BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee is a Tennessee-based health plan provider serving 3.4 million members through its work in healthcare and insurance. As an independent licensee of the Blue Cross Blue Shield Association and a qualified Health Insurance Marketplace issuer, the company combines health coverage with customer service and community-focused care. Its careers span a range of professional opportunities, including the BlueBridge internship program, which helps students and recent graduates begin their careers. BlueCross BlueShield of Tennessee also emphasizes a workplace where employees are valued, respected, and included.

Senior Information Security Risk Analyst

Lead application security risk and governance work at BlueCross BlueShield of Tennessee, including SAST/DAST oversight, SOC 2 audits, NIST security plans, and risk remediation.

Description

  • Provide technical expertise in application security risk management.
  • Oversee the SAST/DAST application scanning program.
  • Evaluate security vulnerabilities and findings from application and infrastructure scans.
  • Work with application teams, incident managers, and business stakeholders to prioritize and reduce risk.
  • Improve use of the SAST/DAST platform and strengthen vulnerability management.
  • Make risk more visible by turning technical findings into actionable business insights.
  • Contribute to a prominent Data Governance initiative.
  • Collaborate with business leaders, data owners, and security, privacy, compliance, and technology teams.
  • Set governance standards, assess risk, monitor compliance, and improve data stewardship.
  • Coordinate SOC 2 audits, including evidence gathering, control validation, and auditor communication.
  • Keep control documentation, mappings, and narratives current.
  • Manage audit findings, remediation work, and issue closure.
  • Develop and maintain NIST System Security Plans (SSPs).
  • Create and manage security awareness training, phishing simulations, and targeted campaigns.
  • Maintain security policies, standards, and procedures throughout their lifecycle.
  • Conduct enterprise and third-party risk reviews, maintain risk registers, assess vendors, and track remediation.
  • Monitor vulnerability fixes against service-level agreements.
  • Complete responses to RFPs and security questionnaires.
  • Contribute across GRC initiatives and encourage collaboration and shared accountability.

Requirements

  • Bachelor’s degree in a relevant discipline, or equivalent experience totaling four years.
  • At least five years of professional experience in information security or related IT work with security responsibilities.
  • At least two years of experience focused on Governance, Risk, and Compliance (GRC).
  • Experience using AI-enabled tools to automate or improve GRC processes is preferred.
  • A CISSP, CRISC, CISA, or CISM certification is preferred.
  • Ability to assess and document organizational risks, determine their impact, and recommend mitigations.
  • Ability to interpret and apply regulations and frameworks such as NIST, SOC 2, and HIPAA.
  • Ability to analyze security, compliance, and risk metrics.
  • Ability to explain complex risk and compliance topics to technical and non-technical audiences.
  • Ability to work collaboratively across functions.
  • Strong time management skills.
  • Excellent verbal and written communication skills.
  • Strong interpersonal and relationship-building abilities.
  • Ability to work with staff and management at all levels.
  • Availability during Eastern Time business hours is required.
  • Participation in an on-call rotation is required for two weeks every 22 weeks.
  • Visa sponsorship is unavailable for this role.

Benefits

  • Remote, work-from-home position.
  • Employee worker type.
  • Opportunity to shape enterprise-wide decisions and help advance an established Data Governance program.

Related Jobs

ReSus Consult GmbH

Sales Director, HVAC and Plumbing (SHK)

ReSus Consult GmbH
DEGermany
€120,000 – €180,000 / year
HybridFull-timeLeadGerman RequiredSales

Lead a regional portfolio of five to twelve SHK trade businesses, with responsibility for budgets and operational development. Build regional collaboration through digitalization, shared capacity, larger projects and best-practice exchange.

Open
smartkündigen OHG

Senior Sales Manager (German-speaking), Remote

smartkündigen OHG
11 – 50 Employees
B2CProductivitySaaS

Advise customers, grow existing accounts, and close sales for smartkündigen’s digital contract cancellation service. Work fully remotely without cold calling.

Open
smartkündigen OHG

Senior Sales Manager, Remote

smartkündigen OHG
11 – 50 Employees
B2CProductivitySaaS

Advise customers, grow existing accounts, and close sales for smartkündigen’s digital contract cancellation service. Work fully remotely worldwide, handling inbound inquiries without cold calling.

Open