Job Title: Cybersecurity GRC Manager
Location: Massachusetts (Hybrid/Onsite as per company policy)
Type: Full-Time Permanent
Company: Blue Cross Blue Shield of Massachusetts
Overview:
Blue Cross Blue Shield of Massachusetts is seeking a Cybersecurity GRC Manager to lead governance risk and compliance initiatives across the enterprise. This role will oversee security controls maintain compliance with regulatory frameworks manage audits and support the development of a mature risk-aware security program.
Key Responsibilities:
- Lead the Governance Risk and Compliance (GRC) program for cybersecurity across the organization.
- Manage and enhance security policies standards and procedures aligned with business needs and regulatory requirements.
- Oversee risk assessments control evaluations and mitigation planning across enterprise systems and cloud environments.
- Own compliance efforts for frameworks such as NIST ISO 27001 SOC2 HIPAA HITRUST and internal policies.
- Manage enterprise cybersecurity audit cycles including internal audit external audit and third-party assessments.
- Partner with IT Legal Privacy Procurement and business units to ensure alignment of security controls and risk practices.
- Lead third-party/vendor risk management processes including due diligence and ongoing monitoring.
- Develop and track security metrics dashboards and reports for senior leadership.
- Provide oversight and guidance to analysts engineers and cross-functional teams supporting GRC efforts.
- Drive continuous improvement of the cybersecurity risk management framework tools and processes.
- Ensure security governance is embedded in new technologies applications and business processes.
Job Title: Cybersecurity GRC Manager Location: Massachusetts (Hybrid/Onsite as per company policy) Type: Full-Time Permanent Company: Blue Cross Blue Shield of Massachusetts Overview: Blue Cross Blue Shield of Massachusetts is seeking a Cybersecurity GRC Manager to lead governance risk and complian...
Job Title: Cybersecurity GRC Manager
Location: Massachusetts (Hybrid/Onsite as per company policy)
Type: Full-Time Permanent
Company: Blue Cross Blue Shield of Massachusetts
Overview:
Blue Cross Blue Shield of Massachusetts is seeking a Cybersecurity GRC Manager to lead governance risk and compliance initiatives across the enterprise. This role will oversee security controls maintain compliance with regulatory frameworks manage audits and support the development of a mature risk-aware security program.
Key Responsibilities:
- Lead the Governance Risk and Compliance (GRC) program for cybersecurity across the organization.
- Manage and enhance security policies standards and procedures aligned with business needs and regulatory requirements.
- Oversee risk assessments control evaluations and mitigation planning across enterprise systems and cloud environments.
- Own compliance efforts for frameworks such as NIST ISO 27001 SOC2 HIPAA HITRUST and internal policies.
- Manage enterprise cybersecurity audit cycles including internal audit external audit and third-party assessments.
- Partner with IT Legal Privacy Procurement and business units to ensure alignment of security controls and risk practices.
- Lead third-party/vendor risk management processes including due diligence and ongoing monitoring.
- Develop and track security metrics dashboards and reports for senior leadership.
- Provide oversight and guidance to analysts engineers and cross-functional teams supporting GRC efforts.
- Drive continuous improvement of the cybersecurity risk management framework tools and processes.
- Ensure security governance is embedded in new technologies applications and business processes.
View more
View less