Senior Cybersecurity Compliance Lead Consultant

Blue Cross and Blue Shield AssociationChicago, IL

About The Position

This role will lead the creation and deployment of defined and structured processes to support the evolving and maintaining of the cyber risk management program. The consultant will work across the BCBSA organization to align cyber risk management with the organization's goals and outcomes. They will utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies. The role requires applying experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance. This position will support IT and information security leadership in making risk-informed decisions and shaping the future direction of BCBSA's cybersecurity program. The consultant will assess internal and third-party supplier risks, translate them for both technical and non-technical audiences, and clearly articulate recommended actions and organizational impact. Specifically, this role will lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations. The consultant is responsible for providing Cyber Risk leadership and subject matter expertise on all assigned projects, identifying day-to-day task assignments, and providing technology and project management guidance on deliverables. They will validate and ensure Cyber Risk requirements are thorough, testable, detailed, concise, and traceable. The role is accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders. Responsibilities include project planning, budget approvals, estimation, and management for all project deliverables, collaborating with Service Delivery managers as appropriate. The consultant will be proficient in implementing cyber risk processes, lead teams to attain goals, pursue excellence, and establish discipline-specific best-practices. They will drive all project decisions, possess a strong ability to make timely decisions, and establish project governance. Collaboration with other team-members and peers, building trust, exhibiting a sense of urgency, being biased for action, and possessing good follow-up skills are essential. The role requires being customer-focused with the ability to persuade and drive consensus to resolve conflict and facilitate timely decision-making. The consultant will review and approve team progress reports, expenses, invoices, and contracts thoroughly and in a timely manner. They will review the status reports of team members and address issues as appropriate, and comply with and help enforce standard policies and procedures. Providing and seeking timely feedback to IT partners, peers, and team-members is expected. The consultant will provide leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focusing on continuous improvement. They will provide project team(s) business/technical leadership and guidance on day-to-day tasks, and drive change for implementing process improvements and ensuring long-term compliance. The role leads the creation and maintenance of methodologies and processes for the department and is expected to lead multiple, simultaneous projects and time-critical deliverables. A formal risk register will be maintained that drives security, governance, and ensures security findings are aligned with business objectives. The consultant is responsible for maintaining positive working relationships with all groups, cross-functional teams, including technical teams. They will identify opportunities/needs and work with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure. Budget forecasts and estimates for Cyber Risk activities will be provided on a continuous basis, including variance analysis and justifications, and following established BCBSA processes/procedures. The consultant will provide status updates to Senior/Executive management and escalate risks/issues with customer issues appropriately and in a timely manner. They will ensure design, development, testing, and investigative activities lead to appropriate resolution. Effective and tactful communication of relevant and potentially difficult/sensitive information to senior management is required. The consultant will engage, understand, and effectively communicate the needs of the business to IT teams/partners, and resolve and/or escalate issues, propose alternatives, and set or manage expectations in a timely fashion. Responsibilities include leading and managing delivery on multiple projects and being responsible for all project-related resource management, task prioritization, and development. Frequent Plan interactions via System Advisory Group or project communications are expected to ensure business solutions meet Plan needs and implementation/budget concerns are understood. Frequent project participation/collaboration is required to ensure technical solutions meet business needs.

Requirements

  • Bachelor's Degree IT, information Security, Risk or IT Management, Computer Science, or a related field; or equivalent work experience
  • 10+ Years career experience in IT or a closely related field
  • Experience leveraging automation and AI-enabled solutions to improve compliance monitoring, reporting, and operational efficiency.
  • Knowledge of national and international regulatory and compliance frameworks such as NIST Cybersecurity Framework, ISO 27001, EU DPD, HIPAA/HITECH.
  • Extensive knowledge in the use of Project Management methodologies and tools, and change management techniques.
  • Demonstrated leadership, mentoring, and project management skills.
  • Understanding of current application cyber risk development methodologies and risks, researching emerging technologies and possible application to the business.
  • Deep knowledge of FedRAMP requirements, continuous monitoring practices, control implementation, evidence management, and audit readiness.
  • Strong understanding of NIST cybersecurity frameworks, risk management, cloud security, and regulatory compliance obligations.
  • Ability to translate complex compliance requirements into scalable, business-integrated processes and controls.
  • Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.

Responsibilities

  • Lead the creation and deployment of defined and structured processes to support evolving and maintaining the cyber risk management program.
  • Work across the BCBSA organization to align cyber risk management with the organization's goals and outcomes.
  • Utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies.
  • Apply experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance.
  • Support IT and information security leadership in making risk informed decisions and shaping the future direction of BCBSA's cybersecurity program.
  • Assess internal and third-party supplier risks, realistically translate them for both technical and non-technical audiences, and clearly articulate recommended actions and organizational impact.
  • Lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations.
  • Provide Cyber Risk leadership and subject matter expertise on all assigned projects.
  • Identify day-to-day task assignments and provide technology and project management guidance on deliverables.
  • Validate and ensure Cyber Risk requirements are thorough, testable, detailed, concise and traceable.
  • Accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders.
  • Responsible for project planning, budget approvals, estimation and management for all project deliverables, collaborates with Service Delivery managers as appropriate.
  • Implement cyber risk processes, lead teams to attain goals, pursue excellence and establish discipline specific best-practices.
  • Drive all project decisions, make timely decisions and establish project governance.
  • Collaborate with other team-members, peers and build trust, exhibit sense of urgency, biased for action and possess good follow-up skills.
  • Be customer focused with ability to persuade and drive consensus to resolve conflict and facilitate timely decision making.
  • Review and approve team progress reports, expenses, invoices and contracts in a thorough and timely manner.
  • Review the status reports of team members and address issues as appropriate.
  • Comply with and help enforce standard policies and procedures.
  • Provide and seek timely feedback to IT partners, peers and team-members.
  • Provide leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focused on continuous improvement.
  • Provide project team(s) business/technical leadership and guidance on day-to-day tasks.
  • Drive change for implementing process improvements and ensuring long term compliance.
  • Lead the creation and maintenance of methodologies and processes for the department.
  • Lead multiple, simultaneous projects and time-critical deliverables.
  • Maintain a formal risk register that drives security, governance and ensures security findings are aligned with business objectives.
  • Maintain positive working relationships with all groups, cross-functional teams, including technical.
  • Identify opportunities/needs and work with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure.
  • Provide budget forecasts and estimates for Cyber Risk activities on a continuous basis.
  • Responsible for variance analysis and justifications and following the established BCBSA processes/procedures.
  • Provide status updates to Senior/Executive management.
  • Escalate risks/issues with customer issues appropriately and in a timely manner.
  • Ensure design, development, testing and investigative activities lead to appropriate resolution.
  • Effectively and tactfully communicate relevant and potentially difficult/sensitive information to senior management.
  • Engage, understand and effectively communicate needs of business to IT teams/partners.
  • Resolve and/or escalate issues, propose alternatives, and set or manage expectations in a timely fashion.
  • Lead and manage delivery on multiple projects and responsible for all project related resource management, task-prioritization and development.
  • Ensure business solutions meet Plan needs and implementation/budget concerns are understood through frequent Plan interactions via System Advisory Group or project communications.
  • Ensure technical solutions meet business needs through frequent project participation/collaboration.

Benefits

  • paid time off
  • 11 holidays
  • medical/dental/vision insurance
  • generous 401(k) matching
  • lifestyle spending account
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service