Residency in or relocation to Louisiana is preferred for all positions.
POSITION PURPOSELeads the validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements.
QUALIFICATIONSEducation- Bachelor's in IT, Audit, and/or related fields required
- Four years of related experience can be used in lieu of a Bachelor’s degree.
Work Experience- 4 years of relevant, specialized experience and highly developed proficiency within multiple disciplines including Governance, Risk, and Compliance required
Skills and Abilities- This position does not have any direct reports but is expected to mentor and lead the operational activities of junior team members.
- Requires excellent analytical, critical thinking, communication, marketing, and consulting skills.
- Hands-on technical expertise in cybersecurity, IT infrastructure (networking, server management, etc.), cloud technologies, or application development is highly desirable.
- Works under minimal supervision with latitude for independent judgment in a remote environment. Conducts tasks and assignments as directed or independently.
- Requires experience in and working knowledge of at least 2 of the following disciplines:
• Technology Risk Management
• Governance Documentation Management (i.e. Policies, Processes, and Procedures)
• Cybersecurity Awareness and Training
• Management of IT/Security Controls & Ensuring Compliance with Legal and Regulatory Requirements
• Auditing (Preferably IT Audit)
• Technical Management of IT Infrastructure (e.g. networking, server administration, cloud technologies, etc.)
• Cybersecurity Architecture, Incident, and Response
Licenses and Certifications- Multiple Cybersecurity, IT or Security Governance, Information Systems Audit, Compliance, Risk Management, or computer networking trainings and certifications are preferred (e.g. CISA, CRISC, CGEIT, CISM, CISSP, CompTIA Sec+, CIA, CRMA, COSO/ERM, etc., or other relevant certifications from reputable organizations such as GIAC, ISC2, ISACA, or Comp TIA).
ACCOUNTABILITIES AND ESSENTIAL FUNCTIONS
- Collaborates and consults with a team of Cybersecurity and IT professionals to accomplish multiple of the following objectives as determined by management.
- Governance
• Collaborates on the development and implementation of the annual strategic plan
• Develops Board-level reporting
• Maintains and ensures integration with the company’s cybersecurity, control, and risk management frameworks
• Manages and maintains a functional, accessible, and protected control library and facilitates reviews with control owners
• Tracks pertinent laws and regulations and maps relationships between various legal, regulatory, and contractual requirements (HIPAA, SOC-2, SOC-1, AFRMR, etc.) and various security cybersecurity and control frameworks (NIST CSF, NIST 800-53, COBIT, etc.)
• Leads in the design of security controls to ensure alignment with the organization’s risk appetite and tolerance levels to support business objectives
• Develops and maintains IT and Cybersecurity governance documentation assets including charters, policies, standards, processes, procedures, and artifacts
• Ensures alignment of controls with all supporting governance documentation
• Facilitates the identification of metrics and key performance indicators to enable the measurement of security controls performance in meeting business objectives
• Trains and promotes awareness to the workforce on cybersecurity responsibilities and protections through phishing simulations, remote awareness events, computer-based trainings, and frequent communications
• Develops, maintains, and reports on operational governance metrics - Risk Management
• Maintains risk alignment to the company’s chosen cybersecurity framework
• Assesses BCBSLA’s technical environment for alignment to the chosen Cybersecurity Framework and develops remediation efforts to close gaps and mature the cybersecurity control environment.
• Collaborates with Security Architecture, SIRT, and IT technical teams to identify and assess risk, perform security reviews, identify gaps in security architecture, and develop a security risk management plan
• Assesses risk for their inherent, target, and residual likelihood of occurrence and impact to the organization
• Develops comprehensive risk assessments for reporting to multiple audiences including business leaders, technical personnel, audit personnel, senior management, and the board of directors
• Applies Cybersecurity architecture concepts in the design of controls to effectively mitigate risk
• Recommends and coordinates security initiatives to mitigate risks to acceptable levels as defined by corporate appetite tolerances
• Provides enterprise cybersecurity risk management guidance and education. Integrates risk management with appropriate organizational functions.
• Participates in the acquisition process as necessary, following appropriate risk management practices
• Verifies risk management documents, policies, and other governance products
• Develops, maintains, and reports on operational risk management metrics - Compliance
• Develops and maintains continuous control monitoring schedules and oversees security control assessments to verify effectiveness and efficiency
• Monitors controls to ensure controls remain within tolerances, function effectively and efficiently, and are appropriate
• Provides documentation and training to ensure security controls are effectively performed
• Serves as liaison to auditors, consultants, IT management, cybersecurity personnel, and other personnel as needed to ensure organizational compliance with applicable rules, laws, and regulations
• Tracks and manages audit findings for the IT Division to ensure accurate reporting and timely resolution
• Consults with control experts to provide documentation in support of internal and external audit activities
• Develops, maintains, and reports on operational compliance metrics - General Governance, Risk, and Compliance (GRC) Support
• Leads process analysis, development, & improvement efforts
• Assists in developing, testing, and delivering solutions, support, reporting, information, and relationship management to satisfy client requests
• Acts as a liaison between clients and others inside or outside of BCBSLA to facilitate solutions, information sharing, and effective communication
• Contributes to executive and Board-level reporting
• Provides overall support to all Technology GRC team efforts and serves as a resource to other team members
• Provides proactive and reactive subject matter expertise to all levels of the organization
• Interviews process owners and review process design to gain understanding of business requirements
Additional Accountabilities and Essential Functions
The Physical Demands described here are representative of those that must be met by an employee to successfully perform the Accountabilities and Essential Functions of the job. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential functions
- Perform other job-related duties as assigned, within your scope of responsibilities.
- Job duties are performed in a normal and clean office environment with normal noise levels.
- Work is predominately done while standing or sitting.
- The ability to comprehend, document, calculate, visualize, and analyze are required.
All internal employees please apply through Workday Careers.
PLEASE USE A WEB BROWSER OTHER THAN INTERNET EXPLORER IF YOU ENCOUNTER ISSUES (CHROME, FIREFOX, SAFARI)
Additional Information
Please be sure to monitor your email frequently for communications you may receive during the recruiting process. Due to the high volume of applications we receive, only those most qualified will be contacted. To monitor the status of your application, please visit the "My Applications" section in the Candidate Home section of your Workday account.
If you are an individual with a disability and require a reasonable accommodation to complete an application, please contact for assistance.
In support of our mission to improve the health and lives of Louisianians, we encourage the good health of its employees and visitors. We want to ensure that our employees have a work environment that will optimize personal health and well-being. Due to the acknowledged hazards from exposure to environmental tobacco smoke, and in order to promote good health, our company properties are smoke and tobacco free.