Blue Cross and Blue Shield of Nebraska

Cybersecurity Controls Assurance & GRC Automation Analyst

Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, Risk Management, or equivalent experience.
  • 3-5 years in cybersecurity assurance, operations, or GRC.
  • Experience in cybersecurity control testing and security assessments.
  • Familiarity with cybersecurity frameworks like NIST and CIS Controls.
  • Ability to translate technical findings into actionable risk recommendations.

Responsibilities

  • Validate and strengthen cybersecurity controls in a regulated tech environment.
  • Conduct risk-based control assessments beyond basic compliance checks.
  • Utilize automated penetration testing tools and attack simulation platforms.
  • Support GRC processes with evidence collection and control testing.
  • Collaborate with cross-functional teams on audits and compliance activities.

Benefits

  • Remote flexibility with 1-2 days per week in the office.
  • Opportunities for travel to headquarters based on business needs.
  • Collaborative environment impacting healthcare technology.
  • Focus on strengthening cybersecurity to protect communities.
Full Job Description
In this role, you will help shape how BCBSNE validates, measures, and strengthens cybersecurity controls across a modern, highly regulated technology environment. You will perform risk-based control assessments that go beyond checklist complianceevaluating whether controls are well designed, properly implemented, operating effectively, and supported by strong evidence. Your work will connect technical security testing with practical risk insight, helping the organization understand where defenses are strong, where gaps exist, and how to prioritize meaningful improvements.

The ideal candidate will live within driving distance of the Omaha, Nebraska office. This position allows remote flexibility but will have 1-2 days per week in the office.


If living in one of our approved states (Florida, Iowa, Kansas, Minnesota, Missouri, Nebraska, North Dakota, and Texas)  this person may travel to our headquarters based on business needs.


You will work hands-on with emerging, automated penetration testing and attack simulation platforms, and with cloud, identity, endpoint, network, infrastructure, application, vulnerability management, and data-protection systems to validate security posture, identify misconfigurations and control failures, assess attack paths, and recommend practical remediation. You will also support GRC and continuous-control-monitoring capabilities, including automated evidence collection, control testing, remediation tracking, risk management processes, dashboards, metrics, and reporting that make cybersecurity risk easier to see, explain, and act on.


This is an opportunity for a cyber/GRC analyst who enjoys bridging technical exploration with governance impact. You will partner with cybersecurity, technology, risk, audit, and business teams to investigate issues, support audits and regulatory reviews, participate in approved validation activities such as configuration testing, vulnerability and exploitability validation, attack-path analysis, and purple-team exercises, and help turn findings into improvements that strengthen BCBSNEs cyber resilience and protect the members and communities we serve.


To be considered for this position you must have:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or related field, or equivalent experience.
  • Three to five years of experience in cybersecurity assurance, security operations, cybersecurity engineering, penetration testing, IT audit, GRC, risk management, or related experience.
  • Experience performing cybersecurity control testing, technical assessments, configuration reviews, vulnerability validation, or security assessments.
  • Working knowledge of cybersecurity frameworks such as NIST, CIS Controls, HITRUST, HIPAA, or ISO 27001.
  • Experience interpreting technical evidence and translating cybersecurity findings into practical risk and remediation recommendations.

The strongest candidates will also have:

  • Experience with GRC or continuous-control-monitoring processes platforms.
  • Experience with penetration testing, red/purple teaming, attack-path analysis, or adversary-informed testing.
  • Knowledge of MITRE ATT&CK and cloud, identity, network, and endpoint security concepts.
  • Experience in healthcare, financial services, or another highly regulated industry.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, Security+, OSCP, or similar.
  • Experience developing or improving cyber risk metrics, GRC dashboards, or executive-ready reporting.
  • Comfort using automation, scripting, or workflow tools to streamline evidence collection, control testing, or remediation tracking.
  • Ability to communicate technical cybersecurity issues clearly to both technical teams and non-technical stakeholders.

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Other duties may be assigned.


Ready to make an impact? Join a team where your skills, attitude, and ideas are valuedand where youll help shape the future of healthcare technology.

About Blue Cross and Blue Shield of Nebraska

Blue Cross and Blue Shield of Nebraska (BCBSNE) is a non-profit health insurance company headquartered in Omaha, Nebraska. The company provides health insurance coverage to individuals, families, and businesses in Nebraska. BCBSNE offers a variety of health insurance plans, including individual and family plans, Medicare supplement plans, and employer group plans. The company was founded in 1939 and has since grown to over 800 employees.
Learn more about Blue Cross and Blue Shield of Nebraska
Size
800 employees
Industry
Founded
1939

Similar Jobs

More Jobs at Blue Cross and Blue Shield of Nebraska

More Healthcare Jobs

Find similar Cybersecurity Controls Assurance & GRC Automation Analyst jobs: