HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining ...
Experience working with information and cyber security risk management frameworks and threat management frameworks (e.g. ISO27001, NIST CSF, MITRE Telecommunication&CK). * Relevant certifications ...
Experience working with information and cyber security risk management frameworks and threat management frameworks (e.g. ISO27001, NIST CSF, MITRE Telecommunication&CK). * Relevant certifications ...
Senior Cybersecurity Consultant
Nashville, TN · On-site +1
$100K - $120K/yr
Experience with risk quantification methodologies such as FAIR and enterprise risk management ... Advanced knowledge of modern cybersecurity technologies including SIEM, SOAR, EDR/XDR, CASB, PAM ...
Senior Cybersecurity Consultant
Nashville, TN · On-site +1
$100K - $120K/yr
Experience with risk quantification methodologies such as FAIR and enterprise risk management ... Advanced knowledge of modern cybersecurity technologies including SIEM, SOAR, EDR/XDR, CASB, PAM ...
Senior Cybersecurity Consultant
Nashville, TN · On-site
$100K - $120K/yr
Experience with risk quantification methodologies such as FAIR and enterprise risk management ... Advanced knowledge of modern cybersecurity technologies including SIEM, SOAR, EDR/XDR, CASB, PAM ...
Senior Cybersecurity Consultant
Nashville, TN · On-site
$100K - $120K/yr
Experience with risk quantification methodologies such as FAIR and enterprise risk management ... Advanced knowledge of modern cybersecurity technologies including SIEM, SOAR, EDR/XDR, CASB, PAM ...
R&I Cybersecurity & AI Risk Senior Manager
Nashville, TN · On-site
$91K - $321.50K/yr
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks ... Responsibilities - Provide specialized support in cybersecurity, privacy, data, and AI risk ...
R&I Cybersecurity & AI Risk Senior Manager
Nashville, TN · On-site
$91K - $321.50K/yr
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks ... Responsibilities - Provide specialized support in cybersecurity, privacy, data, and AI risk ...
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degree preferred. Relevant certifications preferred (e.g., CISM, CRISC, CISSP, CISA) REQUIRED ...
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degree preferred. Relevant certifications preferred (e.g., CISM, CRISC, CISSP, CISA) REQUIRED ...
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degree preferred. Relevant certifications preferred (e.g., CISM, CRISC, CISSP, CISA) REQUIRED ...
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degree preferred. Relevant certifications preferred (e.g., CISM, CRISC, CISSP, CISA) REQUIRED ...
Manager of Cyber Security
$105.90K - $143.20K/yr
Risk Management: Oversee the assessment and management of cybersecurity risks associated with third-party vendors, partners, and bio-medical devices. Policy Development & Enforcement * Policy ...
Quick apply
Manager of Cyber Security
$105.90K - $143.20K/yr
Risk Management: Oversee the assessment and management of cybersecurity risks associated with third-party vendors, partners, and bio-medical devices. Policy Development & Enforcement * Policy ...
Cybersecurity Administrator
Nashville, TN · On-site +1
$58.74K - $73.42K/yr
All employees are expected to protect the information and assets of the organization through heightened awareness of information security, cybersecurity, and risk management best practices, as well ...
Cybersecurity Administrator
Nashville, TN · On-site +1
$58.74K - $73.42K/yr
All employees are expected to protect the information and assets of the organization through heightened awareness of information security, cybersecurity, and risk management best practices, as well ...
Cybersecurity Administrator
Nashville, TN · Hybrid
$58.74K - $73.42K/yr
All employees are expected to protect the information and assets of the organization through heightened awareness of information security, cybersecurity, and risk management best practices, as well ...
Quick apply
Cybersecurity Administrator
Nashville, TN · Hybrid
$58.74K - $73.42K/yr
All employees are expected to protect the information and assets of the organization through heightened awareness of information security, cybersecurity, and risk management best practices, as well ...
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degree preferred. Relevant certifications preferred (e.g., CISM, CRISC, CISSP, CISA) REQUIRED ...
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field. Advanced degree preferred. Relevant certifications preferred (e.g., CISM, CRISC, CISSP, CISA) REQUIRED ...
... Risk Management Framework (RMF) Subject Matter Expert (SME) to support our clients. The RMF SME ... Requirements: * Bachelor's degree in Cybersecurity, Information Systems, or related field (or ...
... Risk Management Framework (RMF) Subject Matter Expert (SME) to support our clients. The RMF SME ... Requirements: * Bachelor's degree in Cybersecurity, Information Systems, or related field (or ...
Cyber Security Manager (Customer Identity and Access Management)
Nashville, TN · On-site
$107.20K - $144.90K/yr
... risk management, compliance, and cyber security, effectively mitigating risk to levels within the company's risk appetite • Ensures disciplined change management by evaluating risk and control ...
