Job Search

One Mission. More Than Half a Million Reasons.
As we empower every New Yorker
to live the healthiest life possible.

IT Security Risk Manager

Job Ref: 90220
Category: Information Technology
Location: 50 Water Street, 7th Floor, New York, NY 10004
Job Type: Regular
Employment Type: Full-Time
Hire In Rate: $130,000.00
Salary Range: $130,000.00 - $145,000.00

Empower. Unite. Care.

MetroPlusHealth is committed to empowering New Yorkers by uniting communities through care. We believe that Health care is a right, not a privilege. If you have compassion and a collaborative spirit, work with us. You can come to work being proud of what you do every day.

About NYC Health + Hospitals

MetroPlusHealth provides the highest quality healthcare services to residents of Bronx, Brooklyn, Manhattan, Queens and Staten Island through a comprehensive list of products, including, but not limited to, New York State Medicaid Managed Care, Medicare, Child Health Plus, Exchange, Partnership in Care, MetroPlus Gold, Essential Plan, etc. As a wholly-owned subsidiary of NYC Health + Hospitals, the largest public health system in the United States, MetroPlusHealth's network includes over 27,000 primary care providers, specialists and participating clinics. For more than 30 years, MetroPlusHealth has been committed to building strong relationships with its members and providers to enable New Yorkers to live their healthiest life.

Position Overview 

Collaborates with IT Security management in the development of enterprise Security assessment tools and policy and procedures. Assesses information risk and facilitates remediation of identified vulnerabilities with the organization, systems and applications and vendors. Reports on findings and recommendations for corrective action.

Job Description

  • Collaborates with IT Security management in the development of enterprise Security assessment tools and policy and procedures. 
  • Performs vulnerability assessments as assigned utilizing I.T. Security tools and methodologies.  Summarizes risk posture across the organization or within specific business units.
  • Identifies opportunities to reduce organizational risk, detects and remediates vulnerabilities and ensures compliance and audit readiness.
  • Makes recommendations for corrective action and documents management decisions regarding acceptance or mitigation of risk scenarios.
  • Facilitates and monitors performance and compliance of risk remediation tasks.  Reports on findings.
  • Liaises with organization partners and vendors regarding the security maintenance of their systems and applications.
  • Creates and presents changes related to risk mitigation to Change Authorization Board (CAB), as needed.
  • Provides weekly status on projects, including outstanding issues and progression.
  • Participates in the development of ‘security awareness’ education and training, as necessary.
  • Performs related duties, as required.

Minimum Qualifications

  • Bachelor’s Degree in Information Security, Audit or related field, and five (5) years progressively responsible information security assessment or audit experience, required or High School Diploma or equivalent, and eight (8) years progressively responsible information technology risk management experience, required.
  • Thorough knowledge and understanding of current information risk assessment techniques is required for this position.
  • Familiarity with Federal and State compliance regulations including HIPPA, PCI-DSS and NYSDFS, required.
  • Strong interpersonal and communication skills
  • Experience in a healthcare environment, preferred.
  • Certified in at least one (1) of the following preferred: 
    • Certified in Risk and Information Systems Control (CRISC); Highly desirable/preferred 
    • Certified Information Systems Security Professional (CISSP) Preferred 
    • Certified Information Systems Auditor (CISA), Security+, Global Information Assurance Certification (GIAC) or related certification preferred 

Professional Competencies

  • Integrity and Trust
  • Customer Focus
  • Functional/Technical skills
  • Written/Oral Communication