BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee ir Tenesī bāzēts veselības plānu nodrošinātājs, kas ar veselības aprūpes un apdrošināšanas pakalpojumu palīdzību apkalpo 3,4 miljonus biedru. Kā neatkarīgs Blue Cross Blue Shield Association licences turētājs un kvalificēts Health Insurance Marketplace izsniedzējs uzņēmums apvieno veselības apdrošināšanas segumu ar klientu apkalpošanu un uz kopienu vērstu aprūpi. Uzņēmums piedāvā dažādas profesionālās karjeras iespējas, tostarp BlueBridge prakses programmu, kas palīdz studentiem un nesenajiem absolventiem sākt karjeru. BlueCross BlueShield of Tennessee arī uzsver darba vidi, kurā darbinieki tiek novērtēti, cienīti un iekļauti.

Senior Information Security Risk Analyst

Lead application security risk and governance work at BlueCross BlueShield of Tennessee, including SAST/DAST oversight, SOC 2 audits, NIST security plans, and risk remediation.

Apraksts

  • Provide technical expertise in application security risk management.
  • Oversee the SAST/DAST application scanning program.
  • Evaluate security vulnerabilities and findings from application and infrastructure scans.
  • Work with application teams, incident managers, and business stakeholders to prioritize and reduce risk.
  • Improve use of the SAST/DAST platform and strengthen vulnerability management.
  • Make risk more visible by turning technical findings into actionable business insights.
  • Contribute to a prominent Data Governance initiative.
  • Collaborate with business leaders, data owners, and security, privacy, compliance, and technology teams.
  • Set governance standards, assess risk, monitor compliance, and improve data stewardship.
  • Coordinate SOC 2 audits, including evidence gathering, control validation, and auditor communication.
  • Keep control documentation, mappings, and narratives current.
  • Manage audit findings, remediation work, and issue closure.
  • Develop and maintain NIST System Security Plans (SSPs).
  • Create and manage security awareness training, phishing simulations, and targeted campaigns.
  • Maintain security policies, standards, and procedures throughout their lifecycle.
  • Conduct enterprise and third-party risk reviews, maintain risk registers, assess vendors, and track remediation.
  • Monitor vulnerability fixes against service-level agreements.
  • Complete responses to RFPs and security questionnaires.
  • Contribute across GRC initiatives and encourage collaboration and shared accountability.

Prasības

  • Bachelor’s degree in a relevant discipline, or equivalent experience totaling four years.
  • At least five years of professional experience in information security or related IT work with security responsibilities.
  • At least two years of experience focused on Governance, Risk, and Compliance (GRC).
  • Experience using AI-enabled tools to automate or improve GRC processes is preferred.
  • A CISSP, CRISC, CISA, or CISM certification is preferred.
  • Ability to assess and document organizational risks, determine their impact, and recommend mitigations.
  • Ability to interpret and apply regulations and frameworks such as NIST, SOC 2, and HIPAA.
  • Ability to analyze security, compliance, and risk metrics.
  • Ability to explain complex risk and compliance topics to technical and non-technical audiences.
  • Ability to work collaboratively across functions.
  • Strong time management skills.
  • Excellent verbal and written communication skills.
  • Strong interpersonal and relationship-building abilities.
  • Ability to work with staff and management at all levels.
  • Availability during Eastern Time business hours is required.
  • Participation in an on-call rotation is required for two weeks every 22 weeks.
  • Visa sponsorship is unavailable for this role.

Priekšrocības

  • Remote, work-from-home position.
  • Employee worker type.
  • Opportunity to shape enterprise-wide decisions and help advance an established Data Governance program.

Saistītās vakances

NOVALINK SOLUTIONS LLC

GIS Analyst III (Hybrid) – Mechanicsville, VA

NOVALINK SOLUTIONS LLC

Develop GIS applications and advanced analyses for VDOT highway maintenance assets. The role covers enterprise data, linear referencing, mapping, and technical coordination.

Atvērt
Anecdotes

Senior Software Engineer

Anecdotes

Build end-to-end product capabilities for Anecdotes’ AI-native enterprise GRC platform. Design scalable backend systems and user-facing experiences with modern AI development tools.

Atvērt
Bagira

Senior Full Stack Team Leader

Bagira

Lead Bagira’s new full stack team as it builds cloud-connected Windows software for military training and simulation. Shape the product architecture and guide delivery across C#/.NET, JavaScript/TypeScript, and cloud environments.

Atvērt
Deutsche Windtechnik

Site Coordinator, Wind Energy Operations

Deutsche Windtechnik

Coordinate project documents and maintenance reporting for Deutsche Windtechnik’s wind energy operations in Taiwan. Work with engineers, clients, and other stakeholders to manage permits, safety records, and document control.

Atvērt