Cyber Security Manager (Customer Identity and Access Management)
Nashville, TN · On-site
$107.20K - $144.90K/yr
... risk management, compliance, and cyber security, effectively mitigating risk to levels within the company's risk appetite • Ensures disciplined change management by evaluating risk and control ...
Cybersecurity Lead
Oak Ridge, TN · On-site
$96.30K - $130.10K/yr
NIST 800-53 Rev 5, Risk Management Framework, NIST Cybersecurity Framework (CSF), FedRAMP ... Authorization, Tenable Nessus (ACAS), and DISA STIGs. Desired Skills * Strategic thinker with ...
Cybersecurity Lead
Oak Ridge, TN · On-site
$96.30K - $130.10K/yr
NIST 800-53 Rev 5, Risk Management Framework, NIST Cybersecurity Framework (CSF), FedRAMP ... Authorization, Tenable Nessus (ACAS), and DISA STIGs. Desired Skills * Strategic thinker with ...
Cyber Security Engineer
Nashville, TN · On-site
The Cyber Security Engineer supports services for cloud applications and infrastructure security, utilizing extensive experience to lead complex projects and ensure compliance with risk management ...
Cyber Security Engineer
Nashville, TN · On-site
The Cyber Security Engineer supports services for cloud applications and infrastructure security, utilizing extensive experience to lead complex projects and ensure compliance with risk management ...
Security Compliance Advisor I (SOC 2, ISO 27001)
Nashville, TN · Remote
$65K - $70K/yr
Foundational cybersecurity risk management concepts and tech documentation Preferred Technical Skills * Experience with vulnerability scanning tools and exposure to penetration testing concepts
Quick apply
Security Compliance Advisor I (SOC 2, ISO 27001)
Nashville, TN · Remote
$65K - $70K/yr
Foundational cybersecurity risk management concepts and tech documentation Preferred Technical Skills * Experience with vulnerability scanning tools and exposure to penetration testing concepts
Senior Cybersecurity and IT Policy SME
Knoxville, TN · On-site
$95.40K - $123.10K/yr
Experience advising senior leadership on cybersecurity strategy, policy, and risk management. * Strong analytical and problem-solving skills with the ability to assess complex environments and ...
Quick apply
Senior Cybersecurity and IT Policy SME
Knoxville, TN · On-site
$95.40K - $123.10K/yr
Experience advising senior leadership on cybersecurity strategy, policy, and risk management. * Strong analytical and problem-solving skills with the ability to assess complex environments and ...
Cybersecurity Risk Management information
See Tennessee salary details
$51.7K - $62.4K
1% of jobs
$62.4K - $73K
4% of jobs
$73K - $83.7K
5% of jobs
$83.7K - $94.3K
9% of jobs
$100.2K is the 25th percentile. Wages below this are outliers.
$94.3K - $105K
11% of jobs
$105K - $115.6K
10% of jobs
The median wage is $119.7K / yr.
$115.6K - $126.2K
28% of jobs
$132.4K is the 75th percentile. Wages above this are outliers.
$126.2K - $136.9K
14% of jobs
$136.9K - $147.5K
11% of jobs
$147.5K - $158.2K
4% of jobs
$158.2K - $168.8K
4% of jobs
$51.7K
$120.7K
$168.8K
How much do cybersecurity risk management jobs pay per year?
What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?
What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?
What is cybersecurity risk management?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
Other
Medical, Dental, Vision, Life, Retirement, PTO
Posted 13 days ago
HCA Healthcare rating
6.4
Based on 2,173 frontline employees who took The Breakroom Quiz
628th of 864 rated healthcare providers
Job description
This position is incentive eligible.
Introduction
Do you want to join an organization that invests in you as a Director of Information Protection Security and Risk? At HCA, you come first. HCA Healthcare has committed up to $300 million in programs to support our incredible team members over the course of three years.
Benefits
At HCA, we want to ensure your needs are met. We offer eligible colleagues an attractive benefit package that includes medical, wellbeing, dental and vision benefits along with some unique benefits including:
- Medical, Dental, Vision, Life Insurance and Flexible Spending
- Paid Time Off (PTO) and Personal Leave
- 401K (100% annual match - 3% to 9% of pay based on years of service)
- Academic Assistance and Reimbursements for Tuition and Student Loans
- Employee Discounts including Tickets, Retail, Mental Health Apps, Education Apps, Identity Theft Protection etc.
- Home, Auto, and Pet Insurance
- Employee Stock Purchase Program (ESPP)
- Short Term & Long Term Disability coverage
- Adoption Assistance
- Legal Benefits and lots more!
Learn more about Employee Benefits
You contribute to our success. Every role has an impact on our patients’ lives and you have the opportunity to make a difference. We are looking for a dedicated Director of Information Protection Security and Risk like you to be a part of our team.
