IT Security Risk Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
The IT Security Risk Manager is a key member of the Enterprise Risk Management team within the Tarrant County Hospital District’s Office of Legal Affairs. Reporting to the Deputy General Counsel, this role is responsible for leading the identification, assessment, monitoring, and mitigation of information technology and security risks across the health system. The IT Security Risk Manager plays a critical role in ensuring that information systems are appropriately protected and aligned with applicable regulatory requirements, industry standards, and internal policies. Essential Job Functions & Accountabilities
- Conducts risk assessments and reviews of the IT control framework to identify control gaps and risk exposures.
- Partners with IT, cybersecurity, infrastructure, and business leaders to assess and reduce technology and security risk.
- Provides risk guidance and recommendations for new initiatives, technologies, system implementations, and significant system changes.
- Facilitates IT security risk workshops, training sessions, and awareness programs for employees and stakeholders.
- Assists with cybersecurity incident investigations, including root cause analysis and remediation tracking.
- Participates in business continuity and disaster recovery planning, testing, and evaluation activities.
- Recommends and evaluates controls to enhance system resilience and minimize operational and security impact.
- Identifies and supports the implementation of practical and cost-effective solutions to IT security and risk issues.
- Provides aggregated risk oversight and supervision for high-impact IT service areas.
- Develops, analyzes, and presents reports on key IT risk metrics, assessments, and activities to management and stakeholders.
- Builds and maintains effective working relationships with risk team members, Enterprise Risk Management, Legal, IT, Compliance, and other key partners.
- Provides guidance in the development, implementation, and communication of IT risk-related policies, standards, and procedures.
- Establishes and maintains an external professional network with IT risk peers, industry groups, and applicable risk forums.
- Coordinates and works collaboratively with internal and external auditors, as requested.
- Evaluates alternative strategies to reduce the organization’s exposure to catastrophic and operational loss.
- Participates in end-to-end risk remediation planning, execution, monitoring, and closure activities.
- Supports Office of Legal Affairs projects and strategic initiatives related to IT risk and security.
- Job description is not an all-inclusive list of duties and may be subject to change with or without notice. Staff are expected to perform other duties as assigned., * Work is indoors and sedentary and is subject to schedule changes and/or variable work hours.
- There are no harmful environmental conditions present for this job.
- The noise level in this work environment is usually moderate.
- Hybrid or in-office work environment.
- Requires extended use of computers and collaboration tools.
- May involve participation in after-hours incident support or risk reviews.
Requirements
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or related field of study from accredited college or university.
- 5+ years of experience in IT risk management, cybersecurity, IT audit, or IT governance; to include experience with IT risk frameworks, cloud platforms, and conducting vendor risk assessments and third-party reviews.
Preferred Qualifications
- Master’s Degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or related field of study from accredited college or university.
- Experience in IT cloud environments and incident response.
- Experience managing enterprise-wide risk programs.
- Experience working in IT or Risk Management in the healthcare sector, and supporting regulatory, audit, or compliance programs.
- Certified in one of the following:
- CRISC (Certified in Risk and Information Systems Control)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CEH
- CompTIA Security+
- Other cybersecurity certifications
Knowledge, Skills & Abilities
- Knowledge of risk assessment methodologies and risk scoring models.
- Knowledge of regulatory requirements (SOX, GDPR, HIPAA, PCI-DSS, GLBA).
- Knowledge of IT systems, networks, applications, and cybersecurity controls.
- Knowledge of emerging technologies and evolving cybersecurity threats.
- Knowledge of Microsoft Office Suite, including Word, Excel, Outlook, and PowerPoint.
- Skilled in developing risk mitigation strategies and control recommendations.
- Skilled in analyzing and solving complex problems related to IT risk and security.
- Skilled in effective verbal and written communication with executives, stakeholders, and diverse audiences.
- Skilled in building and maintaining professional relationships across all levels of the organization.
- Skilled in facilitating cross-functional discussions and influencing risk mitigation outcomes.
- Skilled in organizing and managing multiple projects and priorities.
- Ability to identify, assess, and prioritize IT risks across the organization.
- Ability to interpret security logs, technical documentation, and audit reports.
- Ability to collaborate effectively with both technical and non-technical stakeholders.
- Ability to work effectively under pressure in a fast-paced environment.
- Ability to maintain a high level of integrity, professionalism, and confidentiality when handling sensitive information.
- Ability to support business continuity and disaster recovery planning.
- Ability to work independently while contributing to a team environment.
- Ability to demonstrate initiative, sound judgment, and attention to detail in risk documentation.
Physical Requirements
- Visual acuity to read information from computer screens, forms, and other printed materials and information.
- Able to speak (enunciate) clearly in conversation and general communication.
- Hearing ability for verbal communication/conversation/responses via telephone, telephone systems, and face-to-face interactions.
- Manual dexterity for typing, writing, standing and reaching, flexibility, body movement for bending, crouching, walking, kneeling and prolonged sitting.
- Lifting and moving objects and equipment up to 25 lbs.
- Able to meet physical demands of the job with assistive or adaptive devices or reasonable accommodations.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
IT Salaries in UK
Best Paying Jobs in Technology
From developer to manager – what does it take to become an engineering manager?