Blue Shield of California
Information Security Risk and Governance Specialist, Consultant
Oakland, California · Posted today
Opens ecge.fa.us2.oraclecloud.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Not specified
- Source
- Oracle (employer's hiring system)
Skills mentioned
SOC 2, Cybersecurity
About the role
Your Role
The Information Security Team is seeking an Information Security Risk and Governance Specialist. In this role, you will be supporting Stellarus by helping translate regulatory, contractual, policy, and security requirements into sustainable and measurable governance and control practices.
Stellarus recognizes that IT Services are crucial, strategic, organizational assets and therefore we must invest appropriate levels of resource into the support, delivery and management of these critical IT Services and the IT systems that underpin them.
This position has responsivities within the Information Security Compliance organization, for maturing the Compliance function, ensuring IT audit-readiness with policy, regulations and control standards.
Your Work
In this role, you will:
GRC Program Operations & Reporting
- Maintain accurate information within GRC systems, control repositories, risk registers, policy repositories, and assurance trackers.
- Contribute to the development and maintenance of dashboards and reporting regarding security risks, control performance, exceptions, audit activity, findings, and remediation.
- Support development and continuous improvement of GRC processes, methodologies, templates, procedures, and operating standards.
Application & Technology Governance
- Support governance processes that establish visibility into applications, systems, infrastructure, data environments, and technology services subject to security requirements.
- Partner with technology teams to incorporate security governance requirements into the technology lifecycle, including implementation, material changes, and retirement.
- Maintain mappings between applications/technology assets and applicable risks, controls, owners, frameworks, and evidence.
- Assist in determining which applications and technology components are in scope for applicable regulatory and assurance frameworks.
Audit & Assessment Support
- Serve as a liaison between internal/external auditors/assessors and internal control owners.
- Coordinate information security evidence and responses for internal audits, external audits, customer assessments, regulatory reviews, and certification activities.
- Maintain organized, reusable evidence repositories to reduce duplicative requests and audit fatigue.
- Support readiness activities associated with SOC 2, NIST, HIPAA, HITRUST, and other applicable assessments.
Information Security Risk Management
- Support information security risk management program, including identification, assessment, documentation, treatment, monitoring, and reporting of technology and cybersecurity risks.
- Support development of security risk metrics, key risk indicators, dashboards, and management reporting.
- Monitor open risks, exceptions, findings, and remediation commitments and facilitate escalation of overdue or high-risk items.
- Facilitate security risk assessments for systems, applications, technologies, business processes, and organizational changes.
- Maintain security risk assessments for systems, applications, technologies, business processes, and organizational changes.
Control Assurance & Monitoring
- Perform or coordinate control self-assessments and evidence reviews.
- Evaluate whether controls are appropriately designed, implemented, documented, and supported by sufficient evidence.
- Track findings and remediation through closure and validate supporting evidence when appropriate.
- Identify control gaps and work with control owners to establish corrective action plans.
Your Knowledge and Experience
- Requires a bachelor's degree or equivalent experience
- Requires at least 7 years of prior relevant experience
- Understanding of and experience working with security assurance and trust frameworks (in particular NIST, HIPAA and SOC 2)
- Experience interacting with internal/external auditors and explaining technical concepts
- Ability to communicate effectively with customers and internal teams
- Superior organizational skills, extraordinary attention to detail, and an agile mindset that processes can always be improved
- Proven ability to manage projects and deliverables to completion
- Ability to understand and contextualize complex technical concepts into terms readily understandable by a non-technical audience
- Satisfactory knowledge and skills including technical or functional expertise, business acumen and financial analysis skills, risk management, critical thinking and decision-making skills.
- Intermediate understanding of healthcare information security governance, risk, and compliance practices
- Ability to learn and understand Stellarus’ security controls and to maintain a security knowledge base that can be used for multiple projects
Additionally, candidate must be able to:
- Demonstrate personal commitment to change through actions and words, and mobilize others to support change through times of stress and uncertainty
- Foster a team culture of continuous improvement, mentoring and learning, data driven decisions, and accountability for delivery of key metrics and deliverables
- Breakdown raw information and undefined problems into specific, workable components that in-turn clearly identifies the issues at hand
- Make logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision-making process
- Improve organizational performance though the application of original thinking to existing and emerging methods, processes, products and services
#LI-FB1
Job ID or-ecge-fa-us2-oraclecloud-com-cx-1003-20261906 · Original posting ↗
Visa sponsorship history
- 9 H-1B petitions approved for CALIFORNIA PHYSICIANS SERVICE DBA BLUE SHIELD OF CALIFORNIA in fiscal year 2023 (USCIS).
From public government data. It shows this employer has sponsored workers before, not that this job offers sponsorship: check the job ad or ask the employer. More visa-friendly jobs