Sr IT Controls & Risk Specialist

Remote, USA Full-time
Job Summary Medline is looking for a Senior IT Controls & Risk Specialist to play a critical role in establishing and managing an IT controls framework for the enterprise. Reporting to the IT Controls & Risk Manager, this position will lead the design, development, and implementation of information and technology risk management policies, standards, processes, and best practices and drive adoption through effective enterprise change management, education and awareness. Additionally, the specialist will evaluate the compliance of new and existing technology solutions against applicable controls. Job Description MAJOR RESPONSIBILITIES Controls Framework Design, Implementation, and Management Control Framework Development: Analyze, design, create, and maintain a unified IT controls framework drawing from leading industry frameworks and applicable regulatory requirements (e.g. NIST CSF, CIS, HITRUST, PCI, etc.) Documentation: Create comprehensive documentation for the controls framework, including risks, control objectives, and implementation guidelines. Align with existing enterprise policies and develop policies to fill identified gaps. Stakeholder Engagement: Collaborate with cross-functional teams to ensure stakeholder buy-in and alignment with organizational risk tolerance. Technology Evaluation and Risk Management Compliance Evaluation: Assess new and existing technologies for compliance with applicable controls. Risk Register Management: Maintain a risk register to manage non-compliance and track remediation efforts. Tool Administration: Lead the configuration of GRC tools used for IT risk management processes. Awareness and Education Material Development: Develop tailored written and verbal awareness materials for different audiences, supporting user education initiatives. Drive communication campaigns to ensure employee adoption using metrics to measure and track success. Communication and Cross-Functional Collaboration Communication Planning: Execute a communication plan for impacted audiences when process and policy changes are made. Relationship Building: Build trusted relationships with IT Compliance, Information Security, Legal, and Corporate Compliance teams to ensure message alignment and cross-functional collaboration. MINIMUM JOB REQUIREMENTS Education Bachelor’s Degree in Information Technology, Information Security, Risk Management, Business Administration, or related field. Or equivalent combination of education, professional certifications, and relevant work experience. Certification / Licensure None required. Work Experience 3+ years professional experience within IT Controls and Frameworks, IT Risk Management, IT Internal Controls, or related GRC field. Knowledge / Skills / Abilities Experience developing or maintaining a controls-based IT compliance framework Experience evaluating or auditing web-based software technologies against company or regulatory requirements Experience deploying or supporting risk management, compliance, information security, information governance, or privacy programs across a large enterprise In-depth understanding of NIST CSF, CIS, NIST 800-53, HITRUST, CMMC, PCI DSS, or similar frameworks. Ability to describe framework scope, composition, and implementation strategies. Familiar with the technical components of software technologies, including APIs, web services, and common web and cloud application integration and architecture patterns Experience with modern GRC tools and other technologies supporting IT risk management activities Experience applying change management methodologies to support IT risk management initiatives Strong written and verbal skills, including a demonstrated ability to translate complex or technical information into concepts that are easily understood Proven ability to effectively interact with, manage, and influence cross-functional teams and partners PREFERRED JOB REQUIREMENTS 8+ years of professional experience in Technology Risk, Information Security, or leadership role in a technical area within a highly regulated industry. Certification / Licensure Certification in relevant GRC discipline (e.g., CISA, CISM, CRISC, CISSP, CGRC) or IT governance frameworks (e.g., ITIL). Knowledge / Skills / Abilities Experience implementing or using AuditBoard CrossComply, AuditBoard ITRM, or other TPRM, Privacy, or GRC tools Participation in IT compliance and audit processes Experience organizing process information and technical concepts into a knowledge base for wider audience consumption, leveraging diagrams or infographics and knowledge management tools Experience driving successful, insight-based, creative communications plans that deliver against program objectives, on time and within budget Experience deploying policy or technology changes across a large enterprise and measuring and reporting program process over time. Understanding of fundamental Information Governance concepts (e.g., records retention, data protection, data handling) Knowledge of enterprise change management methodologies Familiarity with SAP security model and its integration with GRC products Familiarity with M365 governance and compliance settings Medline Industries, LP, and its subsidiaries, offer a competitive total rewards package, continuing education & training, and tremendous potential with a growing worldwide organization. The anticipated salary range for this position: $96,200.00 - $144,560.00 Annual The actual salary will vary based on applicant’s location, education, experience, skills, and abilities. This role is bonus and/or incentive eligible. Medline will not pay less than the applicable minimum wage or salary threshold. Our benefit package includes health insurance, life and disability, 401(k) contributions, paid time off, etc., for employees working 30 or more hours per week on average. For a more comprehensive list of our benefits please click here. For roles where employees work less than 30 hours per week, benefits include 401(k) contributions as well as access to the Employee Assistance Program, Employee Resource Groups and the Employee Service Corp. We’re dedicated to creating a Medline where everyone feels they belong and can grow their career. We strive to do this by seeking diversity in all forms, acting inclusively, and ensuring that people have tools and resources to perform at their best. Explore our Belonging page here. Medline Industries, LP is an equal opportunity employer. Medline evaluates qualified individuals without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, neurodivergence, protected veteran status, marital or family status, caregiver responsibilities, genetic information, or any other characteristic protected by applicable federal, state, or local laws. Through our culture of belonging, our agile and resilient global team is determined to get our customers exactly what they need, at the right time, every time. If you’re a self-starter, eager to grow your career within a high-performing environment, this is the place for you. Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match. Medline is the largest provider of medical-surgical products and supply chain solutions serving all points of care. Through its broad product portfolio, resilient supply chain and leading clinical solutions, Medline helps healthcare providers improve their clinical, financial and operational outcomes. Headquartered in Northfield, Illinois, the company employs more than 43,000 people worldwide and operates in more than 100 countries and territories. To learn more about how Medline makes healthcare run better, visit www.medline.com. Apply tot his job
Apply Now

