DSS), and FIPS-140

    Strong teamwork and interpersonal skills

    Experience in leading process improvement initiatives

    Ability to motivate high performance, multi-discipline teams

    Demonstrated competency in project execution

    Demonstrated abilities in relationship management

    Disclaimer : The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

    Compliance Requirement : This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.

    As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.

    Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

    Pay Range Minimum : 108,000.00

    Pay Range Maximum : 199,800.00

    Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.

    Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, age, religion, sex, national origin, sexual orientation / gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, age, religion, sex, national origin, sexual orientation / gender identity, protected veteran status or disability.

    EEO is The Law

    Equal Opportunity Employer Minorities / Women / Protected Veterans / Disabled / Sexual Orientation / Gender Identity ( )

    We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.

    For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org

    California Consumer Privacy Act Employees, Contractors, and Applicants Notice

    Req ID : J251212

    Salary : $199,800

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Manager Information Security & Risk Management - Vulnerability Management?

    Sign up to receive alerts about other jobs on the Manager Information Security & Risk Management - Vulnerability Management career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $220,784 - $286,649
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $164,835 - $201,088
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Highmark Health

    Highmark Health
    Hired Organization Address Juneau, AK Full Time
    This is an individual contributor, credentialed actuary position. Participates in Highmark's Actuarial Executive Develop...
    Highmark Health
    Hired Organization Address Boston, MA Full Time
    Company : Highmark Health Job Description : JOB SUMMARY This job is a strong advocate of cloud technology and engineerin...
    Highmark Health
    Hired Organization Address Seattle, WA Full Time
    Thank you for your interest in employment at a Highmark Health company. Highmark Health uses an online application proce...
    Highmark Health
    Hired Organization Address Pittsburgh, PA Full Time
    Company : Allegheny Health Network Job Description : GENERAL OVERVIEW : Business Forecasting Associate develops and util...

    Not the job you're looking for? Here are some other Manager Information Security & Risk Management - Vulnerability Management jobs in the Providence, RI area that may be a better fit.

    Risk Management Professional

    Information Resource Group, Providence, RI

    AI Assistant is available now!

    Feel free to start your new journey!