Job Description

IT Governance, Risk, and Compliance Manager

  • 494266
  • Full-time


The Arizona Health Care Cost Containment System (AHCCCS), Arizona’s Medicaid agency, is driven by its mission to deliver comprehensive, cost-effective health care to Arizonans in need. AHCCCS is a nationally acclaimed model among Medicaid programs, and a recipient of multiple awards for excellence in workplace effectiveness and flexibility. Among government agencies, AHCCCS is recognized for high employee engagement and satisfaction, supportive leadership, and flexible work environments, including remote work opportunities. With career paths for seasoned professionals in a variety of fields, entry-level positions, and internship opportunities, AHCCCS offers meaningful career opportunities in a competitive industry. AHCCCS employees are passionate about their work, committed to high performance, and dedicated to serving the citizens of Arizona.

IT Governance, Risk, and Compliance Manager


Posting Details:

Salary: $80,000 - 90,000 

Grade: 29

Job Summary:

The Information Services Division (ISD) is looking for a highly motivated individual to join our team as a IT Governance, Risk, and Compliance Manager.

Job Duties:

* Leadership: Manage a dynamic team while helping them grow in their positions and keeping them motivated and informed of agency direction. Perform other duties as assigned to ensure the smooth functioning of the department and maintain the reputation of the organization as a viable business partner. Recommend programmatic and technical directions and operate with a high degree of independence in matters relating to the investigation, impact, and analysis of security incidents, decisions regarding risk, and measures for computer and network security. Operate with a high degree of independence with regard to project management activities, including development of project plans and budget/resource estimates.

* Risk: Lead the development and implementation of the system-wide risk management function of the information security program to ensure information security risks are identified and monitored. Internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for the agency's information and technology systems.

* Policy/Compliance: Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures to meet defined requirements, policies and regulations. Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation. Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors, MARS-E 2.0, HIPAA, NIST 800-53, and more.

* Outreach/Awareness: Interacts in both oral and written communications with all levels of staff both internally to the agency and state.

* Audit: Work with lines of business, state governing agencies, sister agencies and other entities to complete required agency audits. Coordinate and track all information technology and security related audits including scope of audits, parties involved, timelines, auditing agencies and outcomes. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the agency in its best light. Provide guidance, evaluation and advocacy on audit responses.

* Problem-Solving Skills: Must be able to assess computer hardware, software, and systems for security risks or violations and work with agency staff and technology vendors to recommend solutions. Develop strategies to address awareness and training for all stakeholders as well as technical solutions. Must be able to assess the status of complex multi-location projects as well as identify and implement appropriate corrective measures to resolve issues as they arise. Must have a strong customer service orientation and the ability to project that attitude to customers in remote locations.

Knowledge, Skills & Abilities (KSAs):

* Knowledge of information security risk management frameworks and compliance practices.

* Knowledge of securing network technologies, client, and serve operating systems.

* Understanding of common security standards and regulations relating to a higher education environment (e.g., PCI DSS, NIST 800-53, ISO2700x, etc.)

* Must be well versed with laws and guidelines affecting healthcare entities in the following areas: Protected Health Information (PHI), Health Insurance Portability and Accountability Act (HIPAA), Center for Medicare & Medicaid Services (CMS), Compliance research, Arizona State regulations

* Ability to develop security standards and guidelines based on best practices and industry standards.

* Experience responding to, analyzing, and communicating information security incidents.

* Excellent interpersonal, communication, and presentation skills, including formal report writing experience.

Selective Preference(s):

* 5 years of planning and managing security projects.

* 5 years managing high-performance teams.

* 7 years of advanced IT skills with high level of information security experience and expertise.


At AHCCCS, we promote the importance of work/life balance by offering workplace flexibility and a variety of learning and career development opportunities. Among the many benefits of a career with the State of Arizona, there are 10 paid holidays per year, accrual of sick and annual leave, affordable medical benefits and participation in the Arizona State Retirement Plan.

For a complete list of benefits provided by The State of Arizona, please visit our benefits page

Contact Us:

Persons with a disability may request a reasonable accommodation such as a sign language interpreter or an alternative format by contacting 602-417-4497.
Requests should be made as early as possible to allow time to arrange the accommodation. Arizona State Government is an AA/EOE/ADA Reasonable Accommodation Employer.

Application Instructions

Please click on the link below to apply for this position. A new window will open and direct you to apply at our corporate careers page. We look forward to hearing from you!

Apply Online