BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee
BlueCross BlueShield of Tennessee este un furnizor de planuri de sănătate cu sediul în Tennessee, care deservește 3,4 milioane de membri prin activitatea sa în domeniul serviciilor medicale și al asigurărilor. În calitate de licențiat independent al Blue Cross Blue Shield Association și emitent eligibil pentru planurile de pe Piața asigurărilor de sănătate, compania combină acoperirea medicală cu serviciile pentru clienți și îngrijirea axată pe comunitate. Oportunitățile de carieră acoperă o gamă largă de domenii profesionale, inclusiv programul de internship BlueBridge, care îi ajută pe studenți și pe proaspeții absolvenți să își înceapă cariera. BlueCross BlueShield of Tennessee pune, de asemenea, accent pe un mediu de lucru în care angajații sunt apreciați, respectați și incluși.

Senior Information Security Risk Analyst

Lead application security risk and governance work at BlueCross BlueShield of Tennessee, including SAST/DAST oversight, SOC 2 audits, NIST security plans, and risk remediation.

Descriere

  • Provide technical expertise in application security risk management.
  • Oversee the SAST/DAST application scanning program.
  • Evaluate security vulnerabilities and findings from application and infrastructure scans.
  • Work with application teams, incident managers, and business stakeholders to prioritize and reduce risk.
  • Improve use of the SAST/DAST platform and strengthen vulnerability management.
  • Make risk more visible by turning technical findings into actionable business insights.
  • Contribute to a prominent Data Governance initiative.
  • Collaborate with business leaders, data owners, and security, privacy, compliance, and technology teams.
  • Set governance standards, assess risk, monitor compliance, and improve data stewardship.
  • Coordinate SOC 2 audits, including evidence gathering, control validation, and auditor communication.
  • Keep control documentation, mappings, and narratives current.
  • Manage audit findings, remediation work, and issue closure.
  • Develop and maintain NIST System Security Plans (SSPs).
  • Create and manage security awareness training, phishing simulations, and targeted campaigns.
  • Maintain security policies, standards, and procedures throughout their lifecycle.
  • Conduct enterprise and third-party risk reviews, maintain risk registers, assess vendors, and track remediation.
  • Monitor vulnerability fixes against service-level agreements.
  • Complete responses to RFPs and security questionnaires.
  • Contribute across GRC initiatives and encourage collaboration and shared accountability.

Cerințe

  • Bachelor’s degree in a relevant discipline, or equivalent experience totaling four years.
  • At least five years of professional experience in information security or related IT work with security responsibilities.
  • At least two years of experience focused on Governance, Risk, and Compliance (GRC).
  • Experience using AI-enabled tools to automate or improve GRC processes is preferred.
  • A CISSP, CRISC, CISA, or CISM certification is preferred.
  • Ability to assess and document organizational risks, determine their impact, and recommend mitigations.
  • Ability to interpret and apply regulations and frameworks such as NIST, SOC 2, and HIPAA.
  • Ability to analyze security, compliance, and risk metrics.
  • Ability to explain complex risk and compliance topics to technical and non-technical audiences.
  • Ability to work collaboratively across functions.
  • Strong time management skills.
  • Excellent verbal and written communication skills.
  • Strong interpersonal and relationship-building abilities.
  • Ability to work with staff and management at all levels.
  • Availability during Eastern Time business hours is required.
  • Participation in an on-call rotation is required for two weeks every 22 weeks.
  • Visa sponsorship is unavailable for this role.

Beneficii

  • Remote, work-from-home position.
  • Employee worker type.
  • Opportunity to shape enterprise-wide decisions and help advance an established Data Governance program.

Locuri de muncă similare

Kreato Global | BPO and Language Solutions

Remote English-Spanish OPI/VRI Interpreter

Kreato Global | BPO and Language Solutions

Interpret remotely between English- and Spanish-speaking people in medical, financial, social service, and customer care settings. Provide language support for Kreato Global across Latin America.

Deschide
RecruitGo

Remote Executive Assistant, Outreach and Marketing — Philippines

RecruitGo

Handle administrative support, CRM, outreach, and marketing for RecruitGo, an Employer of Record serving global clients with talent from emerging markets. Support two UK-facing clients with day-to-day administration and creative campaigns.

Deschide