Logo
State of Washington

IT Security Risk and Compliance Manager

State of Washington, Olympia, Washington, United States, 98502

Save Job

Salary :

$126,177.00 - $164,579.00 Annually Location :

Thurston County - Olympia, WA Job Type:

Full Time - Permanent Job Number:

1454 Department:

Health Benefits Exchange Opening Date:

10/23/2025

Description The mission of Washington Health Benefit Exchange (Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical solutions, an easy-to-use customer experience, our values of integrity, respect, equity and transparency, and by providing undeniable value to the health care community.

The Exchange is a public-private partnership that operates Washington Healthplanfinder, the eligibility and enrollment portal used by one in four Washington residents to obtain health and dental coverage. Through this platform, and with support from a Customer Support Center and statewide network of in-person navigators and brokers, individuals and families can shop, compare and enroll in private, qualified health plans (as defined in the Affordable Care Act) or enroll in Washington Apple Health, the state Medicaid program.

The Exchange embraces the following equity statement adopted by our Board of Directors:

Equity is fundamental to the mission of the Washington Health Benefit Exchange. The process of advancing toward equity and becoming anti-racist is disruptive and demands vigilance to dismantle deeply entrenched systems of privilege and oppression. While systemic racism is a root cause of many societal inequities, we must also use an intersectional approach to address all forms of bias and oppression, which interact with and often exacerbate racial inequities. To be successful, we must recognize the socioeconomic drivers of health and focus on people and places where needs are greatest. As we listen to community, we must hold ourselves accountable to responding to recommendations to remedy inequitable policies, systems, or practices within the Exchange's area of influence. Our goal is that all Washingtonians have full and equal access to opportunities, power and resources to achieve their full potential.

SUMMARY The IT Security Risk and Compliance Manager will manage, oversee and coordinate the work of team members and activities in IT security compliance, risk management and other duties as defined by the Chief Information Security Officer (CISO). This position is responsible for developing the strategic direction for regulatory compliance and managing the risk of WAHBE data and information systems.

The IT Security Risk and Compliance Manager is responsible for continuous assessment of security controls; creation and implementation of IT security policy, procedures, and standards; and development and maintenance of IT security compliance deliverables to ensure the agency's compliance with federal and state regulations. This position reports findings on IT security risk exposures to the CISO and ensures that the risks are managed appropriately. Duties • Provide supervision, guidance, and oversight of the WAHBE IT Security Risk and Compliance Team, ensuring effective execution of responsibilities and alignment with organizational goals. • Develop, maintain, and implement cybersecurity compliance deliverables, ensuring they are regularly updated to meet evolving Centers for Medicare & Medicaid Services (CMS), the Internal Revenue Service (IRS) and WAHBE requirements. Deliverables include but are not limited to System Security Plan, Safeguard Security Report, and Annual Attestation. • Conduct comprehensive and complex cybersecurity risk assessments to identify and evaluate potential threats and vulnerabilities. • Independently perform thorough risk analysis, leveraging advanced technical expertise to evaluate vulnerabilities, cyber threats, and the effectiveness of security controls. • Ensure security controls align with WAHBE IT Security standards and policies, while maintaining compliance with applicable federal regulations, including Centers for Medicare & Medicaid Services (CMS) and the Internal Revenue Service (IRS). • Develop and implement an Information security risk management framework including gap analysis, remediation timelines, regular reviews and updates. • Develop risk management metrics and reports to effectively communicate remediation efforts, risk treatment progress, and enhancements to WAHBE's overall security posture. • Develop, track, and coordinate risk mitigation plans for federal reporting including Corrective Action Plan, Plan of Action and Milestones. • Develop and implement processes to validate and verify the completion of remediation activities and reevaluate control effectiveness as needed to ensure ongoing risk mitigation. • Collaborate with Compliance Officer, Information Security Manager, Cloud/Infrastructure Manager, Lead Product Owner, Tech Ops and other IT stakeholders for risk mitigation and control implementation. • Manage Center for Medicare and Medicaid Services (CMS) and Internal Revenue Service (IRS) security audits and safeguard reviews. • Manage and support third party security risk assessment as mandated by federal regulations. Develop, track, maintain and coordinate resulting risk mitigation plans for any findings. • Maintain and update WAHBE's Information Security policies and procedures with evolving CMS, IRS and WAHBE requirements. • Review laws, regulations and legal agreements for security and privacy language to permit authorized, collection, use, maintenance, and sharing of Personally Identifiable Information (PII) and Federal Tax Information (FTI). • Foster innovation and manage risks during major transformations. • Provide regular briefings and updates to CISO and engage with Enterprise Risk and Compliance Committee. • Communicate any obstacles that hinder successful and timely completion of compliance deliverables to the CISO promptly. • Collaborate with external partners in alignment of technology, processes and procedures to meet WAHBE policy, state and federal regulations. • Work as liaison for technical, business and external partners for audits, assessments and reviews. • Recruit, hire, lead, mentor, and retain talented risk and compliance staff. • Other duties as assigned by the CISO.

