Sr. Information Security Risk Analyst

BlueCross BlueShield of Tennessee, Inc.

Chattanooga (TN)

Hybrid

USD 120,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

BCBST BlueCross BlueShield of Tennessee, Inc. seeks a Senior Information Security Risk Analyst on the GRC team to lead application security risk management and oversee SAST/DAST programs.

You will translate complex findings into actionable business risk insights and drive remediation with application teams and stakeholders. You will also support enterprise data governance initiatives, assess regulatory requirements, and communicate risk to technical and non-technical audiences across the

Qualifications

  • Bachelor’s degree in a relevant field or four years of equivalent experience.
  • 5 years in information security or related IT roles with at least 2 years in GRC (Governance, Risk & Compliance).
  • Experience leveraging AI-enabled tools to automate GRC processes, improving efficiency and scalability.
  • Certifications: CISSP, CRISC, CISA, or CISM.
  • Ability to assess organizational risks and apply regulatory requirements (NIST, SOC 2, HIPAA).
  • Strong communication to technical and non-technical stakeholders.
  • Experience supporting SOC 2 audits, NIST frameworks, SSP development, and third-party risk management.

Responsibilities

  • Lead SOC 2 Audit Support – coordinate audit activities and evidence collection.
  • Manage and Validate Control Frameworks – maintain mappings and narratives with control owners.
  • Track Audit & Remediation Activities – oversee findings and remediation timelines.
  • Develop & Maintain NIST SSPs – create and update system security plans.
  • Drive Security Awareness Programs – design training and phishing simulations.
  • Manage Policies & Governance Documentation – oversee policies, standards and procedures.
  • Conduct Enterprise & Third‑Party Risk Management – perform risk assessments and monitor remediation.
  • Oversee Vulnerability Management – track remediation against SLAs.
  • Support Customer Security Assurance – respond to security questionnaires and RFPs.
  • Leadership – promote collaboration across GRC areas.

Skills

Application security
Risk assessment
GRC
SAST/DAST
Vulnerability management
Stakeholder communication

Education

Bachelor’s degree in a relevant field

Tools

SAST/DAST platforms
AI-enabled GRC tools

Job description

We are hiring a Senior Information Security Risk Analyst on our Governance, Risk & Compliance (GRC) team! In this role, you will serve as a technical subject matter expert in application security risk management, leading governance and oversight of our SAST/DAST application security scanning program, including static and dynamic application security testing. You will assess security vulnerabilities, evaluate findings from application and infrastructure scanning tools, and partner with application teams, incident management teams, and business stakeholders to prioritize and remediate risk. A key focus will be maximizing the value of the SAST/DAST platform, strengthening vulnerability management practices, improving risk visibility, and translating technical findings into actionable business risk insights. Successful candidates will bring strong expertise in application security testing, vulnerability management, and risk assessment, with hands‑on experience using SAST/DAST platforms, a proven ability to drive remediation efforts, and a CISSP, CISM, CISA, CRISC, or comparable security certification. Additionally, this role serves to support a high‑visibility Data Governance initiative where you will help shape how enterprise data is governed, protected, and leveraged across the organization. You will partner with business leaders, data owners, security, privacy, compliance, and technology teams to establish governance standards, assess risk, monitor compliance, and strengthen data stewardship practices. This role provides the opportunity to influence enterprise‑wide decisions and advance a mature Data Governance program. Successful candidates will be skilled relationship builders who can translate complex governance and regulatory requirements into practical business processes, drive accountability for data quality and policy adherence, and effectively balance regulatory expectations with business objectives. Experience supporting SOC 2 audits, NIST frameworks and SSP development, third‑party risk management, governance activities, and communicating complex security risks to both technical and non‑technical audiences is highly valued. Strong collaboration, relationship‑building, and influencing skills are essential, as this role will work across multiple teams to strengthen the organization's security posture. Note: Participation in on‑call rotation is required for two weeks every 22 weeks. Must be able to work Eastern Time business hours. This is a remote, work‑from‑home position, but the final round of interviews will take place on‑site in our Chattanooga, TN office. Sponsorship is not available for this role.

Job Responsibilities
  • Lead SOC 2 Audit Support – Coordinate audit activities including evidence collection, control validation, and auditor engagement.
  • Manage and Validate Control Frameworks – Maintain control documentation, mappings, and narratives while partnering with control owners to ensure effectiveness and alignment with Trust Services Criteria and NIST frameworks.
  • Track Audit & Remediation Activities – Oversee audit findings, remediation efforts, and timely closure of issues.
  • Develop & Maintain NIST SSPs – Create and update System Security Plans (SSPs), including control implementations, inheritance, and system boundaries.
  • Drive Security Awareness Programs – Design and manage training initiatives, including phishing simulations and targeted campaigns.
  • Manage Policies & Governance Documentation – Oversee the full lifecycle of security policies, standards, and procedures to ensure compliance and audit readiness.
  • Conduct Enterprise & Third‑Party Risk Management – Perform risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation.
  • Oversee Vulnerability Management – Track vulnerability remediation against SLAs and collaborate with teams to mitigate risks.
  • Support Customer Security Assurance – Respond to RFPs and security questionnaires, ensuring accurate, compliant, and consistent security representations.
  • Leadership – Leads by example, actively supporting initiatives across all GRC areas while fostering a culture of collaboration and shared accountability.
Job Qualifications

Education Bachelor’s degree in a relevant field or an equivalent of four years of experience is required.

Experience 5 years - Professional experience in Information Security or related IT roles with security-related responsibilities, including at least 2 years focused on Governance, Risk, and Compliance (GRC) functions. Experience leveraging AI-enabled tools to automate and enhance GRC processes, improving efficiency, consistency, and scalability of governance, risk, and compliance activities preferred.

Skills/Certifications Preferred, one or more of the following certifications required: CISSP, CRISC, CISA, or CISM.

Ability to assess and document organizational risks, including identifying impacts and recommending mitigation strategies.

Ability to interpret and apply regulatory requirements and industry frameworks (e.g., NIST, SOC 2, HIPAA) to organizational controls.

Ability to analyze security, compliance, and risk metrics to identify trends and drive continuous improvement.

Ability to communicate complex risk and compliance concepts clearly to both technical and non‑technical stakeholders.

Ability to collaborate effectively across cross‑functional teams to integrate governance, risk, and compliance practices into business processes.

Exceptional time management skills.

Excellent oral and written communication skills.

Strong interpersonal skills and ability to cultivate relationships with internal and external stakeholders, promoting diversity of people, perspectives and ideas.

Ability to work with all levels of staff and management.

Number of Openings Available 1

Worker Type: Employee

Company: BCBST BlueCross BlueShield of Tennessee, Inc.

BCBST will recruit, hire, train and promote individuals in all job classifications without regard to race, religion, color, age, sex, national origin, citizenship, pregnancy, veteran status, sexual orientation, physical or mental disability, gender identity, or any other characteristic protected by applicable law. Further information regarding BCBST's EEO Policies/Notices may be found by reviewing the following page: BCBST's EEO Policies/Notices

BlueCross BlueShield of Tennessee is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at BlueCross BlueShield of Tennessee via-email, the Internet or any other method without a valid, written Direct Placement Agreement in place for this position from BlueCross BlueShield of Tennessee HR/Talent Acquisition will not be considered. No fee will be paid in the event the applicant is hired by BlueCross BlueShield of Tennessee as a result of the referral or through other means.

As Tennessee's largest health benefit plan company, we've been helping Tennesseans find their own unique paths to good health since 1945. More than that, we're your neighbors and friends – fellow Tennesseans with deep roots of caring tradition, a focused approach to physical, financial and community good health for today, and a bright outlook for an even healthier tomorrow. At BCBST, we empower our employees to thrive both independently and collaboratively, creating a collective impact on the lives of our members. We seek talented individuals who excel in a team environment, share responsibility, and embrace accountability. We're also seeking candidates who are proficient in the Microsoft Office suite, including Microsoft Teams, organized, and capable of managing multiple assignments or projects simultaneously. Additional, strong interpersonal abilities along with strong oral and written communication skills are important across all roles at BCBST. We foster a culture where innovation is encouraged. That includes using AI enabled tools responsibly to support everyday work — guided by proven workflows, templates, and policies. As roles become more advanced, we expect employees to leverage AI more broadly to transform how we serve members. BCBST is a remote‑first organization with many employees working primarily from their homes. Each position within the company is classified as either fully remote, partially remote, or office based. BCBST hires employees for remote positions from across the U.S. with the exception of the following states: California, Massachusetts, New Hampshire, New Jersey, and New York. Applicants living in these states may move to an approved state prior to starting a position with BCBST at their own expense. If the position requires the individual to reside in Chattanooga, TN, they may be eligible for relocation assistance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Information Security Risk Analyst
Sr. Information Security Risk Analyst

BlueCross BlueShield of Tennessee • United States

Remote
USD 120,000 - 160,000
Sr. Clinical Business Analyst
Sr. Clinical Business Analyst

BlueCross BlueShield of Tennessee, Inc. • Chattanooga (TN)

Remote
USD 90,000 - 120,000
Sr. BAW Software Engineer
Sr. BAW Software Engineer

BlueCross BlueShield of Tennessee, Inc. • Chattanooga (TN)

Remote
USD 120,000 - 160,000
Remote-first organization
ECF Choices Support Coordinator (Maury, Williamson County)
ECF Choices Support Coordinator (Maury, Williamson County)

Able Too Work • Tennessee

Hybrid
USD 45,000 - 65,000
RN Medical Case Manager
RN Medical Case Manager

BlueCross BlueShield of Tennessee • Chattanooga (TN)

Remote
USD 65,000 - 90,000
Remote-first policy
ECF Choices Support Coordinator (Maury, Williamson County)
ECF Choices Support Coordinator (Maury, Williamson County)

African American Talent • Tennessee

Hybrid
USD 42,000 - 64,000
Mileage reimbursement
Underwriter
Underwriter

BlueCross BlueShield of Tennessee, Inc. • Chattanooga (TN)

Remote
USD 70,000 - 110,000
Remote work
IBM BAW Software Engineer
IBM BAW Software Engineer

BlueCross BlueShield of Tennessee, Inc. • Chattanooga (TN)

Remote
USD 110,000 - 150,000
Senior AI Engineer
Senior AI Engineer

BlueCross BlueShield of Tennessee, Inc. • Chattanooga (TN)

On-site
USD 140,000 - 180,000
Case Manager- Knoxville, TN
Case Manager- Knoxville, TN

BlueCross BlueShield of Tennessee, Inc. • Knoxville (TN)

Hybrid
USD 65,000 - 90,000