Blue Shield Of California

Information Security Risk and Governance Specialist, Consultant

Blue Shield Of California • $110K — $130K *
Lodi, CA 95240In-Person
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience required
  • Minimum of 7 years relevant experience in information security
  • Familiarity with security assurance frameworks like NIST, HIPAA, and SOC 2
  • Experience with internal/external audits and technical communication
  • Strong organizational skills and attention to detail
  • Proven project management capabilities
  • Intermediate knowledge of healthcare information security governance

Responsibilities

  • Maintain GRC systems and control repositories for accurate information
  • Develop and maintain dashboards for security risks and audit activities
  • Support governance processes for technology services and applications
  • Collaborate with technology teams to integrate security requirements
  • Coordinate responses for audits and regulatory reviews
  • Monitor and report on cybersecurity risks and remediation efforts
  • Perform control self-assessments and track findings for closure

Benefits

  • Opportunity to work in a strategic IT environment
  • Focus on continuous improvement and professional development
  • Collaborative team culture fostering mentorship and learning
  • Engagement with diverse regulatory frameworks
  • Flexible work environment with options for remote work
Full Job Description
Job Description

Your Role

The Information Security Team is seeking an Information Security Risk and Governance Specialist. In this role, you will be supporting Stellarus by helping translate regulatory, contractual, policy, and security requirements into sustainable and measurable governance and control practices.

Stellarus recognizes that IT Services are crucial, strategic, organizational assets and therefore we must invest appropriate levels of resource into the support, delivery and management of these critical IT Services and the IT systems that underpin them.

This position has responsivities within the Information Security Compliance organization, for maturing the Compliance function, ensuring IT audit-readiness with policy, regulations and control standards.

Responsibilities

Your Work
In this role, you will:

GRC Program Operations & Reporting
  • Maintain accurate information within GRC systems, control repositories, risk registers, policy repositories, and assurance trackers.
  • Contribute to the development and maintenance of dashboards and reporting regarding security risks, control performance, exceptions, audit activity, findings, and remediation.
  • Support development and continuous improvement of GRC processes, methodologies, templates, procedures, and operating standards.

Application & Technology Governance
  • Support governance processes that establish visibility into applications, systems, infrastructure, data environments, and technology services subject to security requirements.
  • Partner with technology teams to incorporate security governance requirements into the technology lifecycle, including implementation, material changes, and retirement.
  • Maintain mappings between applications/technology assets and applicable risks, controls, owners, frameworks, and evidence.
  • Assist in determining which applications and technology components are in scope for applicable regulatory and assurance frameworks.

Audit & Assessment Support
  • Serve as a liaison between internal/external auditors/assessors and internal control owners.
  • Coordinate information security evidence and responses for internal audits, external audits, customer assessments, regulatory reviews, and certification activities.
  • Maintain organized, reusable evidence repositories to reduce duplicative requests and audit fatigue.
  • Support readiness activities associated with SOC 2, NIST, HIPAA, HITRUST, and other applicable assessments.

Information Security Risk Management
  • Support information security risk management program, including identification, assessment, documentation, treatment, monitoring, and reporting of technology and cybersecurity risks.
  • Support development of security risk metrics, key risk indicators, dashboards, and management reporting.
  • Monitor open risks, exceptions, findings, and remediation commitments and facilitate escalation of overdue or high-risk items.
  • Facilitate security risk assessments for systems, applications, technologies, business processes, and organizational changes.
  • Maintain security risk assessments for systems, applications, technologies, business processes, and organizational changes.

Control Assurance & Monitoring
  • Perform or coordinate control self-assessments and evidence reviews.
  • Evaluate whether controls are appropriately designed, implemented, documented, and supported by sufficient evidence.
  • Track findings and remediation through closure and validate supporting evidence when appropriate.
  • Identify control gaps and work with control owners to establish corrective action plans.


Qualifications

Your Knowledge and Experience
  • Requires a bachelor's degree or equivalent experience
  • Requires at least 7 years of prior relevant experience
  • Understanding of and experience working with security assurance and trust frameworks (in particular NIST, HIPAA and SOC 2)
  • Experience interacting with internal/external auditors and explaining technical concepts
  • Ability to communicate effectively with customers and internal teams
  • Superior organizational skills, extraordinary attention to detail, and an agile mindset that processes can always be improved
  • Proven ability to manage projects and deliverables to completion
  • Ability to understand and contextualize complex technical concepts into terms readily understandable by a non-technical audience
  • Satisfactory knowledge and skills including technical or functional expertise, business acumen and financial analysis skills, risk management, critical thinking and decision-making skills.
  • Intermediate understanding of healthcare information security governance, risk, and compliance practices
  • Ability to learn and understand Stellarus' security controls and to maintain a security knowledge base that can be used for multiple projects

Additionally, candidate must be able to:
  • Demonstrate personal commitment to change through actions and words, and mobilize others to support change through times of stress and uncertainty
  • Foster a team culture of continuous improvement, mentoring and learning, data driven decisions, and accountability for delivery of key metrics and deliverables
  • Breakdown raw information and undefined problems into specific, workable components that in-turn clearly identifies the issues at hand
  • Make logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision-making process
  • Improve organizational performance though the application of original thinking to existing and emerging methods, processes, products and services


#LI-FB1

Physical Requirements:

Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.

Please click here for further physical requirement detail.

About Blue Shield Of California

Blue Shield of California is a not-for-profit health plan provider that has been providing Californians with access to high-quality healthcare for over 80 years. The company offers a range of health insurance products and services to individuals, families, and employers. Blue Shield of California is committed to improving the health and wellbeing of its members and the communities it serves. The company is also committed to sustainability and has implemented a number of initiatives to reduce its environmental impact.
Learn more about Blue Shield Of California
Size
7,000 employees
Industry
Founded
1981

Similar Jobs

More Jobs at Blue Shield Of California

More Healthcare Jobs

Find similar Information Security Risk and Governance Specialist, Consultant jobs: