Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Integrated Risk Operations Analyst image - Rise Careers
Job details

Integrated Risk Operations Analyst

Company :

Highmark Health

Job Description : 

JOB SUMMARY

This job prepares and assists with communication of enterprise policies, standards, and procedures/controls according to applicable laws, regulations, and industry requirements supporting a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, NCQA, the BCBSA, etc.  The incumbent prepares and executes procedures associated with improving upon existing risk treatment activities including, but not limited to, enterprise policies, privacy operations, business resiliency and continuity planning, records and information management.  Assists management in the areas of scheduling, direction, institutionalization of standard practices, prioritization and execution of risk treatment activities.  Works with other areas of Risk Operations to synthesize risk intelligence, cross-functional risk assessment outputs.  Prepares and executes actionable risk treatment strategies.  Monitors and controls quality of risk treatment artifacts (e.g., business resiliency plans, recovery strategies, records taxonomy, policy and procedure inventory, privacy activities) while actively seeking opportunities for continuous process, technology, and reporting improvement.  Collaborates with various areas and Senior Risk Partners (SRPs) on risk treatment plans including, legal, government affairs, HR, finance, facilities, quality, privacy, security, safety, and IT.  Works in a team environment that promotes cooperation, accountability, customer focus and effective work relationships in order to attain business goals.  Prepares and assists with effectively communicating risk treatment progress, methodology, and risk decisioning options to SRPs and business leaders.  Demonstrates a proactive mindset, a positive working approach and feels comfortable working in a highly matrixed environment.  


ESSENTIAL RESPONSIBILITIES

  • Prepares and executes processes to maintain enterprise policies, standards, procedures/controls, including business continuity/disaster recovery plans, strategies, and facilitates related exercises/scenarios/drills.
  • Prepares and executes risk treatment plans and processes across disciplines (e.g., business resiliency, privacy, compliance, information security, quality, legal) according to strategic objectives.  Works within a highly matrixed environment.  
  • Prepares and executes communication strategies of treatment solutions to SRPs and business leaders.  Ensures work adheres to quality, compliance, policies, procedures, privacy requirements, standards, etc.  Consults with peers and superiors on a regular basis.
  • Prepares and executes monitoring programs intended to prevent, detect, and respond to risks, in partnership with business units, SRPs, and other stakeholders.
  • Prepares and executes enterprise-wide programs (e.g., code of conduct, conflict of interest, etc.).
  • Prepares and assists with providing feedback on risk treatment methodology in partnership with Risk Strategy (avoid, accept, transfer, mitigate).
  • Prepares and executes training and education programs in partnership with Enterprise Learning & Development.
  • Other duties as assigned or requested.


EDUCATION


Required

  • Bachelor's Degree in Accounting, Business, Computer Science, Finance, IT or related field. 


Substitutions

  • 6 years of related and progressive experience in lieu of Bachelor's degree


Preferred

  • None

EXPERIENCE


Required

  • 3 years in Governance, risk, and compliance experience including audit, policy, regulatory, business resiliency, or related disciplines
  • 1 year in Privacy operations, business resiliency, policy management and process improvement disciplines


Preferred

  • None


LICENSES or CERTIFICATIONS


Required

  • None

Preferred (any of the following)

  • Business Continuity Management Certification
  • Certified Information Governance Professional (CIGP)
  • Cybersecurity and Infrastructure Security Agency (CISA)
  • Certified Information Privacy Professional (CIPP)

SKILLS

  • Demonstrated knowledge of business continuation and crisis management
  • Demonstrated knowledge of policy and procedure governance and administration
  • Strong knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes
  • Strong knowledge of how to leverage technologies to drive efficient and effective GRC processes across payor/provider industries
  • Strong resource and project planning capabilities, decision making skills, history of results-oriented delivery, and effective team work across a global and diverse team of staff
  • Strong written and verbal communication skills for diverse audiences (senior management, board, peer, and team)
  • Relationship building skills and ability to influence with and without authority in a matrixed organization


Language (Other than English):

None

Travel Requirement:

0% - 25%

PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS

Position Type

Office-based

Teaches / trains others regularly

Occasionally

Travel regularly from the office to various work sites or from site-to-site

Rarely

Works primarily out-of-the office selling products/services (sales employees)

Never

Physical work site required

Yes

Lifting: up to 10 pounds

Constantly

Lifting: 10 to 25 pounds

Occasionally

Lifting: 25 to 50 pounds

Rarely

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.


