Senior Information Security Risk Analyst @BlueCross BlueShield of Tennessee
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2d ago

[Hiring] Senior Information Security Risk Analyst @BlueCross BlueShield of Tennessee

2d ago - BlueCross BlueShield of Tennessee is hiring a remote Senior Information Security Risk Analyst. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

We are hiring a Senior Information Security Risk Analyst on our Governance, Risk & Compliance (GRC) team!

In this role, you will serve as a technical subject matter expert in application security risk management, leading governance and oversight of our SAST/DAST application security scanning program, including static and dynamic application security testing. You will:

  • Assess security vulnerabilities and evaluate findings from application and infrastructure scanning tools.
  • Partner with application teams, incident management teams, and business stakeholders to prioritize and remediate risk.
  • Maximize the value of the SAST/DAST platform and strengthen vulnerability management practices.
  • Improve risk visibility and translate technical findings into actionable business risk insights.

Additionally, this role supports a high-visibility Data Governance initiative where you will help shape how enterprise data is governed, protected, and leveraged across the organization. You will:

  • Partner with business leaders, data owners, security, privacy, compliance, and technology teams to establish governance standards.
  • Assess risk, monitor compliance, and strengthen data stewardship practices.
  • Influence enterprise-wide decisions and advance a mature Data Governance program.

Experience supporting SOC 2 audits, NIST frameworks and SSP development, third-party risk management, governance activities, and communicating complex security risks to both technical and non-technical audiences is highly valued. Strong collaboration, relationship-building, and influencing skills are essential, as this role will work across multiple teams to strengthen the organization's security posture.

Note:

  • Participation in on-call rotation is required for two weeks every 22 weeks.
  • Must be able to work Eastern Time business hours.
  • This is a remote, work-from-home position, but the final round of interviews will take place on-site in our Chattanooga, TN office.
  • Sponsorship is not available for this role.

Qualifications

  • Bachelor’s degree in a relevant field or an equivalent of four years of experience is required.
  • 5 years of professional experience in Information Security or related IT roles with security-related responsibilities, including at least 2 years focused on Governance, Risk, and Compliance (GRC) functions.
  • Experience leveraging AI-enabled tools to automate and enhance GRC processes, improving efficiency, consistency, and scalability of governance, risk, and compliance activities preferred.
  • Preferred, one or more of the following certifications required: CISSP, CRISC, CISA, or CISM.
  • Ability to assess and document organizational risks, including identifying impacts and recommending mitigation strategies.
  • Ability to interpret and apply regulatory requirements and industry frameworks (e.g., NIST, SOC 2, HIPAA) to organizational controls.
  • Ability to analyze security, compliance, and risk metrics to identify trends and drive continuous improvement.
  • Ability to communicate complex risk and compliance concepts clearly to both technical and non-technical stakeholders.
  • Ability to collaborate effectively across cross-functional teams to integrate governance, risk, and compliance practices into business processes.
  • Exceptional time management skills.
  • Excellent oral and written communication skills.
  • Strong interpersonal skills and ability to cultivate relationships with internal and external stakeholders, promoting diversity of people, perspectives and ideas.
  • Ability to work with all levels of staff and management.

Requirements

  • Lead SOC 2 Audit Support – Coordinate audit activities including evidence collection, control validation, and auditor engagement.
  • Manage and Validate Control Frameworks – Maintain control documentation, mappings, and narratives while partnering with control owners to ensure effectiveness and alignment with Trust Services Criteria and NIST frameworks.
  • Track Audit & Remediation Activities – Oversee audit findings, remediation efforts, and timely closure of issues.
  • Develop & Maintain NIST SSPs – Create and update System Security Plans (SSPs), including control implementations, inheritance, and system boundaries.
  • Drive Security Awareness Programs – Design and manage training initiatives, including phishing simulations and targeted campaigns.
  • Manage Policies & Governance Documentation – Oversee the full lifecycle of security policies, standards, and procedures to ensure compliance and audit readiness.
  • Conduct Enterprise & Third-Party Risk Management – Perform risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation.
  • Oversee Vulnerability Management – Track vulnerability remediation against SLAs and collaborate with teams to mitigate risks.
  • Support Customer Security Assurance – Respond to RFPs and security questionnaires, ensuring accurate, compliant, and consistent security representations.
  • Leadership – Leads by example, actively supporting initiatives across all GRC areas while fostering a culture of collaboration and shared accountability.

Company Description

BlueCross BlueShield of Tennessee is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at BlueCross BlueShield of Tennessee via email, the Internet or any other method without a valid, written Direct Placement Agreement in place for this position from BlueCross BlueShield of Tennessee HR/Talent Acquisition will not be considered. No fee will be paid in the event the applicant is hired by BlueCross BlueShield of Tennessee as a result of the referral or through other means.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Information Security Risk Analyst @BlueCross BlueShield of Tennessee
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 129,524+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later