Senior Cybersecurity Compliance Lead Consultant

Blue Cross Blue Shield AssociationChicago, IL
$157,600 - $228,550

About The Position

This role will lead the creation and deployment of defined and structured processes to support the evolving and maintaining of the cyber risk management program. The position requires working across the BCBSA organization to align cyber risk management with the organization's goals and outcomes. The role will utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies. The consultant will apply experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance. This role will support IT and information security leadership in making risk-informed decisions and shaping the future direction of BCBSA's cybersecurity program. The position involves assessing internal and third-party supplier risks, realistically translating them for both technical and non-technical audiences, and clearly articulating recommended actions and organizational impact. Specifically, this role will lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations. The role is responsible for providing Cyber Risk leadership and subject matter expertise on all assigned projects, identifying day-to-day task assignments, and providing technology and project management guidance on deliverables. The consultant will validate and ensure Cyber Risk requirements are thorough, testable, detailed, concise, and traceable. They will be accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders. Responsibilities include project planning, budget approvals, estimation, and management for all project deliverables, collaborating with Service Delivery managers as appropriate. The role requires proficiency in implementing cyber risk processes, leading teams to attain goals, pursuing excellence, and establishing discipline-specific best practices. The consultant is responsible for driving all project decisions, with a strong ability to make timely decisions and establish project governance. Collaboration with other team-members and peers, building trust, exhibiting a sense of urgency, being biased for action, and possessing good follow-up skills are essential. The role requires a customer-focused approach with the ability to persuade and drive consensus to resolve conflict and facilitate timely decision-making. The consultant will review and approve team progress reports, expenses, invoices, and contracts in a thorough and timely manner. They will review the status reports of team members and address issues as appropriate, and comply with and help enforce standard policies and procedures. Providing and seeking timely feedback to IT partners, peers, and team-members is expected. The role involves providing leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focusing on continuous improvement. The consultant will provide project team(s) business/technical leadership and guidance on day-to-day tasks, and is responsible for driving change for implementing process improvements and ensuring long-term compliance. Leading the creation and maintenance of methodologies and processes for the department is expected. The role is expected to lead multiple, simultaneous projects and time-critical deliverables. A formal risk register that drives security, governance, and ensures security findings are aligned with business objectives will be maintained. The consultant is responsible for maintaining positive working relationships with all groups, cross-functional teams, including technical teams. Identifying opportunities/needs and working with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure is required. Budget forecasts and estimates for Cyber Risk activities will be provided on a continuous basis, with responsibility for variance analysis and justifications, and following established BCBSA processes/procedures. The role involves providing status updates to Senior/Executive management and escalating risks/issues with customer issues appropriately and in a timely manner. Ensuring design, development, testing, and investigative activities lead to appropriate resolution is critical. Effectively and tactfully communicating relevant and potentially difficult/sensitive information to senior management is required. The consultant is responsible for engaging, understanding, and effectively communicating the needs of the business to IT teams/partners. Issues will be resolved and/or escalated, alternatives proposed, and expectations set or managed in a timely fashion. The role involves leading and managing delivery on multiple projects and is responsible for all project-related resource management, task prioritization, and development. Frequent Plan interactions via System Advisory Group or project communications are expected to ensure business solutions meet Plan needs and implementation/budget concerns are understood. Frequent project participation/collaboration is required to ensure technical solutions meet business needs.

Requirements

  • Bachelor's Degree IT, information Security, Risk or IT Management, Computer Science, or a related field; or equivalent work experience
  • 10+ Years career experience in IT or a closely related field
  • Experience leveraging automation and AI-enabled solutions to improve compliance monitoring, reporting, and operational efficiency.
  • Knowledge of national and international regulatory and compliance frameworks such as NIST Cybersecurity Framework, ISO 27001, EU DPD, HIPAA/HITECH.
  • Extensive knowledge in the use of Project Management methodologies and tools, and change management techniques.
  • Demonstrated leadership, mentoring, and project management skills.
  • Understanding of current application cyber risk development methodologies and risks, researching emerging technologies and possible application to the business.
  • Deep knowledge of FedRAMP requirements, continuous monitoring practices, control implementation, evidence management, and audit readiness.
  • Strong understanding of NIST cybersecurity frameworks, risk management, cloud security, and regulatory compliance obligations.
  • Ability to translate complex compliance requirements into scalable, business-integrated processes and controls.
  • Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.

