Senior Risk and Compliance Analyst

Highmark Health • Pittsburgh, PA • Full Time

Posted on Sat, Jun 20, 2026

Company :

Highmark Health

Job Description : 

JOB SUMMARY

This job works collaboratively to support all risk and compliance assessment activities across Highmark Health, leveraging a broad range of frameworks and standards including NIST, HITRUST, PCI DSS, HIPAA, SOC, MAR, CMS, JCAHO, and other regulatory and industry requirements. The incumbent is responsible for leading and supporting third-party risk management activities, including the assessment of third-party security posture, information security controls and compliance obligations. The role also partners with internal stakeholders, procurement teams, legal counsel, and third-party suppliers to negotiate contractual provisions related to security, privacy, compliance, and risk management. The incumbent will collaborate closely with organizational risk and business partners, technology teams, and global delivery organizations to support business objectives in a manner consistent with the enterprise risk appetite. This individual must possess a proactive mindset, strong analytical and negotiation skills, and the ability to effectively influence and work within a highly matrixed environment.              


ESSENTIAL RESPONSIBILITIES


EDUCATION


Substitutions


Preferred

EXPERIENCE

To Include:


Preferred


LICENSES or CERTIFICATIONS

Preferred (any of the following)


SKILLS


Language (Other than English):

None

Travel Requirement:

0% - 25%

PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS

Position Type

Office-based

Teaches / trains others regularly

Occasionally

Travel regularly from the office to various work sites or from site-to-site

Rarely

Works primarily out-of-the office selling products/services (sales employees)

Never

Physical work site required

Yes

Lifting: up to 10 pounds

Constantly

Lifting: 10 to 25 pounds

Occasionally

Lifting: 25 to 50 pounds

Rarely

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.

As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times.  In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. 
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.

We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.

For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org

California Consumer Privacy Act Employees, Contractors, and Applicants Notice

View the interactive listing →