Information Security Risk and Governance Specialist, Senior
Blue Shield of CaliforniaAbout the role
This role supports Stellarus within the Ascendiun Family of Companies. The Risk Management & Controls Assurance team delivers actionable insights by quantifying IT and business risk to increase resilience while driving a security culture. This Information Security Risk & Governance Specialist, Senior role will report to the Director working as a Risk Quantification Analyst. This position will play a critical role in identifying, evaluating, and quantifying risks, supporting executive decision-making, and driving data-driven business insights. The ideal candidate will bring thought leadership, technical expertise, and a proactive approach to evolve the existing risk management program.
Our leadership model is about developing great leaders at all levels and creating opportunities for our people to grow – personally, professionally, and financially. We are looking for leaders that are energized by creative and critical thinking, building and sustaining high-performing teams, getting results the right way, and fostering continuous learning.
In this role, you will:
- Program Leadership: Lead and further develop the existing risk quantification function, ensuring alignment with the FAIR methodology, NIST CSF 2.0, Unified Control Framework (UCF) and healthcare regulatory requirements (e.g., HIPAA, PCI).
- Risk Analysis: Oversee and perform detailed quantitative analysis on IT, operational and business risks using ThreatConnect and other FAIR-based platforms. Translate quantified risks into financial and business terms to support risk appetite, risk tolerance, and risk-informed decision-making.
- Risk Scenario Development: Design and lead scenario analyses and simulations to evaluate risks related to cybersecurity, IT operations, third parties, and strategic initiatives. Provide quantified insights to support investment justification, control prioritization, and vendor or partner selection.
- Cross-Functional Collaboration: Partner with stakeholders in IT, Enterprise Architecture, Finance, and Operations to ensure risk quantification informs business strategy. Support executive and board-level risk reporting with clear, actionable insights.
- Metrics, Data & Reporting: Develop and implement metrics, KRIs, and KPIs to monitor and communicate risk exposures, emerging trends, and mitigation outcomes. Leverage enterprise data warehouse and analytics platforms to produce timely, accurate, and transparent reporting.
- Thought Leadership and Change Adoption: Act as an internal champion for quantitative risk management, fostering adoption across all three lines of defense. Stay current with industry best practices, frameworks, and tools; recommend new approaches to advance program maturity.
Your Knowledge and Experience
- Requires Bachelor’s degree preferably in one of the following: Mathematics, Statistics, Risk Management, Business, Computer Science, or a related field desired
- Requires 5 years of related experience
- Certifications: FAIR certification strongly preferred; additional certifications such as CRISC, CISA, CISSP, or HITRUST are a plus.
- Technical Skills: Experience with ThreatConnect or similar FAIR-based quantification platforms. Strong data analytics and reporting experience (Tableau, Power BI, etc.); SQL and data warehouse knowledge a plus.
- Communication Skills: Proven ability to communicate complex risk concepts to executives, boards, regulators, and non-technical stakeholders.
- Analytical & Strategic Skills: Demonstrated ability to build quantitative models, interpret results, and deliver actionable insights that influence high-level business decisions
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s