Responsibilities

  • Lead the creation and deployment of defined and structured processes to support evolving and maintaining the cyber risk management program.
  • Work across the BCBSA organization to align cyber risk management with the organization's goals and outcomes.
  • Utilize both analytical and qualitative assessment approaches to identify, assess, and develop appropriate mitigation plans and strategies.
  • Apply experience to effectively manage cyber risk at technical and non-technical levels to help the organization understand where and how to maintain target business risk tolerance.
  • Support IT and information security leadership in making risk informed decisions and shaping the future direction of BCBSA's cybersecurity program.
  • Assess internal and third-party supplier risks, realistically translate them for both technical and non-technical audiences, and clearly articulate recommended actions and organizational impact.
  • Lead BCBSA’s Federal Risk and Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-enabled compliance operating model that embeds regulatory controls, continuous monitoring, audit readiness, and risk management into enterprise technology and business operations.
  • Provide Cyber Risk leadership and subject matter expertise on all assigned projects.
  • Identify day-to-day task assignments and provide technology and project management guidance on deliverables.
  • Validate and ensure Cyber Risk requirements are thorough, testable, detailed, concise and traceable.
  • Accountable for project deliverables, estimates, project team-structures, technical artifacts, and engagement of all project stakeholders.
  • Responsible for project planning, budget approvals, estimation and management for all project deliverables, collaborates with Service Delivery managers as appropriate.
  • Implement cyber risk processes, lead teams to attain goals, pursue excellence and establish discipline specific best-practices.
  • Drive all project decisions, make timely decisions and establish project governance.
  • Collaborate with other team-members, peers and build trust, exhibit sense of urgency, biased for action and possess good follow-up skills.
  • Be customer focused with ability to persuade and drive consensus to resolve conflict and facilitate timely decision making.
  • Review and approve team progress reports, expenses, invoices and contracts in a thorough and timely manner.
  • Review the status reports of team members and address issues as appropriate.
  • Comply with and help enforce standard policies and procedures.
  • Provide and seek timely feedback to IT partners, peers and team-members.
  • Provide leadership as a product champion for cyber risk in the Governance, Risk and Compliance technology platform and Cyber Risk direction to business by establishing a vision and risk strategy to meet established project goals and objectives, while focused on continuous improvement.
  • Provide project team(s) business/technical leadership and guidance on day-to-day tasks.
  • Drive change for implementing process improvements and ensuring long term compliance.
  • Lead the creation and maintenance of methodologies and processes for the department.
  • Lead multiple, simultaneous projects and time-critical deliverables.
  • Maintain a formal risk register that drives security, governance and ensures security findings are aligned with business objectives.
  • Maintain positive working relationships with all groups, cross-functional teams, including technical.
  • Identify opportunities/needs and work with team-leads and other directors to enhance relationships and influence decisions outside of direct functional reporting structure.
  • Provide budget forecasts and estimates for Cyber Risk activities on a continuous basis.
  • Responsible for variance analysis and justifications and following the established BCBSA processes/procedures.
  • Provide status updates to Senior/Executive management.
  • Escalate risks/issues with customer issues appropriately and in a timely manner.
  • Ensure design, development, testing and investigative activities lead to appropriate resolution.
  • Effectively and tactfully communicate relevant and potentially difficult/sensitive information to senior management.
  • Engage, understand and effectively communicate needs of business to IT teams/partners.
  • Resolve and/or escalate issues, propose alternatives, and set or manage expectations in a timely fashion.
  • Lead and manage delivery on multiple projects and responsible for all project related resource management, task-prioritization and development.
  • Participate in Plan interactions via System Advisory Group or project communications to ensure business solutions meet Plan needs and implementation/budget concerns are understood.
  • Collaborate on projects to ensure technical solutions meet business needs.

Benefits

  • paid time off
  • 11 holidays
  • medical/dental/vision insurance
  • generous 401(k) matching
  • lifestyle spending account
  • annual bonus incentive pay
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service