BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee
„BlueCross BlueShield of Tennessee“ yra Tenesyje įsikūręs sveikatos planų teikėjas, aptarnaujantis 3,4 mln. narių sveikatos priežiūros ir draudimo srityse. Būdama nepriklausoma „Blue Cross Blue Shield Association“ licencijos turėtoja ir kvalifikuota „Health Insurance Marketplace“ teikėja, įmonė derina sveikatos draudimo apsaugą su klientų aptarnavimu ir į bendruomenę orientuota priežiūra. Įmonė siūlo įvairių profesinės veiklos galimybių, įskaitant „BlueBridge“ stažuočių programą, padedančią studentams ir neseniai studijas baigusiems žmonėms pradėti karjerą. „BlueCross BlueShield of Tennessee“ taip pat pabrėžia darbo aplinką, kurioje darbuotojai yra vertinami, gerbiami ir įtraukiami.

Senior Information Security Risk Analyst

Lead application security risk and governance work at BlueCross BlueShield of Tennessee, including SAST/DAST oversight, SOC 2 audits, NIST security plans, and risk remediation.

Aprašymas

  • Provide technical expertise in application security risk management.
  • Oversee the SAST/DAST application scanning program.
  • Evaluate security vulnerabilities and findings from application and infrastructure scans.
  • Work with application teams, incident managers, and business stakeholders to prioritize and reduce risk.
  • Improve use of the SAST/DAST platform and strengthen vulnerability management.
  • Make risk more visible by turning technical findings into actionable business insights.
  • Contribute to a prominent Data Governance initiative.
  • Collaborate with business leaders, data owners, and security, privacy, compliance, and technology teams.
  • Set governance standards, assess risk, monitor compliance, and improve data stewardship.
  • Coordinate SOC 2 audits, including evidence gathering, control validation, and auditor communication.
  • Keep control documentation, mappings, and narratives current.
  • Manage audit findings, remediation work, and issue closure.
  • Develop and maintain NIST System Security Plans (SSPs).
  • Create and manage security awareness training, phishing simulations, and targeted campaigns.
  • Maintain security policies, standards, and procedures throughout their lifecycle.
  • Conduct enterprise and third-party risk reviews, maintain risk registers, assess vendors, and track remediation.
  • Monitor vulnerability fixes against service-level agreements.
  • Complete responses to RFPs and security questionnaires.
  • Contribute across GRC initiatives and encourage collaboration and shared accountability.

Reikalavimai

  • Bachelor’s degree in a relevant discipline, or equivalent experience totaling four years.
  • At least five years of professional experience in information security or related IT work with security responsibilities.
  • At least two years of experience focused on Governance, Risk, and Compliance (GRC).
  • Experience using AI-enabled tools to automate or improve GRC processes is preferred.
  • A CISSP, CRISC, CISA, or CISM certification is preferred.
  • Ability to assess and document organizational risks, determine their impact, and recommend mitigations.
  • Ability to interpret and apply regulations and frameworks such as NIST, SOC 2, and HIPAA.
  • Ability to analyze security, compliance, and risk metrics.
  • Ability to explain complex risk and compliance topics to technical and non-technical audiences.
  • Ability to work collaboratively across functions.
  • Strong time management skills.
  • Excellent verbal and written communication skills.
  • Strong interpersonal and relationship-building abilities.
  • Ability to work with staff and management at all levels.
  • Availability during Eastern Time business hours is required.
  • Participation in an on-call rotation is required for two weeks every 22 weeks.
  • Visa sponsorship is unavailable for this role.

Privalumai

  • Remote, work-from-home position.
  • Employee worker type.
  • Opportunity to shape enterprise-wide decisions and help advance an established Data Governance program.

Susiję darbai

Red Hat

Consulting Cloud Architect, OpenShift

Red Hat

Design and deliver Red Hat OpenShift, Kubernetes, and hybrid cloud solutions for enterprise customers. Lead customer engagements focused on infrastructure, automation, and application delivery.

Atidaryti
Kreato Global | BPO and Language Solutions

Remote English-Spanish OPI/VRI Interpreter

Kreato Global | BPO and Language Solutions

Interpret remotely between English- and Spanish-speaking people in medical, financial, social service, and customer care settings. Provide language support for Kreato Global across Latin America.

Atidaryti
RecruitGo

Remote Executive Assistant, Outreach and Marketing — Philippines

RecruitGo
51 – 200 Darbuotojai
KonsultavimasLogistikaRinkodara

Handle administrative support, CRM, outreach, and marketing for RecruitGo, an Employer of Record serving global clients with talent from emerging markets. Support two UK-facing clients with day-to-day administration and creative campaigns.

Atidaryti