Senior Cybersecurity Compliance Lead Consultant

001_BCBSA Blue Cross and Blue Shield Association

Chicago (IL)

On-site

USD 158,000 - 229,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Paid time off
11 holidays
Medical/dental/vision insurance
Generous 401(k) matching
Lifestyle spending account
Annual bonus incentive pay

Job summary

Blue Cross Blue Shield Association in the United States seeks a Senior Cyber Risk Manager to lead the cyber risk program and drive strategic governance. You will coordinate with IT and security leadership to embed risk controls and AI-enabled processes across enterprise technology and operations.

The role requires 10+ years of IT/security experience, deep knowledge of FedRAMP, NIST, and ISO 27001, plus strong leadership and communication skills to influence stakeholders at all levels.

Qualifications

  • Bachelor's degree in IT, information security, risk, IT management, computer science, or related field. or equivalent work experience.
  • 10+ years career experience in IT or a closely related field; experience with automation and AI-enabled solutions to improve compliance monitoring and efficiency.
  • Knowledge of FedRAMP requirements, continuous monitoring, controls, evidence management, and audit readiness.

Responsibilities

  • Lead the cyber risk program and align with organizational goals.
  • Develop mitigation plans using analytical and qualitative methods.
  • Oversee FedRAMP compliance strategy and AI-enabled operating model.
  • Manage cross-functional teams and project governance.

Skills

NIST CSF
ISO 27001
FedRAMP
AI literacy
Leadership
PM skills
Cloud security
Regulatory compliance

Education

Bachelor's Degree in IT / Information Security / Risk / IT Management / CS

Job description

Responsibilities
  • Lead the creation and deployment of defined and structured processes to support evolving and maintaining the cyber risk management program. Work across the BCBSA organization to align cyber risk management with the organization's goals and outcomes.
  • Utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies.
  • Apply experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance.
  • Support IT and information security leadership in making risk informed decisions and shaping the future direction of BCBSA's cybersecurity program.
  • Assess internal and third-party supplier risks, realistically translate them for both technical and non-technical audiences, and clearly articulate recommended actions and organizational impact.
  • Specifically, this role will lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations.
  • Responsible for providing Cyber Risk leadership and subject matter expertise on all assigned projects.
  • Responsible for identifying day-to-day task assignments and providing technology and project management guidance on deliverables.
  • Validates and ensures Cyber Risk requirements are thorough, testable, detailed, concise and traceable.
  • Accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders.
  • Responsible for project planning, budget approvals, estimation and management for all project deliverables, collaborates with Service Delivery managers as appropriate.
  • Proficient in implementing cyber risk processes, leads teams to attain goals, pursue excellence and establish discipline specific best-practices.
  • Responsible for driving all project decisions, strong ability to make timely decisions and establish project governance.
  • Collaborates with other team-members, peers and builds trust, exhibits sense of urgency, biased for action and possesses good follow-up skills.
  • Customer focused with ability to persuade and drive consensus to resolve conflict and facilitate timely decision making.
  • Reviews and approves team progress reports, expenses, invoices and contracts in a thorough and timely manner.
  • Reviews the status reports of team members and addresses issues as appropriate.
  • Complies with and helps to enforce standard policies and procedures.
  • Provides and seeks timely feedback to IT partners, peers and team-members.
  • Provides leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focused on continuous improvement.
  • Provides project team(s) business/technical leadership and guidance on day-to-day tasks.
  • Responsible for driving change for implementing process improvements and ensuring long term compliance.
  • Leads the creation and maintenance of methodologies and processes for the department.
  • Expected to lead multiple, simultaneous projects and time-critical deliverables.
  • Maintains a formal risk register that drives security, governance and ensures security findings are aligned with business objectives.
  • Responsible for maintaining positive working relationships with all groups, cross-functional teams, including technical.
  • Identifies opportunities/needs and works with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure.
  • Provides budget forecasts and estimates for Cyber Risk activities on a continuous basis.
  • Responsible for variance analysis and justifications and following the established BCBSA processes/procedures.
  • Responsible for providing status updates to Senior/Executive management.
  • Responsible for escalating risks/issues with customer issues appropriately and in a timely manner.
  • Ensures design, development, testing and investigative activities lead to appropriate resolution.
  • Effectively and tactfully communicates relevant and potentially difficult/sensitive information to senior management.
  • Responsible for engaging, understanding and effectively communicating needs of business to IT teams/partners Resolves and/or escalates issues, proposes alternatives, and sets or manages expectations in a timely fashion.
  • Responsible for leading and managing delivery on multiple projects and responsible for all project related resource management, task-prioritization and development.
  • Frequent Plan interactions via System Advisory Group or project communications to ensure business solutions meet Plan needs and implementation/budget concerns are understood.
  • Frequent project participation/collaboration to ensure technical solutions meet business needs.
Salary

The posting range for this position is: 157,600.00 - 228,550.00

The posted salary range is the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the hiring range and this hiring range may also be modified in the future. A candidate’s position within the hiring range may be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, relevant experience, skills, seniority, performance, shift, travel requirements, and business or organizational needs.

Qualifications

Education Required: Bachelor's Degree IT, information Security, Risk or IT Management, Computer Science, or a related field; or equivalent work experience

Experience Required: 10+ Years career experience in IT or a closely related field Experience leveraging automation and AI-enabled solutions to improve compliance monitoring, reporting, and operational efficiency.

Knowledge, Skills, and Abilities
  • Knowledge of national and international regulatory and compliance frameworks such as NIST Cybersecurity Framework, ISO 27001, EU DPD, HIPAA/HITECH.
  • Extensive knowledge in the use of Project Management methodologies and tools, and change management techniques.
  • Demonstrated leadership, mentoring, and project management skills.
  • Understanding of current application cyber risk development methodologies and risks, researching emerging technologies and possible application to the business.
  • Deep knowledge of FedRAMP requirements, continuous monitoring practices, control implementation, evidence management, and audit readiness.
  • Strong understanding of NIST cybersecurity frameworks, risk management, cloud security, and regulatory compliance obligations.
  • Ability to translate complex compliance requirements into scalable, business-integrated processes and controls.
  • Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.
Benefits
  • Paid time off
  • 11 holidays
  • Medical/dental/vision insurance
  • Generous 401(k) matching
  • Lifestyle spending account
  • Many other benefits to eligible employees
  • Annual bonus incentive pay
Company Culture

We offer a comprehensive package of benefits including paid time off, 11 holidays, medical/dental/vision insurance, generous 401(k) matching, lifestyle spending account and many other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

At Blue Cross Blue Shield Association (BCBSA), we are a national association of 33 independent, community-based and locally operated Blue Cross Blue Shield companies and we are driven by purpose.

Join the team who supports the nation's largest healthcare network, providing coverage to nearly one in three Americans as we relentlessly pursue affordable healthcare and ensure peace of mind for the people we serve.

Be part of our storied history of innovation as we advance well-being and health equity.

Experience a culture that is built on our core values, connection, work-life flexibility, well-being, and a commitment to our community.

If you thrive at a company that values inclusivity, accountability, courage, teamwork, and respect, we're glad you found us!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Compliance Lead Consultant
Senior Cybersecurity Compliance Lead Consultant

Blue Cross and Blue Shield of Kansas Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 158,000 - 229,000
Senior Manager, Internal Audit
Senior Manager, Internal Audit

001_BCBSA Blue Cross and Blue Shield Association • Chicago (IL)

Hybrid
USD 150,000 - 203,000
Paid time off
11 holidays
Medical/dental/vision insurance
+3
Senior Cybersecurity Compliance Lead Consultant
Senior Cybersecurity Compliance Lead Consultant

Blue Cross Blue Shield Association • Chicago (IL)

On-site
USD 158,000 - 229,000
Paid time off
11 holidays
Medical/dental/vision insurance
+2
Senior Policy Program Manager, Legislative and Regulatory Policy
Senior Policy Program Manager, Legislative and Regulatory Policy

001_BCBSA Blue Cross and Blue Shield Association • Washington

Hybrid
USD 128,000 - 185,000
Vice President, Application Solutions
Vice President, Application Solutions

Blue Cross and Blue Shield of Kansas Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 278,000 - 361,000
Annual bonus
11 holidays
Medical/dental/vision insurance
+2
Vice President, Application Solutions
Vice President, Application Solutions

001_BCBSA Blue Cross and Blue Shield Association • Chicago (IL)

On-site
USD 278,000 - 361,000
Annual bonus
Paid time off
Health/Dental/Vision insurance
+2
AI Strategy and Portfolio Principal
AI Strategy and Portfolio Principal

Blue Cross and Blue Shield of Kansas Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 130,000 - 189,000
Paid time off
11 holidays
Medical/dental/vision insurance
+3
Director, Data and AI Platform Strategy
Director, Data and AI Platform Strategy

001_BCBSA Blue Cross and Blue Shield Association • Chicago (IL)

On-site
USD 170,000 - 240,000
PTO + Holidays
Medical/Dental/Vision
401(k) match
+1
Policy Research Specialist
Policy Research Specialist

001_BCBSA Blue Cross and Blue Shield Association • Washington

Hybrid
USD 103,000 - 139,000
Paid time off
Medical/dental/vision insurance
Generous 401(k) matching
+1
Sr. Brand Strategy and CX Consultant
Sr. Brand Strategy and CX Consultant

001_BCBSA Blue Cross and Blue Shield Association • Washington, Chicago (IL)

On-site
USD 104,000 - 141,000
Medical/dental/vision insurance
11 holidays
generous 401(k) matching
+1