TN Visa Risk And Compliance Jobs
Risk and compliance roles qualify for TN visa sponsorship under the USMCA treaty for Canadian and Mexican professionals with a relevant bachelor's degree. Employers file no lottery and face no annual cap for Canadians, making sponsorship faster than H-1B. Mexican professionals are subject to a separate TN allocation.
See All Risk And Compliance JobsOverview
Showing 5 of 618+ Risk And Compliance jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 618+ Risk And Compliance jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Risk And Compliance roles.
Get Access To All Jobs
JOB SUMMARY
This job works collaboratively to support all risk and compliance assessment activities of Highmark Health across a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, etc. The incumbent will partner with the organizational risk and business partners, the technology organization, and global delivery teams to meet Highmark Health’s mission requirements in a manner consistent with the enterprise risk appetite. This individual must have a proactive mindset and approach, and feel comfortable working in a highly matrixed environment.
ESSENTIAL RESPONSIBILITIES
-
Completes assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess, prioritize, evaluate and address compliance, financial, information security, privacy, and other areas of risk. Prepares draft reports and other management reporting deliverables. Prepares all work paper and supporting documentation evidence according to audit quality standards in a consistent manner.
-
Schedules, delivers, and follows-up to ensure risk questionnaires and other risk assessments are completed timely in order to ensure compliance requirements are met across the Enterprise. Assists in training and mentoring less experienced team members on multi-faceted engagements, platform customer dependencies, and assists with the review and interpretation of less-complex authoritative guidance.
-
Delivers risk assessments to internal and external contacts. Assists with the review of inherent risk assessment results and the stratification of engagement risks, and assists with the development of assurance plans (e.g., on-site audit, contract review, financials assessment, purchasing data analysis) to address relevant risk areas and to ensure proper controls are implemented. Reviews and interprets information provided (including, but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO reports) and assists with performing qualitative and quantitative impact assessments based on physical, technical, and administrative safeguards as well as contractual requirements; conducts additional information gathering and risk assessments with external points of contact, as-needed; documents and reports results.
-
Documents and interprets complex data flow/information sharing activities, customer integrations, and information safeguards into simplified and high-level terminology and/or process/data flows. Assists with maintaining enterprise supplier risk management reporting dashboards in RSA Archer applications in order to keep information complete, accurate, and current. Prepares and assists with the delivery of risk assurance reports to management.
-
Assists with preparation of project plans to support risk assessment and risk decisioning processes in coordination with business owners and other stakeholders within task-based budgets. Collaborates with Information Security, Privacy, Procurement, Audit, Compliance, and other teams across the enterprise to align risk management objectives, practices and procedures.
-
Maintains departmental desk-level procedures, assessment methodology, assessment procedures, questionnaires, training, etc. Reviews and documents activities which demonstrate and support compliance with departmental metrics, performance of internal control activities, awareness of contractual obligations, regulatory requirements, and assistance with responding to customer inquiries/audits.
-
Interfaces with business areas, technical staff, project teams, and third parties to execute cross-functional risk assurance projects. Prepares materials to support communication of assessment results and findings with multiple stakeholder groups.
-
Assists with providing input and consultation on risk and assurance requirements. Consults with other areas (e.g., Procurement, Privacy, Information Security, Legal) throughout the engagement lifecycle along with internal business and contract administration partners. Assists in contract reviews and providing timely feedback on contract terms and conditions.
Other duties as assigned or requested.
Education
Required
Bachelor's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Substitution
6 years of related and progressive experience in lieu of Bachelor's degree
Preferred
- Master's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Experience
Required
- 1 year in Audit and Compliance
To Include:
- 1 year in Business Process Design
- 1 year in Project Management
Preferred
None
LICENSES or CERTIFICATIONS
Required
- None
Preferred (any of the following)
- Certified Public Accountant (CPA)
- Certified Information Systems Analyst (CISA)
- Certified Information Privacy Professional (CIPP)
- Certified Information Systems Security Professional (CISSP)
SKILLS
-
Demonstrate expert knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes.
-
Knowledge of relevant regulatory guidelines, vendor management, sourcing and procurement, and completing assessments of vendors.
-
Excellent resource and project planning capabilities, decision making skills, history of results-oriented delivery, and effective team building across a cross-campus and diverse team of management and staff.
-
Strong written and verbal communication skills for diverse audiences (senior management, board, peer, and team).
-
Strong relationship building skills and ability to influence with and without authority in a matrixed organization.
-
Leadership qualities with an ability to motivate and inspire a group of individuals to achieve superior results.
-
High capacity to think analytically, interpret information/observations, apply judgment and make effective, strategic decisions.
Language (Other than English):
None
Travel Requirement:
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-based
Teaches / trains others regularly
Occasionally
Travel regularly from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
California Consumer Privacy Act Employees, Contractors, and Applicants Notice

JOB SUMMARY
This job works collaboratively to support all risk and compliance assessment activities of Highmark Health across a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, etc. The incumbent will partner with the organizational risk and business partners, the technology organization, and global delivery teams to meet Highmark Health’s mission requirements in a manner consistent with the enterprise risk appetite. This individual must have a proactive mindset and approach, and feel comfortable working in a highly matrixed environment.
ESSENTIAL RESPONSIBILITIES
-
Completes assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess, prioritize, evaluate and address compliance, financial, information security, privacy, and other areas of risk. Prepares draft reports and other management reporting deliverables. Prepares all work paper and supporting documentation evidence according to audit quality standards in a consistent manner.
-
Schedules, delivers, and follows-up to ensure risk questionnaires and other risk assessments are completed timely in order to ensure compliance requirements are met across the Enterprise. Assists in training and mentoring less experienced team members on multi-faceted engagements, platform customer dependencies, and assists with the review and interpretation of less-complex authoritative guidance.
-
Delivers risk assessments to internal and external contacts. Assists with the review of inherent risk assessment results and the stratification of engagement risks, and assists with the development of assurance plans (e.g., on-site audit, contract review, financials assessment, purchasing data analysis) to address relevant risk areas and to ensure proper controls are implemented. Reviews and interprets information provided (including, but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO reports) and assists with performing qualitative and quantitative impact assessments based on physical, technical, and administrative safeguards as well as contractual requirements; conducts additional information gathering and risk assessments with external points of contact, as-needed; documents and reports results.
-
Documents and interprets complex data flow/information sharing activities, customer integrations, and information safeguards into simplified and high-level terminology and/or process/data flows. Assists with maintaining enterprise supplier risk management reporting dashboards in RSA Archer applications in order to keep information complete, accurate, and current. Prepares and assists with the delivery of risk assurance reports to management.
-
Assists with preparation of project plans to support risk assessment and risk decisioning processes in coordination with business owners and other stakeholders within task-based budgets. Collaborates with Information Security, Privacy, Procurement, Audit, Compliance, and other teams across the enterprise to align risk management objectives, practices and procedures.
-
Maintains departmental desk-level procedures, assessment methodology, assessment procedures, questionnaires, training, etc. Reviews and documents activities which demonstrate and support compliance with departmental metrics, performance of internal control activities, awareness of contractual obligations, regulatory requirements, and assistance with responding to customer inquiries/audits.
-
Interfaces with business areas, technical staff, project teams, and third parties to execute cross-functional risk assurance projects. Prepares materials to support communication of assessment results and findings with multiple stakeholder groups.
-
Assists with providing input and consultation on risk and assurance requirements. Consults with other areas (e.g., Procurement, Privacy, Information Security, Legal) throughout the engagement lifecycle along with internal business and contract administration partners. Assists in contract reviews and providing timely feedback on contract terms and conditions.
Other duties as assigned or requested.
Education
Required
Bachelor's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Substitution
6 years of related and progressive experience in lieu of Bachelor's degree
Preferred
- Master's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Experience
Required
- 1 year in Audit and Compliance
To Include:
- 1 year in Business Process Design
- 1 year in Project Management
Preferred
None
LICENSES or CERTIFICATIONS
Required
- None
Preferred (any of the following)
- Certified Public Accountant (CPA)
- Certified Information Systems Analyst (CISA)
- Certified Information Privacy Professional (CIPP)
- Certified Information Systems Security Professional (CISSP)
SKILLS
-
Demonstrate expert knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes.
-
Knowledge of relevant regulatory guidelines, vendor management, sourcing and procurement, and completing assessments of vendors.
-
Excellent resource and project planning capabilities, decision making skills, history of results-oriented delivery, and effective team building across a cross-campus and diverse team of management and staff.
-
Strong written and verbal communication skills for diverse audiences (senior management, board, peer, and team).
-
Strong relationship building skills and ability to influence with and without authority in a matrixed organization.
-
Leadership qualities with an ability to motivate and inspire a group of individuals to achieve superior results.
-
High capacity to think analytically, interpret information/observations, apply judgment and make effective, strategic decisions.
Language (Other than English):
None
Travel Requirement:
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-based
Teaches / trains others regularly
Occasionally
Travel regularly from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
See all 618+ Risk And Compliance jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Risk And Compliance roles.
Get Access To All JobsTips for Finding TN Visa Sponsorship as a Risk And Compliance
Align your credentials to compliance SOC codes
TN eligibility for risk and compliance roles hinges on your degree field matching the position. A finance or business law degree supports a compliance analyst role more cleanly than a general management degree, which CBP officers may scrutinize.
Target employers experienced with visa sponsorship
Financial institutions, insurance carriers, and multinational corporations in regulated industries have recent visa filings and understand work visa sponsorship processes. Prioritize employers whose legal or HR teams are experienced with visa sponsorship, as they're more likely to understand the documentation requirements for compliance-specific job titles and be prepared to provide the support letter needed for TN visa applications.
Negotiate the offer letter before filing begins
Your offer letter must specify the exact TN occupational category and describe duties that align with it. Risk and compliance job descriptions that mix in unqualified management tasks can trigger CBP questions at the port of entry.
Search TN-sponsoring employers using Migrate Mate
Use Migrate Mate to filter risk and compliance roles by employers with active TN visa sponsorship history, saving time you'd otherwise spend cold-emailing HR teams who aren't familiar with TN filings for this occupational category.
Prepare a degree equivalency letter for Mexican applicants
Mexican professionals with a licenciatura in accounting, law, or finance should obtain a credential evaluation confirming U.S. degree equivalency before applying. CBP officers at land ports sometimes request this documentation for compliance-category TN entrants.
Request premium processing if your start date is fixed
Canadian citizens can use USCIS Form I-129 with premium processing to get a 15-business-day decision when a port-of-entry admission isn't feasible. This route is especially useful if your employer's compliance team has a hard onboarding deadline.
Risk And Compliance jobs are hiring across the US. Find yours.
Find Risk And Compliance JobsRisk And Compliance TN Visa: Frequently Asked Questions
Does a risk and compliance role qualify for TN visa status?
Yes, if the position maps to an eligible USMCA occupational category such as accountant, economist, or financial analyst and requires at least a bachelor's degree in a related field. Job titles that mix compliance duties with generalist management responsibilities may face CBP scrutiny, so your offer letter should clearly describe the specialized compliance function.
How does TN visa sponsorship compare to H-1B for compliance professionals?
TN has no lottery and no annual cap for Canadians, so sponsorship can happen year-round without waiting for an October start date. H-1B requires employer sponsorship through a competitive lottery with a roughly 25% selection rate. For compliance roles that clearly fit a USMCA-defined occupation, TN is a faster and more predictable path than H-1B.
Where can I find employers that sponsor TN visas for risk and compliance roles?
Migrate Mate lets you search risk and compliance job listings filtered by employers with TN visa sponsorship history. This removes the guesswork of identifying which financial institutions and corporate compliance teams are already familiar with TN filings for this occupational category.
Can a Mexican compliance professional qualify for TN status the same way a Canadian can?
The eligibility requirements are the same, but Mexican TN applicants must apply through a U.S. consulate rather than at a port of entry. Mexico also has a separate TN allocation under the USMCA. Credential documentation, including a degree equivalency evaluation if your licenciatura is not immediately recognized, is especially important for consular applications.
What happens to my TN status if my employer terminates my compliance role?
Your TN status is tied to the specific employer and role on your admission record. If your position ends, you are expected to depart the U.S. or secure a new TN with a different employer. There is no formal grace period codified for TN holders the way there is for H-1B, so coordinating a new offer quickly is essential.
See which Risk And Compliance employers are hiring and sponsoring visas right now.
Search Risk And Compliance Jobs