Similar Jobs

Senior Compliance Manager Sanctions Officer

Remote, USA Full-time

Snr Third Party Risk Management (TPRM) Consultant

Remote, USA Full-time

Senior Audit Manager- Quantitative Risk Modeling

Remote, USA Full-time

Risk Management Consultant

Remote, USA Full-time

Specialist, Risk Management P&C (Agribusiness)

Remote, USA Full-time

Senior Credit Risk Quantitative Expert (Hybrid)

Remote, USA Full-time

[Remote] GRC Specialist (Governance, Risk & Compliance)$90K/yr - $120Kyr

Remote, USA Full-time

RN | SR Education Specialist | Risk Management

Remote, USA Full-time

Quantitative Risk Management Consultant (W2, Hybrid New York)

Remote, USA Full-time

Program Risk Management Analyst

Remote, USA Full-time

Manager - Inventory and Cost Accountant

Remote, USA Full-time

Advertising Account Executive

Remote, USA Full-time

Experienced Remote Part-Time Data Entry Specialist – Flexible Scheduling and Professional Growth Opportunities at arenaflex

Remote, USA Full-time

Experienced Data Entry Clerk for Remote Part-Time Role at blithequark - Immediate Hiring

Remote, USA Full-time

No Experience Amazon [virtual Assistant] ? Imme...

Remote, USA Full-time

Immediate Hiring: JET Blue Airlines Customer Support - Fresher

Remote, USA Full-time

Engineer, MACD – Third Shift

Remote, USA Full-time

Lead Clinical and Population Health Analyst - Medical Policy

Remote, USA Full-time

Experienced Customer Service Representative – Live Chat Support Assistant for Remote Work Opportunities at blithequark

Remote, USA Full-time

Remote Customer Retention Specialist – Part-Time Evening Shift Opportunity at blithequark

Remote, USA Full-time
Back to Home