This role will lead the creation and deployment of defined and structured processes to support the evolving and maintaining of the cyber risk management program. The position requires working across the BCBSA organization to align cyber risk management with the organization's goals and outcomes. The role will utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies. The consultant will apply experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance. This role will support IT and information security leadership in making risk-informed decisions and shaping the future direction of BCBSA's cybersecurity program. The position involves assessing internal and third-party supplier risks, realistically translating them for both technical and non-technical audiences, and clearly articulating recommended actions and organizational impact. Specifically, this role will lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations. The role is responsible for providing Cyber Risk leadership and subject matter expertise on all assigned projects, identifying day-to-day task assignments, and providing technology and project management guidance on deliverables. The consultant will validate and ensure Cyber Risk requirements are thorough, testable, detailed, concise, and traceable. They will be accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders. Responsibilities include project planning, budget approvals, estimation, and management for all project deliverables, collaborating with Service Delivery managers as appropriate. The role requires proficiency in implementing cyber risk processes, leading teams to attain goals, pursuing excellence, and establishing discipline-specific best practices. The consultant is responsible for driving all project decisions, with a strong ability to make timely decisions and establish project governance. Collaboration with other team-members and peers, building trust, exhibiting a sense of urgency, being biased for action, and possessing good follow-up skills are essential. The role requires a customer-focused approach with the ability to persuade and drive consensus to resolve conflict and facilitate timely decision-making. The consultant will review and approve team progress reports, expenses, invoices, and contracts in a thorough and timely manner. They will review the status reports of team members and address issues as appropriate, and comply with and help enforce standard policies and procedures. Providing and seeking timely feedback to IT partners, peers, and team-members is expected. The role involves providing leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focusing on continuous improvement. The consultant will provide project team(s) business/technical leadership and guidance on day-to-day tasks, and is responsible for driving change for implementing process improvements and ensuring long-term compliance. Leading the creation and maintenance of methodologies and processes for the department is expected. The role is expected to lead multiple, simultaneous projects and time-critical deliverables. A formal risk register that drives security, governance, and ensures security findings are aligned with business objectives will be maintained. The consultant is responsible for maintaining positive working relationships with all groups, cross-functional teams, including technical teams. Identifying opportunities/needs and working with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure is required. Budget forecasts and estimates for Cyber Risk activities will be provided on a continuous basis, with responsibility for variance analysis and justifications, and following established BCBSA processes/procedures. The role involves providing status updates to Senior/Executive management and escalating risks/issues with customer issues appropriately and in a timely manner. Ensuring design, development, testing, and investigative activities lead to appropriate resolution is critical. Effectively and tactfully communicating relevant and potentially difficult/sensitive information to senior management is required. The consultant is responsible for engaging, understanding, and effectively communicating the needs of the business to IT teams/partners. Issues will be resolved and/or escalated, alternatives proposed, and expectations set or managed in a timely fashion. The role involves leading and managing delivery on multiple projects and is responsible for all project-related resource management, task prioritization, and development. Frequent Plan interactions via System Advisory Group or project communications are expected to ensure business solutions meet Plan needs and implementation/budget concerns are understood. Frequent project participation/collaboration is required to ensure technical solutions meet business needs.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior