Jobs and Careers
TR

Manager, Information Security Risk and Consulting (REMOTE)

Trinity Health
United StatesRemotefull_timeVerifiedPosted 17 Jul 2026

About the role

Employment Type:

Full time

Shift:

Description:

The Manager, Information Security Risk and Consulting, operating under the direction of the Director of Information Security Strategy and Planning, plays a critical role in executing and maturing the organization’s third-party and integrated risk management program. This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open source, and internally developed applications, as well as associated system integrations. The role is responsible for identifying, assessing, and prioritizing security risks, ensuring appropriate controls are implemented, and driving continuous monitoring and risk-informed decision-making across the organization.
This position leads the development and reporting of key risk indicators (KRIs) and key performance indicators (KPIs) to provide actionable insights to leadership and support effective governance. Additionally, the role oversees the design and execution of scalable risk management processes, leveraging GRC tools and automation to enhance efficiency and consistency.
As a people leader, the Manager builds, develops, and leads a highly engaged, high-performing team of security risk professionals, fostering a culture of accountability, collaboration, and continuous improvement within a complex and evolving security environment.

Essential Functions 

Our Trinity Health Culture: Knows, understands, incorporates & demonstrates our Trinity Health Mission, Values, Vision, Actions & Promise in behaviors, practices & decisions.
 

Program and Regulatory Compliance

  • Develops and leads Trinity Health’s Information Security Third Party Risk and Integrated Risk Management Program, with direct responsibility for defining team goals, scope of work, and deliverables aligned to Enterprise Information Security (EIS) priorities.
  • Partners with stakeholders to ensure initiatives support the organization’s mission, values, and operational goals, while maintaining compliance with regulatory, legal, and contractual obligations.
  • Leads the team’s engagement in regulatory audit and investigation activities, including the coordination and production of evidence.

People Leadership

  • Responsible for developing and leading a high-performing team of security risk professionals focused on third-party and integrated risk management, risk-based prioritization, and enterprise risk remediation coordination.
  • Provides hands-on leadership and direct supervision of team members, ensuring effective recruitment, performance management, training, and clear accountability for individual and team productivity.
  • Designs and maintains a structured leadership development framework with clear competencies, promotion criteria, and aligned role expectations.
  • Provides ongoing coaching, mentorship, and development planning to prepare employees for advancement while actively promoting psychological safety and open communication.
  • Ensures fair, data-driven evaluations and fosters a collaborative, inclusive leadership culture.
  • Exhibits courageous, authentic leadership—building trust through vulnerability, empathy, and clear, human-centered communication with executives and stakeholders through both formal and informal channels.

Information Security Governance, Risk & Compliance (GRC)

  • Oversees and actively contributes to third-party and integrated risk management activities within Trinity Health GRC platforms, driving continuous process improvement and proactively planning for changes to control frameworks and risk questionnaires.
  • Actively perform and review vendor tiering and risk assessments alongside the team, taking ownership of and/or supporting senior team members through ownership of complex or high-risk cases, as appropriate
  • Define and maintain the third-party cyber risk lifecycle, including intake, inherent risk scoring, due diligence, control assessment, remediation, risk acceptance, ongoing monitoring, renewal review, material change review, and offboarding.
  • Evaluate vendor controls across identity and access management, network security, cloud security, application security, data protection, encryption, vulnerability management, endpoint protection, logging and monitoring, incident response, disaster recovery, secure SDLC, privacy, and governance
  • Review and advise on contractual clauses related to security controls, breach notification, incident cooperation, right to audit, data protection, encryption, access control, regulatory compliance, cyber insurance, subcontractors, business continuity, data retention, and secure data destruction
  • Facilitate and lead offshore security risk compliance program.
  • Translate technical findings into business risk language that e

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Trinity Health

View company profile →