This role will lead the creation and deployment of defined and structured processes to support the evolving and maintaining of the cyber risk management program. The consultant will work across the BCBSA organization to align cyber risk management with the organization's goals and outcomes. They will utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies. The role requires applying experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance. This position will support IT and information security leadership in making risk-informed decisions and shaping the future direction of BCBSA's cybersecurity program. The consultant will assess internal and third-party supplier risks, translate them for both technical and non-technical audiences, and clearly articulate recommended actions and organizational impact. Specifically, this role will lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations. The consultant is responsible for providing Cyber Risk leadership and subject matter expertise on all assigned projects, identifying day-to-day task assignments, and providing technology and project management guidance on deliverables. They will validate and ensure Cyber Risk requirements are thorough, testable, detailed, concise, and traceable. The role is accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders. Responsibilities include project planning, budget approvals, estimation, and management for all project deliverables, collaborating with Service Delivery managers as appropriate. The consultant will be proficient in implementing cyber risk processes, lead teams to attain goals, pursue excellence, and establish discipline-specific best-practices. They will drive all project decisions, possess a strong ability to make timely decisions, and establish project governance. Collaboration with other team-members and peers, building trust, exhibiting a sense of urgency, being biased for action, and possessing good follow-up skills are essential. The role requires being customer-focused with the ability to persuade and drive consensus to resolve conflict and facilitate timely decision-making. The consultant will review and approve team progress reports, expenses, invoices, and contracts thoroughly and in a timely manner. They will review the status reports of team members and address issues as appropriate, and comply with and help enforce standard policies and procedures. Providing and seeking timely feedback to IT partners, peers, and team-members is expected. The consultant will provide leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focusing on continuous improvement. They will provide project team(s) business/technical leadership and guidance on day-to-day tasks, and drive change for implementing process improvements and ensuring long-term compliance. The role leads the creation and maintenance of methodologies and processes for the department and is expected to lead multiple, simultaneous projects and time-critical deliverables. A formal risk register will be maintained that drives security, governance, and ensures security findings are aligned with business objectives. The consultant is responsible for maintaining positive working relationships with all groups, cross-functional teams, including technical teams. They will identify opportunities/needs and work with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure. Budget forecasts and estimates for Cyber Risk activities will be provided on a continuous basis, including variance analysis and justifications, and following established BCBSA processes/procedures. The consultant will provide status updates to Senior/Executive management and escalate risks/issues with customer issues appropriately and in a timely manner. They will ensure design, development, testing, and investigative activities lead to appropriate resolution. Effective and tactful communication of relevant and potentially difficult/sensitive information to senior management is required. The consultant will engage, understand, and effectively communicate the needs of the business to IT teams/partners, and resolve and/or escalate issues, propose alternatives, and set or manage expectations in a timely fashion. Responsibilities include leading and managing delivery on multiple projects and being responsible for all project-related resource management, task prioritization, and development. Frequent Plan interactions via System Advisory Group or project communications are expected to ensure business solutions meet Plan needs and implementation/budget concerns are understood. Frequent project participation/collaboration is required to ensure technical solutions meet business needs.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior