Sr IT/IS GRC Consultant – Information Security Policy Mgt. -

Health Care Service CorporationChicago, IL
$112,200 - $202,600Hybrid

About The Position

This position is responsible for serving as a thought leader in the governance, risk and compliance space; planning, designing, enforcing and auditing information technology and information security policies, standards and procedures which safeguard the integrity of and access to enterprise systems, files and data elements; analyzing, tracking and acting on information technology or information security policy exceptions, audits and assessments; maintaining knowledge of changing technologies, and provides recommendations for adaptation of new technologies, processes or policies; recognizing and identifying potential areas where existing information technology or information security policies, standards and procedures require change, or where new ones need to be developed, especially as a result of future business expansion and technology advances; providing management with analysis via risk assessments and briefings / reports to advise them of critical information technology / information security issues that may affect the company’s business objective and / or compliance; collaborating with and feeds it risk information into the enterprise risk management program; evaluating and recommending information technology and information security products, services and/or processes to reduce risk and maintain compliance with applicable policies, mandates, laws and regulations; implementing the activities associated with the information technology and information security awareness programs and provides education and training on information technology and information security policies, standards and practices; performing control assessments and works with appropriate subject matter experts (SME’s) to document remediation plans; serving as a project lead and mentor to junior GRC team members.

Requirements

  • Bachelor Degree and 5 years of IT / IS work experience with a broad range of exposure to systems analysis, application development, database design and administration.
  • Understanding of IT / IS concepts and how to articulate those in terms of risk.
  • Can recommend and develop strategic responses to issues and risks.
  • Interpret internal or external business issues and concepts and can translate those into IT concepts that must be addressed via policy.
  • Understanding of key IT / IS laws and regulations, such as the Health Insurance Portability and Accountability Act, as well as governance and compliance frameworks (e.g. NIST, COBIT, ITIL, HITRUST).
  • Understanding of and experience with audit and compliance controls.
  • Initiate and invoke creativity to solve complex problems; takes an “outside –in” perspective to identify innovative solutions.
  • Collaborate well with individuals across the business and IT, as well as at all levels of the organization.
  • Verbal and written communication skills, including the ability to articulate complex concepts to various technical and non-technical audience.
  • Experience with and understanding of overall GRC concepts.
  • Work independently, with guidance in only the most complex situations.
  • May lead functional teams and / or projects.

Nice To Haves

  • Bachelor Degree in Computer Science, Information Systems, or other related field.
  • Experience with a GRC solution would be preferred.

Responsibilities

  • Serving as a thought leader in the governance, risk and compliance space.
  • Planning, designing, enforcing and auditing information technology and information security policies, standards and procedures.
  • Analyzing, tracking and acting on information technology or information security policy exceptions, audits and assessments.
  • Maintaining knowledge of changing technologies, and provides recommendations for adaptation of new technologies, processes or policies.
  • Recognizing and identifying potential areas where existing information technology or information security policies, standards and procedures require change, or where new ones need to be developed.
  • Providing management with analysis via risk assessments and briefings / reports to advise them of critical information technology / information security issues.
  • Collaborating with and feeds it risk information into the enterprise risk management program.
  • Evaluating and recommending information technology and information security products, services and/or processes to reduce risk and maintain compliance.
  • Implementing the activities associated with the information technology and information security awareness programs and provides education and training.
  • Performing control assessments and works with appropriate subject matter experts (SME’s) to document remediation plans.
  • Serving as a project lead and mentor to junior GRC team members.

Benefits

  • health and wellness benefits
  • 401(k) savings plan
  • pension plan
  • paid time off
  • paid parental leave
  • disability insurance
  • supplemental life insurance
  • employee assistance program
  • paid holidays
  • tuition reimbursement
  • annual incentive bonus plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service