As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times.  In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. 

Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.

We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.

For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org

California Consumer Privacy Act Employees, Contractors, and Applicants Notice

Average salary estimate

$82500 / YEARLY (est.)
min
max
$70000K
$95000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Posted 3 hours ago

Provide hands-on support and resource navigation as a Community Health Worker at Allegheny Health Network, helping patients overcome social and medical barriers to better health.

Photo of the Rise User
Highmark Health Hybrid Pittsburgh PA, 15212, 420 East North Ave
Posted 3 hours ago

Allegheny Health Network seeks an onsite Medical Scheduler to manage surgical and outpatient scheduling, obtain authorizations, and maintain accurate clinical and billing information for the Ophthalmic & Orbital practice in Pittsburgh.

Photo of the Rise User

Lead and strengthen YMCA of Greenville’s risk, safety, and compliance programs as the Safety & Risk Management Director, ensuring safe operations across aquatics, youth programs, facilities, and volunteers.

Photo of the Rise User
Imprint Hybrid San Francisco
Posted 39 minutes ago

Imprint is hiring a Product Counsel to advise on regulatory, privacy, and product issues for its sponsor-bank credit card platform and help build the company’s legal function.

Photo of the Rise User

Valiant Solutions is hiring a Senior Policy, Compliance, and Training Lead to drive RMF/NIST compliance, Section 508 accessibility, and enterprise security awareness for federal-focused IT programs.

Ibility Hybrid Gaithersburg
Posted 1 hour ago

Experienced grants auditor needed to perform field-based audits and internal control reviews supporting VA grants programs and ensuring compliance with federal regulations.

Photo of the Rise User
Posted 58 minutes ago

Experienced NY State–admitted attorney needed to advise NYCHA on Section 8 programs, regulatory compliance, policy development, and related legal matters.

Experienced bilingual (English/Spanish) litigation paralegal needed to provide full trial support and case management at a busy Miami Lakes personal injury firm.

Photo of the Rise User
KIND Hybrid New York City, NY
Posted 5 hours ago

KIND is hiring a Senior Paralegal to supervise paralegal staff and manage detained-child immigration casework, combining hands-on legal preparation, client contact, and programmatic oversight in New York City.

Photo of the Rise User
NBCUniversal Hybrid 229 W 43rd St, New York, NY 10036, USA
Posted 2 hours ago

Lead enterprise insurance strategy and risk transfer activities for NBCUniversal/Versant as Senior Director, Risk Management, protecting company assets across global media operations.

Photo of the Rise User
GBG Hybrid No location specified
Posted 18 hours ago

Lead GBG's US legal and regulatory strategy as Head of Legal, US, overseeing contracting, compliance, and cross-functional legal support to enable commercial expansion while mitigating risk.

Photo of the Rise User
AECOM Hybrid Sacramento, California, United States
Posted 1 hour ago

AECOM is hiring an Environmental Compliance Auditor to conduct construction-area audits, verify permit and regulatory conformance, and coordinate corrective actions for large infrastructure programs.

Photo of the Rise User
Posted 2 hours ago

Aledade is hiring a Director of Security, GRC to lead and scale enterprise governance, risk, and compliance programs and drive audit readiness and certifications across SOC 2, HIPAA, SOX/ITGC, HITRUST and CPRA.

Photo of the Rise User
Posted 6 hours ago

Lead KIND’s Atlanta legal program as Managing Attorney—supervising staff, providing direct representation and pro bono mentorship, and overseeing program and data management to serve unaccompanied children.

Photo of the Rise User
Posted 20 hours ago

Lead Ohalo’s international regulatory operations to secure timely seed and plant variety approvals and enable rapid, compliant market entry across multiple global jurisdictions.

To create a remarkable health experience, freeing people to be their best.

53 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, onsite
DATE POSTED
September 17, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!