
IT and Cyber Risk Assessment Specialist
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Pennsylvania.
• Utilizes functional expertise to identify, assess, report, and mitigate IT and Cyber risks for the organization.
• Engages proactively with business and technology leadership, along with other stakeholders, to devise, propose, and implement risk mitigation strategies.
• Assists in developing measures to evaluate the effectiveness and progress of risk mitigation strategies.
• Keeps abreast of current and emerging information security trends, threats, technologies, regulatory requirements, industry best practices, and AI-related risks pertinent to assigned responsibilities.
• Contributes to departmental and organizational initiatives by participating in change management, team objectives, and continuous improvement efforts.
• Executes information security risk management tasks and fulfills project assignments while enhancing expertise in designated areas of responsibility.
• Recognizes opportunities for process enhancements that improve efficiency, consistency, and quality, and communicates suggestions to management.
• Conducts information security risk evaluations of third-party vendors by analyzing security questionnaires, audit reports, control documentation, and other relevant evidence.
• Assesses evaluation results and aids in defining third-party information security risk profiles based on established methodologies, company policies, and industry standards.
• Formulates recommendations to address identified security deficiencies and collaborates with internal and external stakeholders to facilitate risk mitigation and remediation initiatives.
• Records assessment activities, findings, recommendations, and communications within sanctioned governance, risk, and compliance platforms.
• Responds to inquiries regarding the organization's information security practices by providing accurate, approved, and professionally articulated information.
• Collaborates with business stakeholders, risk functions, and various teams across the organization to assist in risk assessment activities, remediation tracking, and risk management initiatives.
• Collects, maintains, and analyzes assessment and risk management data to support program oversight, reporting, and informed decision-making.
• Aids in preparing metrics, dashboards, reports, and presentations that convey assessment outcomes, risk trends, remediation progress, and program performance to stakeholders and leadership.
• Identifies trends, reporting opportunities, and areas for data quality improvement to bolster continuous improvement efforts and informed decision-making.
• Employs critical thinking to analyze and synthesize information from diverse sources, including security questionnaires, audit reports, assessment evidence, policies, standards, and stakeholder discussions, to formulate clear findings, recommendations, and reports.
• Communicates effectively through written and verbal channels, customizing messages, reports, and presentations for technical, business, and leadership audiences.
• Assists in the creation, maintenance, and implementation of information security standards, policies, procedures, and related documentation.
• Evaluates security considerations related to third-party AI solutions and provides insights based on established policies, standards, and industry best practices.
• Exhibits curiosity and a willingness to learn about emerging technologies, including AI, and seeks opportunities to enhance team processes, reporting, and analytical capabilities.
• Bachelor's degree (4 Year) or equivalent experience.
• 1 to 3+ years of Information Security experience directly related to the specific responsibilities of this role.
• Ability to read, analyze, and interpret both internal and external documents such as media/publications, professional journals, technical procedures, government regulations, policies, proposals, and standard operating procedures.
• Strong written and verbal communication skills.
• Excellent organizational abilities with the capacity to prioritize tasks and manage multiple responsibilities while maintaining meticulous attention to detail.
• Solid project management skills, including the critical ability to coordinate and balance multiple projects in a time-sensitive environment while meeting deadlines.
• Strong interpersonal skills with a collaborative approach.
• Ability to exercise sound judgment and discretion regarding confidential information.
• Capable of finding common ground and fostering collaboration among management, colleagues, and peers; can influence outcomes without direct authority.
• Proficiency in Microsoft Office Suite (Word, Excel, PowerPoint, Outlook).
• Successfully completes regulatory and job training requirements.
• Agile mindset; awareness and understanding of Agile methodologies (Preferred).
• Clearly defined career paths and job levels.
• Leadership development and virtual training opportunities.
• PTO/parental leave.
• Competitive 401K and employee benefits.
• Free financial counseling, health coaching, and employee assistance program.
• Tuition assistance program.
• Flexible work arrangements.
• Effective productivity/technology tools and training.
Abbott
HonorHealth
Integrity
MD Integrations
Get handpicked remote jobs straight to your inbox weekly.