BlueCross BlueShield of South Carolina

IS Security Risk Analyst III

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a related field or equivalent work experience.
  • 6 years of I/T experience including 4 years in IT security, risk assessment or compliance.
  • Strong understanding of Systems Development Life Cycle methodologies.
  • Expertise in government or private risk frameworks and controls.
  • Excellent analytical skills and ability to interpret regulatory requirements.

Responsibilities

  • Monitor remediation of compliance issues and report on compliance posture.
  • Conduct formal risk analyses and self-assessments independently.
  • Facilitate the development and documentation of security policies and procedures.
  • Serve as an interface with external entities for compliance reviews.
  • Investigate and document Information Security Incidents, advising senior management on critical issues.

Benefits

  • Subsidized health, dental, and vision coverage.
  • 401K with company match.
  • Life insurance.
  • Paid Time Off (PTO) and nine paid holidays.
  • Education assistance and service recognition programs.
Full Job Description

Description

Position Purpose:

Plan and perform compliance and risk assessment activities for information systems and related processes.  Communicate and escalate compliance and risk issues to the appropriate department and/or level of management.  Act as a change agent to influence the I/S and corporate compliance culture.

This position requires a security clearance which requires U.S. Citizenship to obtain.

Sponsorship: This position is not eligible for sponsorship now or in the future. 

What You Will Do:

  • Independently monitor remediation of new and outstanding issues, including Information Security Risk Exception process, to ensure identification of areas of non-compliance. Utilize tools to track and report on compliance posture.
  • Independently conduct formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks.
  • Facilitate development, implementation and documentation of Information Security policies, procedures, processes and programs to guide organization toward continuous compliance. Independently analyze and interpret security regulations and controls to advise on security compliance at a broad perspective across multiple business areas. Consult on organizational impacts of compliance and risk management decisions.
  • Serve as an interface with external entities for governance and compliance reviews regarding information security risk across multiple business areas and controls.
  • Independently investigate, document and resolve Information Security Incidents. Advise senior management of critical issues that may affect organization.
  • Research emerging security topics, threats and capabilities to create/update policy and governance. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices.


Required Education:

  • Bachelor's in a job related field
  • Or an additional 4 years job related work experience
  • Or Associate's plus an additional 2 years job related work experience


Required Work Experience:

  • 6 years of I/T experience including 4 years of IT security, risk assessment and/or compliance experience. Successful completion of BCBSSC I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.


Required Skills and Abilities:

  • Good understanding of Systems Development Life Cycle methodologies.
  • Subject Matter Expert in government or private risk frameworks and control implementations.
  • Good understanding of risk management, information system security and compliance standards.
  • Excellent analytical and decision-making skills.
  • Proven ability to interpret and apply knowledge of regulatory/accreditation requirements.
  • Ability to independently solve problems often spanning multiple environments and business areas.
  • Ability to effect change and bring security, risk and compliance knowledge to the organization through the use of positive influence.
  • Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols.
  • Strong communication skills in presenting results both verbally and in writing.
  • Possess excellent collaboration skills with a wide variety of internal matrix and management staff.


Required Software and Other Tools: Standard office equipment.

We Prefer That You Have:

  • Experience with NIST, FISMA, HIPAA, or other regulatory requirements. 
  • Knowledge of technical security controls from NIST, DISA, USGCB, etc. compliance domains across multiple platforms. 
  • Deep understanding of security risk exposures and how vulnerabilities can be translated into business risk that leadership understands. 
  • Ability to analyze, trend and forecast from high volumes of compliance data. 
  • Experience with compliance programs within a government agency (i.e. Medicare, Tricare) is preferred. 
  • Direct experience with NIST 800-53 security frameworks.
  • Experience with DoD, DIARMF or FedRamp program is a plus.

Preferred Licenses and Certificates:

  • ISACA Certified Information Security Manager (CISM)
  • Comptia Security +
  • ISC2 SSCP (System Security Certified Practitioner)
  • CompTIA Cybersecurity Analyst+ (CySA+)


Work Environment: Fast paced, multi-platformed environment which may require action and response 24X7 to support the technical business needs of the customer.

What We Can Do for You:

We offer our employees great benefits and rewards.  You will be eligible to participate in our benefits program the first of the month following 28 days of employment.  

Our comprehensive benefits package includes:

  • Subsidized health plans, dental and vision coverage

  • 401K retirement savings plan with company match

  • Life Insurance

  • Paid Time Off (PTO)

  • Nine paid holidays

  • On-site cafeterias and fitness centers in major locations

  • Education Assistance

  • Service recognition

  • National discounts to movies, theaters, zoos, theme parks and more

About BlueCross BlueShield of South Carolina

BlueCross BlueShield of South Carolina is a health insurance company that provides coverage to over 5 million people in South Carolina and beyond. The company was founded in 1946 and is headquartered in Columbia, South Carolina. BlueCross BlueShield of South Carolina offers a variety of health insurance plans, including individual and family plans, Medicare plans, and employer-sponsored plans. The company is committed to improving the health of its members and the communities it serves, with initiatives focused on wellness, disease prevention, and access to care. BlueCross BlueShield of South Carolina is a subsidiary of the Blue Cross Blue Shield Association, a national federation of 36 independent, community-based and locally operated Blue Cross Blue Shield companies.
Learn more about BlueCross BlueShield of South Carolina
Size
12,000 employees
Industry

Similar Jobs

More Jobs at BlueCross BlueShield of South Carolina

More Information Technology Jobs

Find similar IS Security Risk Analyst III jobs: