Blue Cross and Blue Shield Association

Senior Cybersecurity Compliance Lead Consultant

Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Information Security, Risk Management, or related field; or equivalent experience
  • 10+ years of experience in IT or a closely related field
  • Experience with automation and AI in compliance monitoring
  • Strong understanding of regulatory frameworks like NIST, ISO, HIPAA/HITECH
  • Expertise in FedRAMP requirements and continuous monitoring practices
  • Demonstrated leadership and project management skills
  • Familiarity with generative AI tools and their business applications

Responsibilities

  • Lead the development of cyber risk management processes
  • Utilize analytical approaches to assess and mitigate cyber risks
  • Assist in risk-informed decision-making for the cybersecurity program
  • Oversee FedRAMP compliance strategy and AI-enabled risk control implementation
  • Communicate risk assessments to both technical and non-technical teams
  • Maintain a risk register aligning security findings with business objectives
  • Manage multiple projects and deliverables effectively

Benefits

  • Paid time off and 11 holidays
  • Medical, dental, and vision insurance
  • Generous 401(k) matching plan
  • Lifestyle spending account
  • Additional comprehensive benefits for eligible employees.
Full Job Description
This role will:
- Lead the creation and deployment of defined and structured processes to support evolving and maintaining the cyber risk management program. Work across the BCBSA organization to align cyber risk management with the organization's goals and outcomes.
-Utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies.
-Apply experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance.
-Support IT and information security leadership in making risk informed decisions and shaping the future direction of BCBSA's cybersecurity program.
-Assess internal and third-party supplier risks, realistically translate them for both technical and non-technical audiences, and clearly articulate recommended actions and organizational impact.

Specifically, this role will lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations.

  • Responsible for providing Cyber Risk leadership and subject matter expertise on all assigned projects. Responsible for identifying day-to-day task assignments and providing technology and project management guidance on deliverables. Validates and ensures Cyber Risk requirements are thorough, testable, detailed, concise and traceable. Accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders.
  • Responsible for project planning, budget approvals, estimation and management for all project deliverables, collaborates with Service Delivery managers as appropriate. Proficient in implementing cyber risk processes, leads teams to attain goals, pursue excellence and establish discipline specific best-practices. Responsible for driving all project decisions, strong ability to make timely decisions and establish project governance. Collaborates with other team-members, peers and builds trust, exhibits sense of urgency, biased for action and possesses good follow-up skills. Customer focused with ability to persuade and drive consensus to resolve conflict and facilitate timely decision making.
  • Reviews and approves team progress reports, expenses, invoices and contracts in a thorough and timely manner. Reviews the status reports of team members and addresses issues as appropriate. Complies with and helps to enforce standard policies and procedures. Provides and seeks timely feedback to IT partners, peers and team-members.
  • Provides leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focused on continuous improvement. Provides project team(s) business/technical leadership and guidance on day-to-day tasks. Responsible for driving change for implementing process improvements and ensuring long term compliance. Leads the creation and maintenance of methodologies and processes for the department. Expected to lead multiple, simultaneous projects and time-critical deliverables.
  • Maintains a formal risk register that drives security, governance and ensures security findings are aligned with business objectives.
  • Responsible for maintaining positive working relationships with all groups, cross-functional teams, including technical. Identifies opportunities/needs and works with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure.
  • Provides budget forecasts and estimates for Cyber Risk activities on a continuous basis. Responsible for variance analysis and justifications and following the established BCBSA processes/procedures.
  • Responsible for providing status updates to Senior/Executive management. Responsible for escalating risks/issues with customer issues appropriately and in a timely manner. Ensures design, development, testing and investigative activities lead to appropriate resolution.
  • Effectively and tactfully communicates relevant and potentially difficult/sensitive information to senior management.
  • Responsible for engaging, understanding and effectively communicating needs of business to IT teams/partners
  • Resolves and/or escalates issues, proposes alternatives, and sets or manages expectations in a timely fashion.
  • Responsible for leading and managing delivery on multiple projects and responsible for all project related resource management, task-prioritization and development. Frequent Plan interactions via System Advisory Group or project communications to ensure business solutions meet Plan needs and implementation/budget concerns are understood. Frequent project participation/collaboration to ensure technical solutions meet business needs.

The posting range for this position is:

157,600.00 - 228,550.00


Qualifications:

Education

  • Required Bachelor's Degree IT, information Security, Risk or IT Management, Computer Science, or a related field; or equivalent work experience

Experience

  • Required 10+ Years career experience in IT or a closely related field
  • Experience leveraging automation and AI-enabled solutions to improve compliance monitoring, reporting, and operational efficiency.


Knowledge Skills and Abilities

  • Knowledge of national and international regulatory and compliance frameworks such as NIST Cybersecurity Framework, ISO 27001, EU DPD, HIPAA/HITECH.
  • Extensive knowledge in the use of Project Management methodologies and tools, and change management techniques.
  • Demonstrated leadership, mentoring, and project management skills.
  • Understanding of current application cyber risk development methodologies and risks, researching emerging technologies and possible application to the business.
  • Deep knowledge of FedRAMP requirements, continuous monitoring practices, control implementation, evidence management, and audit readiness.
  • Strong understanding of NIST cybersecurity frameworks, risk management, cloud security, and regulatory compliance obligations.
  • Ability to translate complex compliance requirements into scalable, business-integrated processes and controls.
  • Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.

The posted salary range is the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting.  We may ultimately pay more or less than the hiring range andthis hiring range may also be modified in the future. A candidate’s position within the hiring range may be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, relevant experience, skills, seniority, performance, shift, travel requirements, and business or organizational needs.This job is also eligible for annual bonusincentive pay.

We offer a comprehensive package of benefits including paid time off, 11 holidays,medical/dental/vision insurance, generous 401(k) matching, lifestyle spending account and many other benefits to eligible employees.

About Blue Cross and Blue Shield Association

The Blue Cross Blue Shield Association (BCBSA) is a federation of 36 separate United States health insurance companies that provide health insurance in the United States to more than 106 million people. It was formed in 1982 from the merger of its two namesake organizations: Blue Cross was founded in 1929 and became the Blue Cross Association in 1960, while Blue Shield emerged in 1939 and the Blue Shield Association was created in 1948. The Blue Cross Blue Shield Association is headquartered in Chicago and has offices in Washington, D.C. The association provides health insurance products and services to more than 106 million Americans.
Learn more about Blue Cross and Blue Shield Association
Size
1,000 employees
Industry
Founded
1929

Similar Jobs

More Jobs at Blue Cross and Blue Shield Association

More Information Technology Jobs

Find similar Senior Cybersecurity Compliance Lead Consultant jobs: