Jobs › Pennsylvania › Pittsburgh PA › Risk Partner
Risk Partner
Highmark Health is hiring for the role of Risk Partner, Pittsburgh PA, Penn Avenue Place (On-site). This is a Risk role in the governance, risk, and compliance field. Review the full details below and apply directly with Highmark Health.
Company :
Highmark Health Job Description :
JOB SUMMARY
This job is responsible for implementing, executing and maintaining the Compliance Program and its related policies to ensure the businesses act within the parameters of federal and state laws, regulations, and regulatory guidance. The incumbent is also responsible for the administration, interpretation, and enforcement of the Compliance Program including auditing/monitoring operational processes, conducting or overseeing compliance investigations, and ensuring that adequate training takes place under the Compliance Program. In this capacity, the individual is responsible for the collaborative and iterative execution of the risk and compliance plan for these entities across all areas in the enterprise risk taxonomy. Through matrixed leadership with Risk Operations and with support from Risk Enablement, the incumbent monitors and tracks the delivery of risk activities, including but not limited to, internal and external audit progress, recurring risk and compliance reporting, mandated training, investigations, and the impacts of new and changing laws, regulations, and contractual relationships. The incumbent must have extensive knowledge of the applicable federal and state rules as well as a solid working knowledge of managed care operations, compliance program structures, information security and audit methodologies. The incumbent must also have a foundational understanding of privacy regulations, including in-depth knowledge of HIPAA and possess the ability to perform a privacy risk assessment. The incumbent must have the highest level of integrity and ethics and demonstrate professional representation of the company.
ESSENTIAL RESPONSIBILITIES
Provides thought leadership and acts as an advisor to business leaders to ensure business decisions are made in alignment with the enterprise risk strategy / framework. Participates in and understands the business operations and strategy. Serves as a single point of contact for the business’ risks, compliance, privacy and security needs, and partners closely with legal counsel on all efforts.
Works with Risk Operations and the Strategic Risk Partner to implement and maintain an effective compliance and risk management program for the supported entities. This includes, but is not limited to education and training requirements, reporting and intake protocols, monitoring and implementation of new or changing regulatory requirements, risk assessment and audit execution, risk treatment plans, policy and procedure maintenance, response and investigation procedures and compliance expectations.
Provide proactive guidance, education, and information to senior management, so that business leaders remain informed and aware of risks, requirements, mitigation strategies, and management’s responsibilities. Participates in discussions or presentations to existing Compliance or Risk Committees. Gathers data and prepares reports for senior management and Board of Directors as needed. Ensure reporting obligations are met. Participates on various risk committees and may represent their entity when appropriate.
Informs business entity of risk related activity, ensures awareness and monitors execution. Tracks, monitors and reports on Risk Operations activities for the assigned business entity using the standard metrics and reporting created by Risk Enablement.
Proactively identifies and addresses risk in partnership with Risk Operations, Legal, and business entity leaders by thoroughly understanding strategy and functional operation of the business entity. Serves as a single point of contact to respond and intake risk from the senior leadership team, and follows protocol to triage.
Respond to reports of potential or real instances of non-compliance including recommendations for resolution, risk treatment and corrective action plans. Work with legal counsel and Internal Investigations Unit to ensure timely notice or disclosure of incidents or issues as appropriate/required. Ensure all reported matters are addressed in a timely and responsible manner in compliance with corporate policy, state and federal law and best practices.
Liaise with external regulators or enforcement bodies interacting with the assigned business entity per defined communication and legal protocols. Serve as the single point of contact for regulators.
Ensure completion of all education and training initiatives and requirements and identify priorities for focus for the accountable entities.
Participate in the implementation of the enterprise’s risk strategy for effective risk and compliance program governance; intended to strategically and proactively mitigate risk, and promptly detect and correct instances of non-compliance. This includes but is not limited to formal risk assessment processes and the implementation of an annual audit plan.
Maintain a strong working knowledge of the regulatory, security, and privacy landscape.
Other duties as assigned or requested.
EDUCATION
Required
Bachelor's Degree in Business, Finance, Health Administration, Public Health, Public Administration, Legal, Accounting or related field, or relevant experience and/or education as determined by the company in lieu of bachelor's degree
Preferred
Master's Degree in Business, Finance, Health Administration, Public Health, Public Administration, Legal, Accounting or related field
Location and market context
This role is based in Pittsburgh PA on-site. Local candidates benefit from being close to Highmark Health's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management roles
Risk roles own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Roles like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management role
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Highmark Health would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Risk Program Manager · WVU Medicine · St. Joseph's Hospital STJ
- Senior Model Risk Manager · Western Alliance Bank · Phoenix, AZ
- Information Security Risk, Risk Management Advisor · Fannie Mae · Plano, TX
- Technical Manager, Cyber Risk Management · Carnegie Mellon University (SEI) · Pittsburgh, PA
- Director of Governance, Risk, and Compliance · EliseAI · New York, NY
- Senior Cybersecurity Risk Analyst - USA Remote · Danaher · 12 Locations
- German-Speaking Third Party Risk Management Specialist (m/f) · PwC · Bratislava
- Vice President, Enterprise Risk Management · The Mutual Group · Iowa - TMG Home
Want to be next in a role like this?
Roles like Risk Partner in Pittsburgh PA, Penn Avenue Place open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.