Blue Shield of California logo

Information Security Risk and Governance Specialist, Consultant

Posted 1 day ago

OfficeOakland, CA, United States

Your Role

The Information Security Team is seeking an Information Security Risk and Governance Specialist.  In this role, you will be supporting Stellarus by helping translate regulatory, contractual, policy, and security requirements into sustainable and measurable governance and control practices.  

Stellarus recognizes that IT Services are crucial, strategic, organizational assets and therefore we must invest appropriate levels of resource into the support, delivery and management of these critical IT Services and the IT systems that underpin them.

This position has responsivities within the Information Security Compliance organization, for maturing the Compliance function, ensuring IT audit-readiness with policy, regulations and control standards.

Your Work 
In this role, you will:

GRC Program Operations & Reporting

  • Maintain accurate information within GRC systems, control repositories, risk registers, policy repositories, and assurance trackers.
  • Contribute to the development and maintenance of dashboards and reporting regarding security risks, control performance, exceptions, audit activity, findings, and remediation.
  • Support development and continuous improvement of GRC processes, methodologies, templates, procedures, and operating standards.

Application & Technology Governance

  • Support governance processes that establish visibility into applications, systems, infrastructure, data environments, and technology services subject to security requirements.
  • Partner with technology teams to incorporate security governance requirements into the technology lifecycle, including implementation, material changes, and retirement.
  • Maintain mappings between applications/technology assets and applicable risks, controls, owners, frameworks, and evidence.
  • Assist in determining which applications and technology components are in scope for applicable regulatory and assurance frameworks. 

Audit & Assessment Support

  • Serve as a liaison between internal/external auditors/assessors and internal control owners.
  • Coordinate information security evidence and responses for internal audits, external audits, customer assessments, regulatory reviews, and certification activities.
  • Maintain organized, reusable evidence repositories to reduce duplicative requests and audit fatigue.
  • Support readiness activities associated with SOC 2, NIST, HIPAA, HITRUST, and other applicable assessments.

Information Security Risk Management

  • Support information security risk management program, including identification, assessment, documentation, treatment, monitoring, and reporting of technology and cybersecurity risks.
  • Support development of security risk metrics, key risk indicators, dashboards, and management reporting.
  • Monitor open risks, exceptions, findings, and remediation commitments and facilitate escalation of overdue or high-risk items.
  • Facilitate security risk assessments for systems, applications, technologies, business processes, and organizational changes.
  • Maintain security risk assessments for systems, applications, technologies, business processes, and organizational changes.

Control Assurance & Monitoring

  • Perform or coordinate control self-assessments and evidence reviews.
  • Evaluate whether controls are appropriately designed, implemented, documented, and supported by sufficient evidence.
  • Track findings and remediation through closure and validate supporting evidence when appropriate.
  • Identify control gaps and work with control owners to establish corrective action plans.

Your Knowledge and Experience 

  • Requires a bachelor's degree or equivalent experience
  • Requires at least 7 years of prior relevant experience
  • Understanding of and experience working with security assurance and trust frameworks (in particular NIST, HIPAA and SOC 2)
  • Experience interacting with internal/external auditors and explaining technical concepts
  • Ability to communicate effectively with customers and internal teams
  • Superior organizational skills, extraordinary attention to detail, and an agile mindset that processes can always be improved
  • Proven ability to manage projects and deliverables to completion
  • Ability to understand and contextualize complex technical concepts into terms readily understandable by a non-technical audience
  • Satisfactory knowledge and skills including technical or functional expertise, business acumen and financial analysis skills, risk management, critical thinking and decision-making skills.
  • Intermediate understanding of healthcare information security governance, risk, and compliance practices
  • Ability to learn and understand Stellarus’ security controls and to maintain a security knowledge base that can be used for multiple projects

Additionally, candidate must be able to:

  • Demonstrate personal commitment to change through actions and words, and mobilize others to support change through times of stress and uncertainty
  • Foster a team culture of continuous improvement, mentoring and learning, data driven decisions, and accountability for delivery of key metrics and deliverables
  • Breakdown raw information and undefined problems into specific, workable components that in-turn clearly identifies the issues at hand
  • Make logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision-making process
  • Improve organizational performance though the application of original thinking to existing and emerging methods, processes, products and services

 

#LI-FB1

About Blue Shield of California

Blue Shield of California strives to create a healthcare system worthy of its family and friends that is sustainably affordable. The health plan is a tax paying, nonprofit, independent member of the Blue Shield Association with nearly 6 million members, over 7,500 employees and more than $25 billion in annual revenue. Founded in 1939 in San Francisco and now headquartered in Oakland, Blue Shield of California and its affiliates provide health, dental, vision, Medicaid and Medicare healthcare service plans in California. The company has contributed more than $60 million to Blue Shield of California Foundation in the last three years to have an impact on California communities. For more news about Blue Shield of California, please visit news.blueshieldca.com.

7967InsuranceOakland, California1939601 W 12th St, Oakland, California 94607, USNot-for-profit California Health Plan, health insurance, and access to health care
Apply smarter with Jobr

Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.

Direct from company career pages
AI-personalised cover letters
Human review before every submit
Application tracking & follow-ups