Qualifications

Required: • Bachelor's degree in engineering or technology-related major and ten years of experience with increasing management responsibilities (minimum of 5 years' experience in staff management). • Five years of experience leading and managing staff and contractor resources within IT risk and compliance domains. • Excellent understanding of standards and guidelines to include CMS standards such as Minimal Acceptable Risk Standards for Exchanges (MARS-E 2.2) and Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE) and/or Internal Revenue Service (IRS) standards such as Publication 1075. • Excellent understanding of audit processes, standards, and procedures. • Strong understanding of best practices in testing methods and metrics. • Upholds the highest ethical standards, demonstrating honesty, transparency, and consistency in words and actions. Takes responsibility for decisions, maintains confidentiality, and adheres to organizational policies and regulatory requirements. • Motivated self-starter with initiative to take independent action and accept responsibility for your actions. • Excellent project management skills and able to set clear timelines, defined roles, and practice effective change management. • Ability to prioritize and manage multiple projects simultaneously and follow-through on issues in a timely manner. • Strong interpersonal skills; ability to work with all levels of internal management and staff, as well as outside clients, vendors, diverse populations, stakeholder groups, and customers. • Skilled in resolving conflicts and addressing disagreements among team members by utilizing active listening and fostering open dialogue. • Creative and proactive problem solver; must possess the ability to make independent decisions and judgments about work priorities. • Well organized, flexible, proactive, resourceful, and efficient with strong attention to detail. • Strong understanding of contracting processes and procedures and contract management. • Ability to maintain a high level of confidentiality.

Desired: • Excellent understanding of National Institute of Standards and Technologies (NIST) security guidelines, outlined in SP 800-53 Rev 5 and NIST Risk Management Framework (RMF), outlined in SP 800-37 Rev., • Proven ability to develop and implement change management strategies, including stakeholder engagement, communication plans, and training programs, to ensure smooth transitions and sustainable adoption of new processes or technologies. • Excellent verbal and written communication skills. • Demonstrates remarkable composure and resilience in fast-paced, high-pressure environments, consistently maintaining focus and delivering results. • Foster a positive and collaborative approach to risk management within a dynamic, fast-paced organizational culture. Supplemental Information

APPLICATION INSTRUCTIONS This position will be open until we find a suitable number of candidates to review. If interested, please

submit an application

as soon as possible. The Exchange reserves the right to close the recruitment at any time.

SALARY INFORMATION Full Salary Range: $109,719.00 to $164,579.00 annually, with midpoint at $137,149.00.

Hiring Range: $126,177.00 and $137,149.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer.

The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum. BENEFITS Take a peek at our

WORKING CONDITIONS Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location.

The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

SPECIAL REQUIREMENTS A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The result of this background screen must meet the Exchange's eligibility standards.

OTHER INFORMATION The above statements are intended to describe the general nature and levels of work being performed. They are not intended to be construed as an exhaustive list of responsibilities, duties and skills of personnel so classified.

This is not an employment agreement or contract. Management has the exclusive right to alter this job description at any time without notice.

The Washington Health Benefit Exchange is an All qualified applicants will receive consideration for employment without regard to race, color, religion, age, marital status, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

We participate in You can view the Department of Justice's Right to Work poster More than Just a Paycheck! Employee benefits are not just about the kind of services you get, they are also about how much you may have to pay out of pocket. Washington State offers one of the most competitive benefits packages in the nation.

We understand that your life revolves around more than just your career. Like everyone, your first priority is ensuring that you and your family will maintain health and financial security. That's why choice is a key component of our benefits package. We have a selection of health and retirement plans, paid leave, staff training and other compensation benefits that you can mix and match to meet your current and future needs.

Read about our benefits: The following information describes typical benefits available for full-time employees who are expected to work more than six months. Actual benefits may vary by appointment type or be prorated for other than full-time work (e.g. part-time); view the job posting for benefits details for job types other than full-time.

