Cybersecurity Controls Assurance & GRC Automation Analyst
Job Summary
At Blue Cross and Blue Shield of Nebraska we are a mission-driven organization dedicated to championing the health and well-being of our members and the communities we serve.
Our team is the power behind that promise. And as the industry rapidly evolves and we seek ways to optimize business processes and customer experiences theres no greater time for forward-thinking professionals like you to join us in delivering on it! As a member of Team Blue youll find purpose opportunities and the support you need to build a meaningful career and make a powerful impact in our community.
In this role you will help shape how BCBSNE validates measures and strengthens cybersecurity controls across a modern highly regulated technology environment. You will perform risk-based control assessments that go beyond checklist complianceevaluating whether controls are well designed properly implemented operating effectively and supported by strong evidence. Your work will connect technical security testing with practical risk insight helping the organization understand where defenses are strong where gaps exist and how to prioritize meaningful improvements.The ideal candidate will live within driving distance of the Omaha Nebraska office. This position allows remote flexibility but will have 1-2 days per week in the office.
If living in one of our approved states (Florida Iowa Kansas Minnesota Missouri Nebraska North Dakota and Texas) this person may travel to our headquarters based on business needs.
You will work hands-on with emerging automated penetration testing and attack simulation platforms and with cloud identity endpoint network infrastructure application vulnerability management and data-protection systems to validate security posture identify misconfigurations and control failures assess attack paths and recommend practical remediation. You will also support GRC and continuous-control-monitoring capabilities including automated evidence collection control testing remediation tracking risk management processes dashboards metrics and reporting that make cybersecurity risk easier to see explain and act on.
This is an opportunity for a cyber/GRC analyst who enjoys bridging technical exploration with governance impact. You will partner with cybersecurity technology risk audit and business teams to investigate issues support audits and regulatory reviews participate in approved validation activities such as configuration testing vulnerability and exploitability validation attack-path analysis and purple-team exercises and help turn findings into improvements that strengthen BCBSNEs cyber resilience and protect the members and communities we serve.
To be considered for this position you must have:
- Bachelors degree in Cybersecurity Information Technology Computer Science Risk Management or related field or equivalent experience.
- Three to five years of experience in cybersecurity assurance security operations cybersecurity engineering penetration testing IT audit GRC risk management or related experience.
- Experience performing cybersecurity control testing technical assessments configuration reviews vulnerability validation or security assessments.
- Working knowledge of cybersecurity frameworks such as NIST CIS Controls HITRUST HIPAA or ISO 27001.
- Experience interpreting technical evidence and translating cybersecurity findings into practical risk and remediation recommendations.
The strongest candidates will also have:
- Experience with GRC or continuous-control-monitoring processes platforms.
- Experience with penetration testing red/purple teaming attack-path analysis or adversary-informed testing.
- Knowledge of MITRE ATT&CK and cloud identity network and endpoint security concepts.
- Experience in healthcare financial services or another highly regulated industry.
- Relevant certifications such as CISSP CISM CISA CRISC CGRC Security OSCP or similar.
- Experience developing or improving cyber risk metrics GRC dashboards or executive-ready reporting.
- Comfort using automation scripting or workflow tools to streamline evidence collection control testing or remediation tracking.
- Ability to communicate technical cybersecurity issues clearly to both technical teams and non-technical stakeholders.
To perform this job successfully an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge skill and or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Other duties may be assigned.
Ready to make an impact Join a team where your skills attitude and ideas are valuedand where youll help shape the future of healthcare technology.
Learn more about what makes BCBSNE such an exceptional place to work by visiting strongly believe that diversity of experience perspective and background will lead to a better workplace for our employees and a better product for our customers and members.
**We are unable to sponsor or take over sponsorship of an employment visa at this time**
Learn more about what makes BCBSNE such an exceptional place to work by visiting strongly believe that diversity of experience perspective and background will lead to a better workplace for our employees and a better product for our customers and members.
Required Experience:
IC
About Company
Blue Cross & Blue Shield of Nebraska offers a variety of health, vision, dental & travel insurance plans for groups, individuals and families at an affordable rate.