Blue Shield Of California

Information Security Risk and Governance Specialist, Consultant

Blue Shield Of California$100K — $130K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience
  • 7+ years of relevant experience
  • Healthcare, pharmaceutical, or biotechnology industry experience
  • CISSP-ISSAP, Red team, and Certified Ethical Hacker certifications preferred
  • Familiarity with governance frameworks such as COBIT, HIPAA, and NIST
  • Experience in governance, risk, and compliance (GRC) is essential
  • Strong communication and executive presentation skills

Responsibilities

  • Participate in technology risk governance activities
  • Develop and implement technology governance programs
  • Assess AI tools and enhance AI risk management
  • Implement strategic goals set by BSC leadership
  • Conduct third-party security risk assessments
  • Enhance training and awareness for business teams
  • Partner with cross-functional teams to operationalize IT risk management framework
  • Lead the development of reporting processes for stakeholders

Benefits

  • Hybrid work model with in-office collaboration
  • Flexible work arrangements based on individual needs
  • Commitment to reasonable accommodations for medical conditions
  • Engaging workplace culture with a focus on collaboration
  • Potential for increased in-office presence based on business needs
Full Job Description
Job Description

Your Role

The Technology and Data Trust Assurance Services team drives BSC technology and information security adherence to regulatory standards, as well as policies, standards, and controls development, with the goal of evaluating, directing and monitoring IT vendor performance, while safeguarding company assets and maintaining and securing the confidentiality, integrity, and availability of Blue Shield of California data. The Technology Risk and External Assurance program runs technology governance forums and manages technology risk from identification to risk consequence management for BSC. The Information Security Risk & Governance Specialist, Consultant will report to the Senior Manager, Technology Risk Assurance. In this role, you will be a key individual contributor to the Technology Risk and External Assurance team and Blue Shield's overall strategy and goals by providing consistent, coordinated technology governance, information security oversight, AI governance, technology risk assessment, and risk reporting in partnership with leaders, stakeholders, and Stellarus.

Responsibilities

Your Work

In this role, you will:

  • Participate in technology risk governance activities (e.g., committees, presentation preparations, training and awareness, etc.)
  • Develop and implement technology governance programs, including technical performance oversight, AI governance, and data exchange and third-party risk governance that will help BSC understand its inherent and residual risk exposure
  • Assess AI tools, techniques, and procedures to enhance AI risk management capabilities throughout the company
  • Implement strategic goals established by BSC leadership
  • Be responsible for third-party security risk assessment activities ensuring Blue Shield's data is stored, transmitted, and processed in a secure manner
  • Enhance and conduct training and awareness activities to business teams and applicable third parties
  • Partner with cross functional operational business partners including Customer Experience, Customer Care, Markets, Health Solutions and Enterprise Risk Management to operationalize and socialize the IT risk management framework and program and to identify shifts in the organization's implicit risk appetite.
  • Lead and support the development of reporting processes to communicate progress of in-flight initiatives, risks and planned initiatives to senior executives and stakeholders in other business units


Qualifications

Your Knowledge and Experience

  • Requires a bachelor's degree or equivalent experience
  • Requires at least 7 years of prior relevant experience
  • Previous experience working in the healthcare, pharmaceutical, biotechnology or related services industry is required
  • CISSP-ISSAP preferred
  • Red team experience preferred
  • Certified Ethical Hacker preferred
  • Knowledge of various information technology governance and control frameworks and industry standards such as COBIT, COSO, ITIL, PMBOK, HIPAA, and NIST are required
  • Knowledge of Artificial Intelligence (AI) governance and monitoring practices is preferred
  • Demonstrated experience as a governance, risk and compliance (GRC) expert is required
  • Requires business acumen, strategic thinking, financial analytical skills, and decision-making skills
  • Excellent communication and presentation skills at every level including executives is required
  • Experience working with healthcare partner and vendor contracts and understanding of the key components of basic agreements and how legal terms impact business terms and vice versa is preferred.


Hybrid

This role requires employees to be in - office based on our hybrid workplace model, balancing purposeful in - person collaboration with flexibility. For most teams, this means coming into the office two days each week.

Employees living more than 50 miles from an office location will work with their manager to determine in-office time based on business need.

#LI-CP4

Our Workplace Model

We believe in fostering a workplace environment that balances purposeful in-person collaboration with flexibility - providing clear expectations while respecting the diverse needs of our workforce. Our workplace model is designed around intentional in-person interaction, collaboration, connection, creativity and flexibility:
  • For most teams, this means coming into the office two days per week.
  • Employees living more than 50 miles from an office location, out of state employees, and employees in certain member-facing roles should work with their manager to determine in-office time based on business need.
  • For employees with medical conditions that may impact their ability to work in-office, we are committed to engaging in an interactive process and providing reasonable accommodations to ensure their work environment is conducive to their success and well-being.

The Company reserves the right to require more presence in the office based on business needs, and requirements are subject to change with periodic reviews.

Physical Requirements:

Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.

Please click here for further physical requirement detail.

About Blue Shield Of California

Blue Shield of California is a not-for-profit health plan provider that has been providing Californians with access to high-quality healthcare for over 80 years. The company offers a range of health insurance products and services to individuals, families, and employers. Blue Shield of California is committed to improving the health and wellbeing of its members and the communities it serves. The company is also committed to sustainability and has implemented a number of initiatives to reduce its environmental impact.
Learn more about Blue Shield Of California
Size
7,000 employees
Industry
Founded
1981

Similar Jobs

More Jobs at Blue Shield Of California

More Healthcare Jobs

Find similar Information Security Risk and Governance Specialist, Consultant jobs: