This job directs and manages Identity and Access Management (IAM) services for the Enterprise. Provides leadership to the Organization's IAM program, including developing and managing the related policies, standards, architectures, and controls. Partners with Information Security, IT Infrastructure, Application Development, and business units to ensure secure and appropriate access to systems and data. Develops talent, addresses resource management, cultivates capabilities of staff, plans and coordinates work, and manages performance. Actively contributes to the IAM strategic planning process to develop and implement department strategic plans and action steps that support corporate strategic objectives. Defines service levels and monitors adherence. Sets budgets and controls expenses within the operating unit. Creates a team environment that promotes cooperation, empowerment, accountability, customer focus, and effective work relationships in order to realize business goals.
ESSENTIAL RESPONSIBILITIES
Perform management responsibilities including, but not limited to : involved in hiring and termination decisions; coaching and development; rewards and recognition; performance management and staff productivity.
Plan, organize, staff, direct and control the day-to-day operations of the department; develop and implement policies and programs as necessary; may have budgetary responsibility and authority.
Communicate effectively with all levels of the organization : facilitate meetings; plan, design and provide presentations; represent HM Health Solutions with outside entities; prepare divisional procedures, policies, reports and correspondence.
Provide Leadership to the Department : lead and champion organizational change; encourage participation in activities that support relationship development; champion information security and risk management innovation; demonstrate and champion the following characteristics in fulfilling the responsibilities of the job - passion, empowerment, accountability, collaboration and ethics.
Provide oversight of all aspects of project management to ensure continuous improvement of processes : negotiate and collaborate with senior executives and staff to develop solutions and options; develop and adhere to internal standards and strategies; ensure adherence to approved methodologies; coordinate resources, time, contingency plans and risk management; provide oversight regarding metrics, funding, budgets and resources.
Other duties as assigned or requested.
EDUCATION
Required
Bachelor’s Degree in Information Security, Information Systems, Information Assurance, Computer Science or related field, or relevant experience and / or education as determined by the company in lieu of bachelor's degree
Preferred
Master's Degree in Information Security, or a related field with a focus on Identity and Access Management.
EXPERIENCE
Required
10 - 15 years in Information Security and / or Information Risk Management and / or Information Technology
10 - 15 years in developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
7 - 10 years in mentoring others in a leadership role
5 - 7 years in Staff Management
5 - 7 years in developing and executing strategic plans to realize business objectives
5 - 7 years establishing budgets and meeting fiduciary goals
Preferred
Experience managing an Identity and Access Management program using industry-standard frameworks.
Experience with cloud-based IAM solutions.
Experience with implementing and managing role-based access control (RBAC), attribute-based access control (ABAC), and policy-based access control (PBAC).
Experience with Zero Trust security models and their application to Identity and Access Management.
Experience with the application of Artificial Intelligence (AI) and Machine Learning (ML) to Identity and Access Management.
Experience with Identity Governance technologies (e.g., SailPoint).
Experience with Public Key Infrastructure (PKI).
Experience with Federated Identity Management (SAML, OAuth, OpenID Connect).
Experience with enterprise directory services such as Active Directory and LDAP.
Experience with securing APIs using IAM principles and technologies.
Experience with cloud-based identity providers like Azure AD, AWS IAM, and Google Cloud Identity.
LICENSES AND CERTIFICATIONS
Required
None
Preferred
(any of the following)
Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
Certified in Risk and Information Systems Controls (CRISC)
Information Technology Infrastructure Library (ITIL)
SKILLS
Knowledge of regulatory requirements such as Health Insurance Portability and Accountability Act (HIPPA), HITECH, Payment Card Industry Data Security Standards (PCI DSS), and FIPS-140
Strong executive communication and presenting skills
Strong teamwork and interpersonal skills
Experience in leading process improvement initiatives
Ability to motivate high performance, multi-discipline teams
Demonstrated competency in project execution
Demonstrated abilities in relationship management
Language (Other than English) :
None
Travel Requirement :
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-basedTeaches / trains others regularlyOccasionallyTravel regularly from the office to various work sites or from site-to-siteRarelyWorks primarily out-of-the office selling products / services (sales employees)NeverPhysical work site requiredYesLifting : up to 10 poundsConstantlyLifting : 10 to 25 poundsOccasionallyLifting : 25 to 50 poundsRarely
Disclaimer :
The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement
: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum :
$126,400.00
Pay Range Maximum :
$236,000.00
Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.We endeavor to make this site accessible to any and all users. If you would
#J-18808-Ljbffr
serp_jobs.job_alerts.create_a_job
Director Risk Management • Washington, DC, United States
Job_description.internal_linking.related_jobs
serp_jobs.job_card.promoted
IT Risk Management Director
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Director - IT FLCO Application Risk Lead.Key Responsibilities Oversee technology risk management and application control environment Drive proactive oversight of contr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
serp_jobs.job_card.promoted
Director of Security Operations
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Director of Security Operations.Key Responsibilities Guide, mentor, and develop SOC analysts while fostering a high-performance culture Architect and enhance monitorin...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
Information Security Consultant
VirtualVocationsAlexandria, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for an Information and Security Consultant.Key Responsibilities Provide corporate security consulting support to multiple projects and security requests Identify and analyze...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
serp_jobs.job_card.promoted
Director of Product Management
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Director of Product Management - Threat Detection.Key Responsibilities : Define and champion a compelling product vision & strategy for threat detection across the portf...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
Information Security Analyst
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for an Information Security Analyst to detect, prevent, and respond to information threats and security breaches.
