Senior Information Risk Analyst @Blue Cross Blue Shield of Massachusetts
All Others
Salary usd 110,970 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 6d ago

[Hiring] Senior Information Risk Analyst @Blue Cross Blue Shield of Massachusetts

6d ago - Blue Cross Blue Shield of Massachusetts is hiring a remote Senior Information Risk Analyst. πŸ’Έ Salary: usd 110,970 - 135,630 per year πŸ“Location: USA

Role Description

The Senior Information Risk Analyst is a risk management professional, a versatile technical risk and information security expert, and a highly valued partner within the Information Risk Management (IRM) team. In this role, you will evaluate the organization's technology risk posture by conducting objective, fact-based assessments of existing and emerging third parties, systems, and applications. By analyzing these findings through a pragmatic, risk-based framework, you will partner directly with business stakeholders to design practical mitigation strategies that align with the organization's overall risk tolerance and business objectives. A critical component of this position involves translating complex technology and digital threats into clear, actionable business insights.

This position is open to candidates based in Massachusetts as well as remote, US-based candidates.

Your Day to Day

  • Perform vendor risk assessments to identify, evaluate and communicate risks to ensure they are properly understood and managed in alignment with organizational risk appetite, as well as applicable legal, regulatory, contractual and organizational requirements throughout the lifecycle of the relationship with the vendor.
  • Function as a technology risk subject matter expert; possess a strong technical understanding of infrastructure resiliency, secure data transmission protocols, network architecture, and modern threat vectors.
  • Execute thorough and timely technology risk assessments, including compliance risk, AI risk, application risk, and other analyses, across applications, initiatives, and business processes.
  • Evaluate contractual protection documentation to ensure vendor agreements mitigate compliance, regulatory, and data risk, mandate appropriate technical and administrative safeguards that protect BCBSMA data within established risk tolerances.
  • Partner with Legal and Procurement teams to guide negotiations on contract language and mitigation strategies, bringing third-party risk to acceptable levels.
  • Translate complex HIPAA regulatory requirements and risk mitigations into plain language and guide business units in the implementation of appropriate data safeguarding strategies, ensuring compliance is achieved through practical, risk-based solutions.
  • Distill complex risk data into high-impact executive dashboards and advanced visual reports for senior leadership with a clear, quantitative understanding of the risk landscape.
  • Serve as a trusted risk advisor and consultant to business units, partnering with them during the development and coordination of business processes and systems to proactively embed risk management strategies.
  • Actively engage with business units to gain foresight into upcoming initiatives, ensuring technology risks are proactively managed and embedded from the planning phase.
  • Contribute expert-level guidance to cross-functional teams in the development of risk, compliance, and information protection policies, standards, and procedures.
  • Drive the regular review and enhancement of governance documents to ensure they remain practical, relevant, and aligned with our evolving business needs.
  • Lead targeted internal initiatives and process improvements as directed by leadership to help optimize the team's advisory capabilities and overall risk delivery framework.

Qualifications

  • In addition to third-party risk management or a cybersecurity generalist, expertise in one or more of the following: risk management, regulatory compliance, application risk analysis, data analytics, and visualizations.
  • Solutions-oriented business partner, leveraging a deep understanding of technical defense concepts, vulnerability landscapes, and system safeguard principles.
  • Strong personal drive, organization and execution skills, and ability to self-manage to a defined outcome, including project decomposition, task identification, leadership alignment, regular status points, and successful on-time completion.
  • Collaborator who develops and champions practical risk mitigation strategies rather than rigid technical blockers.
  • Ability to analyze and translate complex technical findings into clear, actionable business contexts, working collaboratively with stakeholders to mitigate risk and enable risk informed executive decisions.
  • Experience assisting in the development and tracking of Key Risk Indicators (KRIs) and performance metrics to continuously monitor the health of the third-party ecosystem and the broader technology risk program.
  • Strong interpersonal skills to cultivate relationships and foster cross-team collaboration across the enterprise.
  • Ability to serve as a mentor to team members, providing peer guidance, operational support, and coaching on technology risk management strategies and assessment processes.

Requirements

  • BA or BS degree in Risk Management, Technology, Business Administration, Information Security, a related field, or equivalent practical experience.
  • 8+ years of experience in third-party risk management, technology, IT, or risk management functions.
  • 5+ years of dedicated experience executing risk assessments, vendor evaluations, or risk management programs within an information protection framework.
  • CRISC, CTPRP (Certified Third-Party Risk Professional), or C3PRMP strongly preferred.
  • Demonstrated experience navigating healthcare regulatory and compliance frameworks, specifically HIPAA and HITRUST.
  • Hands-on experience utilizing enterprise GRC platforms and Third-Party Risk Management tools (e.g., Whistic, RiskRecon, ServiceNow, or similar).
  • Relevant audit, general GRC, or high-level protection certifications are a plus (e.g., CISSP, CISA, GRCP, CGRC, CISM).

Benefits

  • Comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and a suite of well-being benefits to eligible employees.

Location

Boston

Time Type

Full time

Salary Range

$110,970.00 - $135,630.00

Company Description

At Blue Cross Blue Shield of Massachusetts, we believe in wellness and that work/life balance is a key part of associate wellbeing. We are committed to investing in your development and providing the necessary resources to enable your success.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Information Risk Analyst @Blue Cross Blue Shield of Massachusetts
All Others
Salary usd 110,970 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 6d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 131,036+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later