
Manager, Information Security Risk and Consulting
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in Michigan.
• The Manager of Information Security Risk and Consulting is pivotal in implementing and advancing the organization’s third-party and integrated risk management program.
• Responsible for overseeing enterprise risk assessments related to commercial off-the-shelf (COTS), open source, and internally created applications, along with their associated system integrations.
• Identify, evaluate, and prioritize security risks while ensuring that suitable controls are established.
• Promote ongoing monitoring and risk-informed decision-making throughout the organization.
• Spearhead the development and reporting of key risk indicators (KRIs) and key performance indicators (KPIs).
• Manage the design and execution of scalable risk management processes, utilizing GRC tools and automation to improve efficiency and consistency.
• Recruit, develop, and lead a highly engaged and high-performing team of security risk professionals.
• Cultivate a culture of accountability, collaboration, and continuous improvement within a complex and evolving security landscape.
• Create and lead Trinity Health’s Information Security Third Party Risk and Integrated Risk Management Program.
• A Bachelor’s degree in Information Security or a comparable combination of education and experience.
• One or more security certifications such as Certified Information Systems Security Professional (CISSP), International Social Security Association (ISSA), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified in Governance, Risk and Compliance (GRCP), or an equivalent qualification.
• At least seven (7) years of progressive experience in information services, including a minimum of three (3) years in cybersecurity governance, risk, and compliance (GRC).
• A minimum of three (3) years in a management role, demonstrating effective leadership and emotional intelligence.
• Proven track record of leading, developing, and retaining high-performing, engaged teams in complex security environments, including managing diverse talent and executing customized development strategies to promote individual and team success.
• A minimum of three (3) years of progressively responsible experience in healthcare and/or other regulated sectors.
• Strong understanding of the HIPAA Security Rule and relevant industry security regulations, with the capacity to quickly build and maintain expertise; working knowledge of broader HIPAA mandates, including Privacy and Breach Notification Rules.
• Demonstrated knowledge of enterprise security principles and practices, with practical experience or proven ability in implementing, integrating, and managing security solutions across enterprise environments.
• Familiarity with one or more information security regulations and/or frameworks such as HIPAA, ISO 27001/2, FISMA, FIPS, HITRUST, and NIST security.
• Experience with GRC platforms (e.g., ServiceNow GRC, RSA Archer, OneTrust, or similar) that support risk and compliance initiatives.
• Proven ability to utilize tools to enhance process efficiency, facilitate reporting, and support scalable risk management approaches.
• Health insurance
• Professional development opportunities
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.