Jobs and Careers
BL

Sr. Director, GRC and Customer Trust

Blue Shield of California
United Statesfull_timeVerifiedPosted 21 Jan 2026

About the role

Your Role

The Sr. Director of GRC and Customer Trust is a strategic security leader responsible for governing technical controls, managing external and regulatory security assessments, overseeing third party and customer assurance, ensuring organizational resiliency and integrating our customers into Stellarus compliance process. This role drives proactive risk management, technical incident response, and compliance programs (e.g., HIPAA, PCI DSS, SOC2, NIST), partnering across technical functions, business, and regulatory stakeholders to ensure robust security, operational continuity, and strong external trust.

 

The successful candidate will lead and drive a model of customer trust and compliance by design through our product lifecycle with cross-functional teams, repeatable features to be ingested as part of design to safeguard data and assets. The candidate will provide expert guidance to support internal teams to ensure requirements are met. The Sr. Director of GRC and Customer Trust will report to the Chief Information Security Officer. Our leadership model is about developing great leaders at all levels and creating opportunities for our people to grow – personally, professionally, and financially. We are looking for leaders that are energized by creative and critical thinking, building and sustaining high-performing teams, getting results the right way, and fostering continuous learning.

 

Your Work

In this role, you will:

  • Lead Customer, External Assurance, and IT Risk Assurance teams with clear strategy and governance
  • Oversee all regulatory and customer technical assessments (PCI DSS, HIPAA, SOC 2, NIST CSF)
  • Ensure accurate, audit‑ready technical security documentation and timely responses to regulators, partners, and customers
  • Drive the full assessment lifecycle, including industry research and regulatory change management
  • Represent the organization at industry forums, elevating assessment and risk practices
  • Manage the Governance, Risk & Compliance (GRC) function and oversee enterprise controls design and effectiveness
  • Lead vendor security risk management and ensure compliance with regulatory, contractual, and cyber‑insurance requirements
  • Oversee IT compliance programs across HIPAA, PCI, NIST 800‑53, HITRUST, SOC 2 Type II, ISO 27001, and state laws
  • Implement compliance‑by‑design processes across technology and business platforms
  • Use data‑driven insights, KPIs, KRIs, and risk quantification to inform priorities and executive decision‑making
  • Primary interface for customer GRC requests
  • Design the Stellarus Trust Center platform for customer engagement
  • Centralize and automate customer self-service access to Stellarus security, privacy, and compliance information
  • Provide real-time customer access to approved security artifacts and key updates
  • Design governance models that support agile and DevSecOps delivery while meeting healthcare compliance
  • Translate regulatory and security requirements into clear, actionable controls for product teams
  • Partner with Technology and Security to embed automated safeguards (logging, monitoring, access controls)
  • Maintain continuous audit readiness for regulatory audits and customer security reviews
  • Lead the Technical Controls and Resiliency Assurance teams with a unified vision for enterprise safeguards
  • Oversee technical control frameworks, business continuity plans, and incident response integration (e.g., Stellarus)
  • Guide technical continuity lifecycle activities, ensuring seamless risk mitigation across platforms
  • Advance innovation to strengthen resiliency, control effectiveness, and operational excellence
  • Serve as a strategic advisor to Product, IT, Operations, and Legal leaders
  • Champion secure‑by‑default and risk‑informed product development
  • Mentor and develop GRC and IT Risk talent across direct and matrixed teams
  • Identify systemic risks and drive opportunities to streamline and strengthen enterprise controls
  • Deliver clear, actionable risk insights to executives and governance committees

 

Your Knowledge and Experience

  • Requires a Bachelor’s degree in Business, Finance, Economics, Public Health, or Information Technology
  • Minimum of one industry applicable security and risk or compliance certifications (CRISC, CISSP, CISM, CISA, etc) required
  • Requires at least 12 years of experience in IT Risk Management, Management Consulting, Technology Strategy or IT Compliance
  • Requires at least 6 years of people management experience
  • Proven experience in technology risk and compliance management, preferably in the healthcare industry, with the ability to coordinate cross functional teams of IT professionals

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Blue Shield of California

View company profile →