Note:

If the position offers benefits which differ from the following, the job posting should include the specific benefits.

Insurance Benefits Employees and their families are covered by medical (including vision), dental and basic life insurance. There are multiple medical plans with affordable monthly premiums that offer coverage throughout the state.

Staff are eligible to enroll each year in a medical flexible spending account which enables them to use tax-deferred dollars toward their health care expenses. Employees are also covered by basic life and long-term disability insurance, with the option to purchase additional coverage amounts.

To view premium rates, coverage choice in your area and how to enroll, please visit the Public Employees Benefits Board (PEBB) website. The Washington Wellness program from the Health Care Authority works with PEBB to support our workplace wellness programs.

Dependent care assistance allows the employee to save pre-tax dollars for a child or elder care expenses.

Other insurance coverage for auto, boat, home, and renter insurance is available through payroll deduction.

The Washington State Employee Assistance Program promotes the health and well-being of employees.

Retirement and Deferred Compensation State Employees are members of the Washington Public Employees' Retirement System (PERS). New employees have the option of two employer contributed retirement programs. For additional information, check out the Department of Retirement Systems' web site.

Employees also have the ability to participate in the Deferred Compensation Program (DCP). This is a supplemental retirement savings program (similar to an IRA) that allows you control over the amount of pre-tax salary dollars you defer as well as the flexibility to choose between multiple investment options.

Social Security All state employees are covered by the federal Social Security and Medicare systems. The state and the employee pay an equal amount into the system.

Public Service Loan Forgiveness If you are employed by a government or not-for-profit organization, and meet the qualifying criteria, you may be eligible to receive student loan forgiveness under the Public Service Loan Forgiveness Program.

Holidays Full-time and part-time employees are entitled to paid holidays and one paid personal holiday per calendar year.

Note:

Employees who are members of certain Unions may be entitled to additional personal leave day(s), please refer to position specific Collective Bargaining Agreements for more information.

Full-time employees who work full monthly schedules qualify for holiday compensation if they are employed before the holiday and are in pay status for at least 80 nonovertime hours during the month of the holiday; or for the entire work shift preceding the holiday.

Part-time employees who are in pay status during the month of the holiday qualify for the holiday on a pro-rata basis. Compensation for holidays (including personal holiday) will be proportionate to the number of hours in pay status in the month to that required for full-time employment, excluding all holiday hours. Pay status includes hours worked and time on paid leave.

Sick Leave Full-time employees earn eight hours of sick leave per month. Overtime eligible employees who are in pay status for less than 80 hours per month, earn a monthly proportionate to the number of hours in pay status, in the month to that required for full-time employment. Overtime exempt employees who are in pay status for less than 80 hours per month do not earn a monthly accrual of sick leave.

Sick leave accruals for part-time employees will be proportionate to the number of hours in pay status, in the month to that required for full-time employment. Pay status includes hours worked, time on paid leave and paid holiday.

Vacation (Annual Leave) Full-time employees accrue vacation leave at the rates specified in (1) or the applicable collective bargaining agreement (CBA). Full-time employees who are in pay status for less than 80 nonovertime hours in a month do not earn a monthly accrual of vacation leave.

Part-time employees accrue vacation leave hours in accordance with (1) or the applicable collective bargaining agreement (CBA) on a pro rata basis. Vacation leave accrual will be proportionate to the number of hours in pay status, in the month to that required for full-time employment.

Pay status includes hours worked, time on paid leave and paid holiday.

As provided in , an employer may authorize a lump-sum accrual of vacation leave or accelerate the vacation leave accrual rate to support the recruitment and/or retention of a candidate or employee for a Washington Management Service position. Vacation leave accrual rates may only be accelerated using the rates established WAC 357-31-165.

Note:

Most agencies follow the civil service rules covering leave and holidays for

exempt

employees even though there is no requirement for them to do so. However, agencies are required to adhere to the applicable RCWs pertaining holidays and leave.

Military Leave Washington State supports members of the armed forces with 21 days paid military leave per year.

Bereavement Leave Most employees whose family member or household member dies, or for loss of pregnancy, are entitled to five (5) days of paid bereavement leave. In addition, the employer may approve other available leave types for the purpose of bereavement leave.

Additional Leave Leave Sharing

Family and Medical Leave Act (FMLA) Leave Without Pay

Please visit the State HR Website for more detailed information regarding benefits.

Updated 07-21-2025