Job Description
Responsibilities include:
-Conduct comprehensive risk assessments across applications, systems, and enterprise-wide initiatives to identify potential threats, vulnerabilities, and their impact on confidentiality, integrity, and availability of data.
-Lead or support the execution of HIPAA Security Risk Assessments (SRA) and/or HICP assessments, including documenting findings, recommending corrective actions, and ensuring ongoing compliance.
-Independently conduct risk rating for issues using ISO, COBIT, NIST frameworks in partnership with other stakeholders. Additionally, guide and facilitate diverse business units in performing their own risk ratings to help them understand risk implications and remediation priorities.
-Collaborate with the stakeholders in developing and implementing risk mitigation strategies aligned with industry standards and best practices such as NIST, ISO 27001, and HIPAA.
-Utilize Governance, Risk, and Compliance (GRC) tools—specifically ServiceNow—to manage risk registers, track remediation plans, automate workflows, and generate reports on risk status and compliance metrics.
-Manage and oversee policy exception processes, including documentation, risk analysis, and tracking.
-Pay rate between $40-60/hr
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
-At least 4+ years of experience in cybersecurity risk management, including performing risk assessments at both application and enterprise levels.
-Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field—or equivalent industry training and certifications.
-Hands-on experience with GRC platforms, particularly ServiceNow, including modules related to risk, compliance, and policy management.
-Demonstrated expertise in conducting risk assessments and developing mitigation strategies aligned with HIPAA, NIST, and ISO 27001.
-Experience with HIPAA Security Risk Assessments and/or HICP assessments.
-Proven ability to work independently, manage multiple projects, and collaborate with cross-functional teams.
-Experience managing policy exceptions, including evaluating risks and ensuring proper documentation and approvals.
-Skilled in drafting procedures and operational documentation related to cybersecurity risk and compliance processes.
-Strong understanding of security principles, technical controls, and common attack vectors.
-Excellent communication, interpersonal, and presentation skills with the ability to effectively engage technical and non-technical stakeholders across all levels.
-Strong analytical, problem-solving, and critical thinking abilities.
-MUST BE located in Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Washington (state), West Virginia, Wisconsin, Wyoming, North Carolina, or Virginia
Nice to Have Skills & Experience
- A solid understanding of regulations such as HIPAA—including experience with HIPAA Security Assessments or Health Industry Cybersecurity Practices (HICP) assessments—is preferred.
-Relevant industry certifications such as CRISC, CISM, CISSP, or CISA.
-Experience working in a regulated industry, particularly healthcare.
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.