Senior Information Security Risk Analyst

🔥 1 hour ago

🎸 Tennessee – Remote

infoinfo

⏰ Full Time

🟠 Senior

🎲 Risk

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of BlueCross BlueShield of Tennessee

BlueCross BlueShield of Tennessee

5001 - 10000 employees

Founded 1952

🏥 Healthcare

💼 Consulting

🛡️ Insurance

Healthcare • Consulting • Insurance

BlueCross BlueShield of Tennessee is a leading health plan provider in Tennessee, serving 3. 4 million members. The company is committed to creating a workforce where everyone is valued, respected, and part of the team, emphasizing diversity and inclusion. They offer a range of career opportunities, including internships through their BlueBridge program, enabling new professionals to transition from college to work. BlueCross BlueShield of Tennessee also focuses on providing exceptional customer service and community care, striving to make a difference in the healthcare industry. It is an independent licensee of the Blue Cross Blue Shield Association and a qualified health plan issuer in the Health Insurance Marketplace.

📋 Description

• Serve as a technical subject matter expert in application security risk management • Lead governance and oversight of the SAST/DAST application security scanning program • Assess security vulnerabilities and evaluate application and infrastructure scanning findings • Partner with application teams, incident management teams, and business stakeholders to prioritize and remediate risk • Maximize the value of the SAST/DAST platform and strengthen vulnerability management practices • Improve risk visibility and translate technical findings into actionable business risk insights • Support a high-visibility Data Governance initiative • Partner with business leaders, data owners, security, privacy, compliance, and technology teams • Establish governance standards, assess risk, monitor compliance, and strengthen data stewardship practices • Coordinate SOC 2 audit activities, including evidence collection, control validation, and auditor engagement • Maintain control documentation, mappings, and narratives • Oversee audit findings, remediation efforts, and issue closure • Create and update NIST System Security Plans (SSPs) • Design and manage security awareness training initiatives, phishing simulations, and targeted campaigns • Manage the lifecycle of security policies, standards, and procedures • Perform enterprise and third-party risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation • Track vulnerability remediation against SLAs • Respond to RFPs and security questionnaires • Support initiatives across GRC areas and foster collaboration and shared accountability

🎯 Requirements

• Bachelor’s degree in a relevant field or an equivalent of four years of experience is required • 5 years of professional experience in Information Security or related IT roles with security-related responsibilities • At least 2 years focused on Governance, Risk, and Compliance (GRC) functions • Experience leveraging AI-enabled tools to automate and enhance GRC processes preferred • One or more of CISSP, CRISC, CISA, or CISM certifications preferred • Ability to assess and document organizational risks, identify impacts, and recommend mitigation strategies • Ability to interpret and apply regulatory requirements and industry frameworks, including NIST, SOC 2, and HIPAA • Ability to analyze security, compliance, and risk metrics • Ability to communicate complex risk and compliance concepts to technical and non-technical stakeholders • Ability to collaborate across cross-functional teams • Exceptional time management skills • Excellent oral and written communication skills • Strong interpersonal and relationship-building skills • Ability to work with all levels of staff and management • Must be able to work Eastern Time business hours • Participation in on-call rotation is required for two weeks every 22 weeks • Sponsorship is not available for this role

🏖️ Benefits

• Remote, work-from-home position • Employee worker type • Opportunity to influence enterprise-wide decisions and advance a mature Data Governance program

Apply Now

Similar Jobs

🔥 4 hours ago

M&T Bank

10,000+ employees

🛡️ Insurance

💼 Consulting

🏦 Banking

Senior Risk Analyst overseeing interest-rate, market, liquidity, and regulatory reporting risks at M&T Bank. Conducting second-line reviews and presenting independent risk assessments.

🔥 11 hours ago

Alliant Insurance Services

10,000+ employees

🛡️ Insurance

🤝 B2B

💼 Consulting

Senior Corporate Risk Analyst managing corporate insurance programs, claims analysis, contracts, and renewal strategy. Supporting risk management operations through data analysis, negotiations, and cross-functional collaboration.

🇺🇸 United States – Remote

💰 $690M Debt Financing - Alliant Insurance Services on 2019-10

⏰ Full Time

🟠 Senior

🎲 Risk

🔥 18 hours ago

Relation Insurance Services

1001 - 5000

💼 Consulting

🏗️ Construction

🏥 Healthcare

Risk Advisor selling commercial insurance and expanding client accounts for Relation Insurance. Building pipelines, advising on risk, and transitioning sold clients to service teams.

🔥 18 hours ago

Mercury

1001 - 5000

💳 Fintech

🏦 Banking

☁️ SaaS

Senior Operational Risk Manager operating Mercury’s operational risk program for startup banking services. Building issues, events, controls, and Board reporting as Mercury prepares to operate as a bank.

🔥 19 hours ago

Avantor

10,000+ employees

🏥 Healthcare

🏭 Manufacturing

💼 Consulting

Senior Director leading Avantor’s global EHS3 governance, compliance, and sustainability strategy. Driving enterprise risk management, regulatory assurance, operational excellence, and organizational transformation.