Blue Cross Blue Shield of Rhode Island

Information Security Analyst

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, or related fields preferred; or an equivalent combination of high school education and industry experience.
  • 3+ years of experience in vendor management, third-party risk management, or enhanced vendor oversight.
  • Experience evaluating technology risks related to AI and emerging technologies is desired.
  • Certifications like CISSP, CISA, or CRISC are preferred but not mandatory.
  • Advanced knowledge of Microsoft Office tools.

Responsibilities

  • Conduct security and risk assessments for third-party vendors and AI solutions to identify vulnerabilities.
  • Collaborate with stakeholders to align third-party practices with organizational policies and regulatory standards.
  • Review and analyze security certifications and documentation to assess vendor risk.
  • Maintain inventories and documentation related to vendor and AI risk management.
  • Evaluate vendor controls for compliance with cybersecurity and data protection standards.
  • Provide recommendations for risk mitigation and support remediation efforts.
  • Stay informed on industry threats, best practices, and regulatory changes related to third-party and AI security.

Benefits

  • Flexible work schedules: in-office, hybrid, or remote options.
  • Support for associate well-being and work/life balance.
  • Convenient location near public transportation in downtown Providence.
Full Job Description
Pay Range:
$83,200.00 - $124,800.00
Please email if you are a candidate seeking a reasonable accommodation for the application and/or interview process.

Why this job matters:

Blue Cross & Blue Shield of Rhode Island is seeking an innovative and detail-oriented security professional to join its Information Security team. This role is responsible for assessing, monitoring, and mitigating security, privacy, compliance, and operational risks associated with third-party vendors, delegates, and AI-enabled solutions. The successful candidate will support the organization's Enhanced Vendor Oversight (EVO) and AI governance programs by conducting risk assessments, reviewing vendor controls and AI use cases, communicating risk findings to stakeholders, supporting remediation efforts, and helping ensure alignment with organizational policies, regulatory requirements, and industry best practices.

What you Will Do:
  • Conduct security, privacy, and risk assessments of third-party vendors, delegates, and AI-enabled solutions to identify potential risks and vulnerabilities.
  • Collaborate with business and technology stakeholders to ensure third-party and AI-related practices align with organizational policies, regulatory requirements, and governance standards.
  • Review and analyze security attestations, certifications, and supporting documentation (e.g., SOC 2, HITRUST, ISO certifications) to assess vendor risk.
  • Maintain vendor and AI risk inventories, portfolios, engagement records, risk assessments, and related documentation.
  • Evaluate third-party and AI vendor controls related to cybersecurity, data protection, privacy, regulatory compliance, model governance, and secure development practices.
  • Provide risk mitigation recommendations and support remediation activities to improve vendor and AI security posture.
  • Support implementation and monitoring of Enhanced Vendor Oversight (EVO), AI governance requirements, standards, and risk management processes.
  • Stay informed on emerging threats, industry best practices, regulatory developments, and evolving risks related to third-party security, AI, and technology governance.


What you need to succeed:
  • Preferred: Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, or similar areas of study from an accredited college or university. OR
  • a high school diploma combined with strong industry experience and/or candidates currently enrolled in a bachelor's degree program will be considered.
  • 3+ years of relevant industry experience ideally focused in vendor management, third-party risk management, or related enhanced vendor oversight tasks.
  • Experience evaluating technology, cybersecurity, privacy, or third-party risks associated with Artificial Intelligence (AI), machine learning, generative AI, or emerging technologies is preferred.
  • Relevant certifications are preferred, such as CISSP, CISA, CRISC, or equivalent, but are not required.


The Extras:
  • Advanced knowledge of Microsoft Office; including Outlook, Word, Excel, and PowerPoint.
  • Understanding of Artificial Intelligence (AI), Machine Learning (ML), Generative AI, and related technology risks.
  • Knowledge of AI governance frameworks and industry best practices.
  • Familiarity with the NIST Artificial Intelligence Risk Management Framework (NIST AI RMF).
  • Familiarity with ISO/IEC 42001 Artificial Intelligence Management Systems (AIMS).
  • Understanding of AI-related regulatory, privacy, security, and ethical considerations.
  • Experience reviewing AI vendor security questionnaires, AI governance documentation, AI model risk documentation, or AI-related control environments.
  • Strong analytical and organizational skills.
  • Effective oral and written communication skills.
  • Must be a self-driven, team player.
  • Ability to work independently and as part of a team.
  • Knowledge of healthcare industry regulations and standards is a plus.

Location:
BCBSRI is headquartered in downtown Providence, conveniently located near the train station and bus terminal. We actively support associate well-being and work/life balance and offer the following schedules, based on role:
  • In-office: onsite 5 days per week
  • Hybrid: onsite 2-4 days per week
  • Remote: onsite 0-1 days per week. Permitted to reside in the following states, pending approval from the Human Resources Department: Arizona, Connecticut, Florida, Georgia, Louisiana, Massachusetts, North Carolina, Oklahoma, Rhode Island, South Carolina, Texas, Virginia

About Blue Cross Blue Shield of Rhode Island

Blue Cross Blue Shield of Rhode Island is a non-profit health insurance company that provides medical, dental, and vision coverage to individuals and businesses in Rhode Island. The company also offers Medicare Advantage plans and prescription drug coverage. Blue Cross Blue Shield of Rhode Island was founded in 1939 and is headquartered in Providence, Rhode Island.
Learn more about Blue Cross Blue Shield of Rhode Island
Size
800 employees
Industry
Founded
1939

Similar Jobs

More Jobs at Blue Cross Blue Shield of Rhode Island

More Information Technology Jobs

Find similar Information Security Analyst jobs: