We’re looking for a Manager of IT Governance, Risk, and Compliance (GRC) who enjoys helping teams navigate risk and compliance in a practical, collaborative way. This role plays an important part in keeping our technology environment secure, compliant, and aligned with our business goals—without slowing innovation.
In this role, you’ll work closely with partners across IT, Security, Internal/External Audit, Legal, Privacy, and the business to turn regulatory requirements and risk frameworks into solutions that actually work in the real world. You’ll help guide risk assessments, develop and improve policies and controls, support audits, and strengthen our overall GRC program in a way that’s thoughtful and sustainable.
We’re looking for someone who has technical know-how along with the ability to communicate clearly, build strong relationships, and take a balanced, risk‑based approach. Ideal candidates will have experience presenting to executive audiences, proficiency with PowerBI and experience in healthcare (or other regulated industries).
Note:
This is a fully remote role, but onsite travel to our Chattanooga, Tennessee headquarters may be required for final interviews.
Sponsorship is not available for this role.
Job Duties & Responsibilities
o Manage information risk management program including facilitated risk decisions with decision making authorities and being an engaged partner with lines of business.
o Develop and implement an effective policy compliance monitoring and enforcement program.
o Manage the security operations and/or engineering functions including incident response, security monitoring, security design and engineering and security architecture.
o Develop and manage Enterprise Information Security Threat Management Program.
o Manage teams tasked with vulnerability discovery and reporting.
o Coordinate the use of external resources involved in the performance of security testing (i.e., penetration tests, vulnerability scans).
o Ensure that an Information Security training program is addressed as part of the overall compliance training to ensure the organization’s workforce is knowledgeable of Information Security policies, practices and relevant guidance appropriate to their role in the organization.
Job Qualifications
Education
Experience
Skills/Certifications
N/A
Number of Openings Available
1Worker Type:
EmployeeCompany:
BCBST BlueCross BlueShield of Tennessee, Inc.Applying for this job indicates your acknowledgement and understanding of the following statements:
BCBST will recruit, hire, train and promote individuals in all job classifications without regard to race, religion, color, age, sex, national origin, citizenship, pregnancy, veteran status, sexual orientation, physical or mental disability, gender identity, or any other characteristic protected by applicable law.
Further information regarding BCBST's EEO Policies/Notices may be found by reviewing the following page:
BlueCross BlueShield of Tennessee is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at BlueCross BlueShield of Tennessee via-email, the Internet or any other method without a valid, written Direct Placement Agreement in place for this position from BlueCross BlueShield of Tennessee HR/Talent Acquisition will not be considered. No fee will be paid in the event the applicant is hired by BlueCross BlueShield of Tennessee as a result of the referral or through other means.