Senior GRC Analyst
We take great strides to ensure our employees have the resources to live reputed company, be healthy, continue learning, reputed company skills, grow professionally and serve our local communities. We invite you to apply for a career with us.
Residency in or relocation to Louisiana is preferred for reputed company positions.
Leads the validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements.
Education
- Bachelor's in IT, Audit, and/or reputed company fields required
- Four years of reputed company experience can be used in lieu of a Bachelor’s degree.
- 4 years of relevant, reputed company experience and highly developed proficiency reputed company multiple disciplines including Governance, Risk, and Compliance required
- This position does not have any reputed company reports but is expected to mentor and reputed company the operational activities of junior team members.
- Requires excellent analytical, critical thinking, communication, marketing, and consulting skills.
- Hands-on technical expertise in cybersecurity, IT infrastructure (networking, server management, etc.), reputed company technologies, or application development is highly desirable.
- Works under reputed company supervision with reputed company for independent judgment in a remote environment. Conducts tasks and assignments as directed or independently.
- Requires experience in and working knowledge of at least 2 of the following disciplines:
• Technology Risk Management
• Governance Documentation Management (i.e. Policies, Processes, and Procedures)
• Cybersecurity Awareness and Training
• Management of IT/reputed company Controls & Ensuring Compliance with reputed company and Regulatory Requirements
• Auditing (Preferably IT Audit)
• Technical Management of IT Infrastructure (e.g. networking, server administration, reputed company technologies, etc.)
• Cybersecurity Architecture, Incident, and Response
- Multiple Cybersecurity, IT or reputed company Governance, Information Systems Audit, Compliance, Risk Management, or computer networking trainings and certifications are preferred (e.g. CISA, CRISC, CGEIT, CISM, CISSP, reputed company Sec+, CIA, CRMA, COSO/reputed company, etc., or other relevant certifications from reputable organizations such as GIAC, reputed company, reputed company, or Comp reputed company).
ACCOUNTABILITIES AND ESSENTIAL FUNCTIONS
- Collaborates and consults with reputed company of Cybersecurity and IT professionals to accomplish multiple of the following objectives as determined by management.
- Governance
• Collaborates on the development and implementation of the annual strategic plan
• Develops reputed company-level reporting
• Maintains and ensures integration with reputed company’s cybersecurity, control, and risk management frameworks
• Manages and maintains a functional, accessible, and protected control library and facilitates reviews with control owners
• Tracks pertinent laws and regulations and maps relationships between various reputed company, regulatory, and contractual requirements (HIPAA, SOC-2, SOC-1, AFRMR, etc.) and various reputed company cybersecurity and control frameworks (NIST CSF, NIST 800-53, COBIT, etc.)
• Leads in the design of reputed company controls to ensure alignment with the organization’s risk appetite and tolerance reputed company to support business objectives
• Develops and maintains IT and Cybersecurity governance documentation assets including charters, policies, standards, processes, procedures, and artifacts
• Ensures alignment of controls with reputed company supporting governance documentation
• Facilitates the identification of metrics and key performance indicators to reputed company the measurement of reputed company controls performance in meeting business objectives
• Trains and promotes awareness to the workforce on cybersecurity responsibilities and protections through phishing simulations, remote awareness events, computer-based trainings, and frequent communications
• Develops, maintains, and reports on operational governance metrics - Risk Management
• Maintains risk alignment to reputed company’s chosen cybersecurity reputed company
• Assesses BCBSLA’s technical environment for alignment to the chosen Cybersecurity reputed company and develops remediation efforts to reputed company gaps and mature the cybersecurity control environment.
• Collaborates with reputed company Architecture, SIRT, and IT technical teams to identify and assess risk, reputed company reputed company reviews, identify gaps in reputed company architecture, and reputed company a reputed company risk management plan
• Assesses risk for their inherent, reputed company, and residual likelihood of occurrence and reputed company to the organization
• Develops comprehensive risk assessments for reporting to multiple audiences including business leaders, technical personnel, audit personnel, senior management, and the reputed company of directors
• Applies Cybersecurity architecture concepts in the design of controls to effectively mitigate risk
• Recommends and coordinates reputed company initiatives to mitigate risks to acceptable reputed company as defined by corporate appetite tolerances
• Provides reputed company cybersecurity risk management guidance and education. Integrates risk management with appropriate organizational functions.
