REQUIRED EDUCATION** Bachelor's Degree - Information Security, Information Systems, Information Assurance, Computer Science or related field **_Substitutions_** At least 10 years' experience in Information Security, Governance, Risk and/or Compliance **PREFERRED EDUCATION** Master's Degree - Computer Science, Information Security or related field **EXPERIENCE** **_Minimum:_** + 7 - 10 years' experience in Information Security and/or Information Risk Management and/or Information Technology + 5 - 7 years' experience within Information Security Governance, Risk and/or Compliance functions and activities + 7 - 10 years' experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences + Familiarity with technologies such as intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms **_Preferred:_** + 10 - 15 years' experience in Information Security and/or Information Risk Management and/or Information Technology + Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework + Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits + IT / Information security risk advisory experience + Governance Risk and Compliance (GRC) tool experience such as ARCHER + In-depth understanding of network security architecture, network and networking protocols + Security industry organization participation / leadership (HITRUST, ISACA, InfraGard, ISC2, ISSA, etc.) **KNOWLEDGE, SKILLS & ABILITIES** + Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 + Knowledge of NIST Risk Assessment methodology + Familiarity with secure SDLC best practices + Ability to work within high performance, multi-discipline teams + Strong teamwork and inter-personal skills + Familiarity with AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) and how they map to enterprise risk management and existing frameworks (NIST CSF, 800-53) + Awareness of secure AI adoption practices, including model lifecycle security, data privacy, and third-party AI/vendor risk considerations + Understanding of automation opportunities in cyber risk management, including AI-assisted risk analysis, control validation, and metric generation **REQUIRED LICENSURE** None **PREFERRED LICENSURE** Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Information Systems Auditor (CISA), Global Information Assurance Certification Security Essentials Certification (GSEC), SANS or similar industry certifications **TRAVEL REQUIREMENT:** 0% - 25% **PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS** ( _The physical, mental demands and working conditions described here are representative of those that must be met by an employee to successfully perform the essential function of their job. Reasonable accommodations will be made when necessary to enable individuals with disabilities to perform the essential duties of the position, to the extent that they do not cause undue hardship._ **_Position Type:_** Remote Lifting: up to 10 pounds Does Not Apply Lifting: 10 to 25 pounds Does Not Apply Lifting: 25 to 50 pounds Does Not Apply **_Disclaimer:_** _The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title.