Job Summary and Qualifications
The Director of Information Protection & Security (IPS) Risk Management leads the risk management function for IPS. In this critical leadership position, you will be responsible for developing and overseeing our organization's comprehensive cybersecurity risk management program. This role will be responsible for developing and implementing a robust cybersecurity risk management strategy aligned with industry best practices and evolving threats. To be successful in this role, the Director of Risk Management must be able to clearly communicate cyber risks to all levels of the organization.
This leader will be key in implementing a risk management program that results in the identification, prioritization, and reduction of cybersecurity and ensures compliance for all in-scope facilities. This trusted advisor will help raise the protection bar by building strong relationships with technical and non-technical stakeholders to make risk visible, facilitate well-informed decision, and drive accountability. The ability to clearly communicate and report cybersecurity risk, and manage organizational relationships, will be key to the success of this role. In addition, this role must be able to establish a outcome-driven metrics approach to risk management and utilize protection level agreements as a mechanism to establish risk thresholds.
This position is expected to promote a culture that supports operating with an acceptable level of risk, developing standardized risk management criteria including but not limited to threats, vulnerabilities, likelihood, impact, and maturity, establishing risk tolerance, planning risk analysis (e.g. Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk management program are documented. It will also ensure a strategy for using and maintaining the risk register to prioritize risk reduction actions and activities is implemented. This position is also responsible for evolving the organization’s current risk treatment framework. This position is also responsible for collaborating with Information Security on the development, configuration, and implementation of the Risk Management Archer GRC application.
This position requires a candidate who can, with minimal guidance, analyze business requirements and processes, understand colleague behaviors, facilitate and lead meetings with key stakeholders within the organization, provide industry expertise and knowledge in the identification and mitigation of organizational risk, and enable decision making to support the adherence to industry standards and federal regulations.
The Director of IPS Risk Management provides guidance, direction, and mentorship to staff members to support the overall team goals and deliverables. A qualified candidate must be a highly motivated self-starter and be committed to delivering quality outcomes that meet team and organizational goals.
What you will do in this role:
Quality
- Work as part of the IPS department’s leadership team to develop company requirements, strategies, priorities, processes, implementation plans, and assurance necessary to protect the company against information protection and security risks that could impact patients, employees, and the financial success of the business
- Remain knowledgeable of legislative, regulatory, contractual, and other compliance requirements (e.g. HIPAA, PCI, SOX, Joint Commission) as well as departmental policies, standards, and procedures and participating in revision processes
- Develop and lead the strategy to mature the risk management roadmap, create new roadmaps where needed, and ensure all roadmaps align with business objectives for the key focus areas
- Provide periodic analysis of Company IPS-related risk position, based on analysis of current controls status and current threat landscapes
- Monitor developments in related industries and communicate on the potential impact on or applicability to the organization
- Ensure metrics are identified within risk management and remediation strategy that help demonstrate risk reduction and report progress to IPS leadership and company executive leadership
- Develop risk register and be aware of associated remediation plans to respond to previously unidentified or inadequately addressed risk areas
- Build rapport, credibility, and cohesion across IPS and other stakeholders across the enterprise
- Partner with Internal Audit and IPS Leadership to ensure periodic reviews of the risk management program are performed to obtain independent assessments of the program’s effectiveness
- Partner with key stakeholders (e.g. Security Architects, DISAs) within IPS as well as with Internal Audit, Enterprise Risk Management, Legal, and ITG to ensure appropriate oversight and governance of the program
- Ensure the team is involving all relevant stakeholders in major decisions; recognizing multiple agendas and making/communicating final decisions in ways that foster maximum ownership and minimum resistance
Service
- Lead the team in providing risk-based security perspective through consulting and collaboration
- Lead the team in facilitating and guiding business decisions and solutions
People
- Accountable for the successful completion of organizational objectives through team members
- Establish mutual objectives and targets for team members
- Mentor team members, including developing and monitoring their personal development plans, and provide feedback via the annual performance review process
- Promote a culture of collaboration, work/life balance, and open communication
- Encourage new ways of thinking and problem solving
- Create a team environment where members embrace change and adopt new practices
- Stay engaged with team members through 1:1s, rounding, and performance review activities
Growth
- Monitor developments in related industries and communicate on the potential impact on or applicability to the organization
- Build rapport, credibility, and cohesion within IPS and with other stakeholders across the enterprise
- Participate in educational opportunities to build and maintain team knowledge of evolving risk, information security, and privacy concepts
Finance
- Responsible for ensuring proposed future work efforts/projects are appropriately captured with labor and spend estimates and submitted for leadership prioritization and funding
What qualifications you will need:
- Bachelor’s degree required
- Master’s degree preferred
- 3+ year(s) of leadership experience
- 7+ years of experience in information technology, information security, privacy, and/or healthcare
- CISSP preferred
- CISA preferred
- CRISC preferred
HCA Healthcare has been recognized as one of the World’s Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"Good people beget good people."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
What HCA Healthcare employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom