Blue Shield Of California

Information Security Risk and Governance Specialist, Consultant

Blue Shield Of California • $110K — $130K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience required
  • 7+ years of relevant experience in information security
  • Familiarity with security assurance frameworks like NIST, HIPAA, and SOC 2
  • Experience liaising with auditors and explaining technical concepts
  • Strong communication skills for both technical and non-technical audiences
  • Exceptional organizational skills and attention to detail
  • Proven project management capabilities

Responsibilities

  • Maintain GRC systems and control repositories for accurate information
  • Develop and enhance dashboards for security risk reporting
  • Support governance processes for technology and application visibility
  • Collaborate with tech teams to integrate security into the technology lifecycle
  • Coordinate responses for audits and regulatory assessments
  • Facilitate security risk assessments and monitor open risks
  • Perform control self-assessments and track remediation efforts

Benefits

  • Flexible workplace model with in-office collaboration two days a week
  • Commitment to reasonable accommodations for employees with medical conditions
  • Focus on continuous improvement and professional development
  • Encouragement of a team culture that values accountability and data-driven decisions
  • Engagement in a supportive environment that fosters innovation and creativity
Full Job Description
Job Description

Your Role

The Information Security Team is seeking an Information Security Risk and Governance Specialist. In this role, you will be supporting Stellarus by helping translate regulatory, contractual, policy, and security requirements into sustainable and measurable governance and control practices.

Stellarus recognizes that IT Services are crucial, strategic, organizational assets and therefore we must invest appropriate levels of resource into the support, delivery and management of these critical IT Services and the IT systems that underpin them.

This position has responsivities within the Information Security Compliance organization, for maturing the Compliance function, ensuring IT audit-readiness with policy, regulations and control standards.

Responsibilities

Your Work
In this role, you will:

GRC Program Operations & Reporting
  • Maintain accurate information within GRC systems, control repositories, risk registers, policy repositories, and assurance trackers.
  • Contribute to the development and maintenance of dashboards and reporting regarding security risks, control performance, exceptions, audit activity, findings, and remediation.
  • Support development and continuous improvement of GRC processes, methodologies, templates, procedures, and operating standards.

Application & Technology Governance
  • Support governance processes that establish visibility into applications, systems, infrastructure, data environments, and technology services subject to security requirements.
  • Partner with technology teams to incorporate security governance requirements into the technology lifecycle, including implementation, material changes, and retirement.
  • Maintain mappings between applications/technology assets and applicable risks, controls, owners, frameworks, and evidence.
  • Assist in determining which applications and technology components are in scope for applicable regulatory and assurance frameworks.

Audit & Assessment Support
  • Serve as a liaison between internal/external auditors/assessors and internal control owners.
  • Coordinate information security evidence and responses for internal audits, external audits, customer assessments, regulatory reviews, and certification activities.
  • Maintain organized, reusable evidence repositories to reduce duplicative requests and audit fatigue.
  • Support readiness activities associated with SOC 2, NIST, HIPAA, HITRUST, and other applicable assessments.

Information Security Risk Management
  • Support information security risk management program, including identification, assessment, documentation, treatment, monitoring, and reporting of technology and cybersecurity risks.
  • Support development of security risk metrics, key risk indicators, dashboards, and management reporting.
  • Monitor open risks, exceptions, findings, and remediation commitments and facilitate escalation of overdue or high-risk items.
  • Facilitate security risk assessments for systems, applications, technologies, business processes, and organizational changes.
  • Maintain security risk assessments for systems, applications, technologies, business processes, and organizational changes.

Control Assurance & Monitoring
  • Perform or coordinate control self-assessments and evidence reviews.
  • Evaluate whether controls are appropriately designed, implemented, documented, and supported by sufficient evidence.
  • Track findings and remediation through closure and validate supporting evidence when appropriate.
  • Identify control gaps and work with control owners to establish corrective action plans.


Qualifications

Your Knowledge and Experience
  • Requires a bachelor's degree or equivalent experience
  • Requires at least 7 years of prior relevant experience
  • Understanding of and experience working with security assurance and trust frameworks (in particular NIST, HIPAA and SOC 2)
  • Experience interacting with internal/external auditors and explaining technical concepts
  • Ability to communicate effectively with customers and internal teams
  • Superior organizational skills, extraordinary attention to detail, and an agile mindset that processes can always be improved
  • Proven ability to manage projects and deliverables to completion
  • Ability to understand and contextualize complex technical concepts into terms readily understandable by a non-technical audience
  • Satisfactory knowledge and skills including technical or functional expertise, business acumen and financial analysis skills, risk management, critical thinking and decision-making skills.
  • Intermediate understanding of healthcare information security governance, risk, and compliance practices
  • Ability to learn and understand Stellarus' security controls and to maintain a security knowledge base that can be used for multiple projects

Additionally, candidate must be able to:
  • Demonstrate personal commitment to change through actions and words, and mobilize others to support change through times of stress and uncertainty
  • Foster a team culture of continuous improvement, mentoring and learning, data driven decisions, and accountability for delivery of key metrics and deliverables
  • Breakdown raw information and undefined problems into specific, workable components that in-turn clearly identifies the issues at hand
  • Make logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision-making process
  • Improve organizational performance though the application of original thinking to existing and emerging methods, processes, products and services


#LI-FB1

Our Values:

At Stellarus, our core values of agility, trust, drive, courage and service shape our approach to developing innovative product offerings.

Our Workplace Model:

We believe in fostering a workplace environment that balances purposeful in-person collaboration with flexibility - providing clear expectations while respecting the diverse needs of our workforce. Our workplace model is designed around intentional in-person interaction, collaboration, connection, creativity and flexibility:
  • For most teams, this means coming into the office two days per week.
  • Employees living more than 50 miles from an office location, out of state employees, and employees in certain member-facing roles should work with their manager to determine in-office time based on business need.
  • For employees with medical conditions that may impact their ability to work in-office, we are committed to engaging in an interactive process and providing reasonable accommodations to ensure their work environment is conducive to their success and well-being.

The Company reserves the right to require more presence in the office based on business needs, and requirements are subject to change with periodic reviews.

Physical Requirements:

Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.

Please click here for further physical requirement detail.

About Blue Shield Of California

Blue Shield of California is a not-for-profit health plan provider that has been providing Californians with access to high-quality healthcare for over 80 years. The company offers a range of health insurance products and services to individuals, families, and employers. Blue Shield of California is committed to improving the health and wellbeing of its members and the communities it serves. The company is also committed to sustainability and has implemented a number of initiatives to reduce its environmental impact.
Learn more about Blue Shield Of California
Size
7,000 employees
Industry
Founded
1981

Similar Jobs

More Jobs at Blue Shield Of California

More Healthcare Jobs

Find similar Information Security Risk and Governance Specialist, Consultant jobs: