Full-Time

IT Governance Risk Compliance

GRC, Specialist

Posted on 12/13/2024

Blue Cross Blue Shield

Blue Cross Blue Shield

1,001-5,000 employees

Healthcare

Junior, Mid, Senior, Expert

Phoenix, AZ, USA

Hybrid position requires onsite presence in Phoenix, AZ at least once per month.

Category
Cybersecurity
IT & Security
Required Skills
Risk Management

You match the following Blue Cross Blue Shield's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • 2 years of experience in information technology or computer systems
  • 1 year of experience in information security and/or compliance
  • 4 years of experience in information technology or computer systems
  • 2 years of experience in information security and/or compliance
  • 1 year of experience in IT audit and/or risk management
  • 6 years of experience in information technology or computer systems
  • 4 years of experience in information security and/or compliance
  • 2 years of experience in IT audit and/or risk management
  • 1 year of experience in project or team leadership
  • 8 years of experience in information technology or computer systems
  • 6 years of experience in information security and/or compliance
  • 4 years of experience in IT audit and/or risk management
  • 2 years of experience in project or team leadership
  • High-School Diploma or GED in general field of study
Responsibilities
  • In-depth knowledge of information security management frameworks (NIST CSF, NIST 800-53, PCI-DSS, HITRUST, ISO), healthcare industry standards and regulations (HIPAA, CMS, URAC, AHCCCS, NCQA, State Privacy Law), and other legislative documentation requirements.
  • Partners with leadership, management, and subject matter experts to develop appropriate internal controls in accordance with industry standards and best practices.
  • Works with the GRC Manager and Chief Information Security Officer (CISO) to ensure policies and content are aligned with approved strategic plan.
  • Develops and/or facilitates in the development of new procedures and processes that support advancing technologies or capabilities.
  • Develop and maintain the on-going annual reviews of information security policies, standards, procedures, and processes.
  • Identifies opportunities to improve procedures and processes that support a culture of information security compliance.
  • Provide subject matter expertise to business and project teams to define information security governance and compliance policy and technical requirements.
  • Evaluates high-level project information and components to forecast work effort required.
  • Participates in large- or complex-technical projects including disaster recovery exercises, scoping, and testing.
  • Administer GRC tools including uploading, updating, and managing content, and overall system management.
  • Conduct GRC tool user training sessions, develop training materials, and provide ongoing support to end users to ensure efficient tool use.
  • Assist with tools configuration and updates to align with organizational needs, participating in testing before production deployment
  • Performs risk and control effectiveness tests, risk analyses, and assessments.
  • Collaborate with internal stakeholders to drive implantation of effective risk treatment plans of identified risks from external assessments, internal scans, and third parties.
  • Analyze and prepare routine GRC metrics and effectiveness testing relating to ongoing measurement.
  • Works the GRC Manager and CISO to prepare executive- and board-level metrics and reporting.
  • Assist in enhancing third-party risk management activities through refined assessment methodologies, process innovation, and comprehensive vendor risk analysis.
  • Perform vendor security and privacy risk assessments for third-party suppliers
  • Review and analyze content of the security and privacy risk questionnaire of third-party suppliers
  • Monitor the ongoing security and privacy risk of third-party suppliers and prepare reports for management
  • Develop and maintain security awareness training for new hires and annual refreshers.
  • Educate workforce on compliance and governance practices through individual training, Intranet articles, etc.
  • Consults with workforce members on information security governance and compliance issues, documentation standardization, and other related concerns or questions.
  • Collaborate with internal and external auditors to facilitate security audits and assessments and control testing for in-scope applications.
  • Support audit readiness by organizing and maintain accurate and current data in GRC tools.
  • Partner with legal and compliance teams to analyze new and upcoming industry regulations related to cybersecurity controls, risk management and reporting, and external reporting requirements for compliance.
  • Each progressive level includes the ability to perform the essential functions of any lower levels and mentor employees in those levels.
  • The position requires a full-time work schedule. Full-time is defined as working at least 40 hours per week, plus any additional hours as requested or as needed to meet business requirements.
  • Perform all other duties as assigned.
Desired Qualifications
  • 2 years of experience in information technology or computer systems
  • 2 years of experience in information security and/or compliance
  • 6 years of experience in information technology or computer systems
  • 3 years of experience in information security and/or compliance
  • 2 years of experience in IT audit and/or risk management
  • 8 years of experience in information technology or computer systems
  • 6 years of experience in information security and/or compliance
  • 4 years of experience in IT audit and/or risk management
  • 2 years of experience in project or team leadership
  • 10 years of experience in information technology or computer systems
  • 8 years of experience in information security and/or compliance
  • 6 years of experience in IT audit and/or risk management
  • 4 years of experience in project or team leadership
  • Bachelor’s Degree or higher in computer science, information systems, business, or related field (All Levels)
  • Certified Information Systems Security Practitioner (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Security Auditor (CISA)
  • Certified Risk and Information Systems Control (CRISC)
  • any security related certification
Blue Cross Blue Shield

Blue Cross Blue Shield

View

Company Stage

N/A

Total Funding

N/A

Headquarters

Chicago, Illinois

Founded

1910

Simplify Jobs

Simplify's Take

What believers are saying

  • Telehealth expansion can meet growing consumer demand post-COVID-19 pandemic.
  • Value-based care models can improve patient satisfaction and reduce operational costs.
  • Increasing demand for mental health services offers growth opportunities for BCBS.

What critics are saying

  • Rising healthcare claims costs could strain BCBS's financial resources.
  • Antitrust lawsuits may lead to significant financial penalties and regulatory scrutiny.
  • COVID-19 vaccine mandate issues could affect workforce stability and public perception.

What makes Blue Cross Blue Shield unique

  • Blue Cross Blue Shield offers Blue Distinction Centers for specialized medical procedures.
  • The company collaborates with cities for community health initiatives like Bluebike unlocks.
  • BCBS promotes data-driven healthcare with leadership roles like VP of Enterprise Data.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Hybrid Work Options

INACTIVE