Key Responsibilities Maintain information security policies a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
Senior Information Security Engineer
VirtualVocationsAlexandria, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Senior Information Security Engineer focused on Governance, Risk, and Compliance (GRC).Key Responsibilities Baseline control library and implement evidence collection p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
serp_jobs.job_card.new
Senior Manager, Data Security Solutions
VirtualVocationsAlexandria, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Senior Manager, Solutions Architecture, Data Security Pre-sales.Key Responsibilities Cultivates trust and builds relationships with customers to identify pain points an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
serp_jobs.job_card.promoted
Information Security Manager
VirtualVocationsFairfax, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for an IT Information Security Manager.Key Responsibilities : Manage the team responsible for the security of the organization's systems and information assets Oversee the de...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
Director of Incident Response
VirtualVocationsFairfax, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Director of Incident Response.Key Responsibilities Lead engagement scoping and coordinate with victims of ransomware and forensic partners Manage workload distribution...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
Director of Incident Management
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Director, IDD Incident Management and Quality Outcomes, Performance-Based Contracting.Key Responsibilities Oversee the full lifecycle of incident management, including ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
serp_jobs.job_card.promoted
Senior Manager, IAM Security
VirtualVocationsRockville, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Senior Manager, Software Engineering Management Security.Key Responsibilities Lead the IAM program, aligning security controls with business drivers and risks Drive op...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
serp_jobs.job_card.promoted
serp_jobs.job_card.new
Information Systems Security Officer
ManTechFort Meade, MD, United States
serp_jobs.job_card.full_time
ManTech is currently looking for an.Information Systems Security Officer (ISSO).In this role, you will provide support for a program, organization, system, or enclave’s information assurance progra...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
serp_jobs.job_card.promoted
Senior Manager, Application Security
VirtualVocationsAlexandria, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Senior Manager, Application Security to lead teams in Product Security, Vulnerability Management, and Security Assessments.
Key Responsibilities : Manage and mentor teams...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
serp_jobs.job_card.promoted
National Security Operations Director
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a National Security GTM Operations Director to support go-to-market efforts in the Government Markets.
Key Responsibilities Design and implement scalable processes for lea...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
serp_jobs.job_card.promoted
Director of Security Engineering
VirtualVocationsArlington, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Director of Cyber Defense Engineering.Key Responsibilities Lead the development and deployment of an AI-enhanced Security Operations Center (SOC) Define architecture f...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
serp_jobs.job_card.promoted
California Licensed Risk Management Director
VirtualVocationsWashington, District of Columbia, United States
serp_jobs.job_card.full_time
Director of BT Risk Management.Key Responsibilities Establish and lead a comprehensive risk management program for the BT organization, including a federated Governance, Risk, and Compliance (GRC...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
serp_jobs.job_card.promoted
IT Director - Healthcare
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Director of IT & Systems in the healthcare sector.Key Responsibilities Lead and manage IT operations to ensure reliable and secure systems performance Develop and enfo...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
serp_jobs.job_card.promoted
Director of IT Strategy
VirtualVocationsBaltimore, Maryland, United States
serp_jobs.job_card.full_time
A company is looking for a Director of Information Technology Strategy and Delivery.Key Responsibilities Develop and implement strategies for aligning technology initiatives with business goals ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
serp_jobs.job_card.promoted
Senior Director of IT PMO
VirtualVocationsAlexandria, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Senior Director of IT Project Management Office.Key Responsibilities Oversee the successful delivery of a project portfolio, ensuring alignment with corporate goals and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
serp_jobs.job_card.promoted
Compliance Director
VirtualVocationsAlexandria, Virginia, United States
serp_jobs.job_card.full_time
A company is looking for a Compliance Director - Remote.Key Responsibilities Lead risk management and compliance activities to ensure adherence to regulations and quality standards Oversee compl...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30