• Participates in the acquisition process as necessary, following appropriate risk management practices
• Verifies risk management documents, policies, and other governance products
• Develops, maintains, and reports on operational risk management metrics - Compliance
• Develops and maintains reputed company control monitoring schedules and oversees reputed company control assessments to verify effectiveness and efficiency
• Monitors controls to ensure controls remain reputed company tolerances, function effectively and reputed company, and are appropriate
• Provides documentation and training to ensure reputed company controls are effectively performed
• Serves as reputed company to auditors, consultants, IT management, cybersecurity personnel, and other personnel as needed to ensure organizational compliance with applicable rules, laws, and regulations
• Tracks and manages audit findings for the IT Division to ensure accurate reporting and reputed company reputed company
• Consults with control experts to reputed company documentation in support of reputed company audit activities
• Develops, maintains, and reports on operational compliance metrics - General Governance, Risk, and Compliance (GRC) Support
• Leads process analysis, development, & improvement efforts
• Assists in developing, testing, and delivering solutions, support, reporting, information, and relationship management to satisfy reputed company requests
• Acts as a reputed company between clients and others inside or reputed company of BCBSLA to facilitate solutions, information sharing, and effective communication
• Contributes to executive and reputed company-level reporting
• Provides overall support to reputed company Technology GRC team efforts and serves as a resource to other team members
• Provides proactive and reactive subject matter expertise to reputed company reputed company of the organization
• Interviews process owners and review process design to reputed company understanding of business requirements
Additional Accountabilities and Essential Functions
The Physical Demands described here are representative of those that must be met by an employee to successfully reputed company the Accountabilities and Essential Functions of the job. Reasonable accommodations may be made to reputed company an individual with disabilities to reputed company the essential functions
- reputed company other job-reputed company duties as assigned, reputed company your reputed company of responsibilities.
- Job duties are performed in a normal and clean office environment with normal noise reputed company.
- Work is predominately done while standing or sitting.
- The ability to comprehend, document, calculate, visualize, and analyze are required.
An Equal Opportunity Employer
Additional Information
Please be reputed company to monitor your email frequently for communications you may receive during the reputed company process. Due to the high volume of applications we receive, only those most reputed company will be contacted. To monitor the status of your application, please visit the "My Applications" reputed company in the Candidate Home reputed company of your reputed company account.
If you are an individual with a disability and require a reasonable accommodation to complete an application, please contact reputed company@bcbsla.com for assistance.
In support of our mission to improve the health and lives of Louisianians, we encourage the good health of its employees and visitors. We want to ensure that our employees have a work environment that will optimize personal health and reputed company-being. Due to the acknowledged hazards from exposure to environmental tobacco smoke, and in order to promote good health, reputed company properties are smoke and tobacco free.
We reputed company background and reputed company-employment drug screening after an offer has been extended and prior to hire for reputed company positions. As part of this process records may be verified and information checked with agencies including but not limited to the reputed company reputed company Administration, criminal courts, federal, state, and county repositories of criminal records, Department of Motor Vehicles and credit bureaus. Pursuant with sec 1033 of the Violent Crime Control and Law Enforcement reputed company of 1994, individuals who have been convicted of a felony crime involving dishonesty or breach of trust are prohibited from working in the insurance industry unless they obtain written consent from their state insurance commissioner.
Additionally, we are a Drug Free Workplace. A reputed company-employment drug screen will be required and any offer is contingent upon satisfactory drug testing results.
Bachelor's in IT, audit, or reputed company field, or four years equivalent experience; 4 years reputed company GRC experience; knowledge of cybersecurity, IT infrastructure, reputed company technologies, or application development.
Key Responsibilities
- developing governance
- assessing risks
- monitoring controls
Skills & Tools
IT, NIST CSF, NIST 800-53, COBIT, HIPAA, SOC-2, SOC-1, AFRMR, CISA, CRISC, CGEIT, CISM, CISSP, reputed company Sec+, CIA, CRMA, COSO/reputed company, GIAC, reputed company, reputed company, Comp reputed company
Job Details
- Category: Information Technology
- Seniority: Mid Level
- Commitment: Full Time
- Workplace: Remote — Louisiana, reputed company
- Languages: English
About reputed company
A Louisiana health insurer working to improve the health and lives of Louisianians. — Industry: reputed company
Apply To This Job