Jobs and Careers
EL

Third Party Cybersecurity GRC Advisor

Elevance Health
United Statesfull_timeVerifiedPosted 3 Jun 2026

About the role

Anticipated End Date:

2026-06-12

Position Title:

Third Party Cybersecurity GRC Advisor

Job Description:

Information Security Advisor ( Third Party Cybersecurity GRC Advisor )

Information Security Risk Management

Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianapolis, IN or Atlanta, GA office, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.

  • Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.

The Information Security Advisor is responsible for independently assessing, documenting, and monitoring cybersecurity risks associated with third-party vendors, service providers, and business partners. This role evaluates vendor security controls, reviews assurance evidence, identifies control gaps, supports remediation and risk acceptance decisions, and provides subject matter expertise throughout the vendor lifecycle.

How you will make an impact:

  • Evaluate vendor security documentation, including SOC reports, ISO certifications, HITRUST certifications, penetration test summaries, security questionnaires, policies, data flow diagrams, and remediation evidence.
  • Assess vendor controls related to access management, encryption, vulnerability management, incident response, business continuity, disaster recovery, cloud/SaaS security, secure software development, and data protection.
  • Provides first level engineering design functions and trouble resolution.
  • Communicate directly with vendors to clarify questionnaire responses, request supporting evidence, validate remediation status, and coordinate risk mitigation activities.
  • Support internal and external audit and compliance activities, including HIPAA, HITRUST, NIST, PCI DSS, SOC 2, and other healthcare or cybersecurity-related assessments.
  • Provides trouble resolution and serves as point of technical escalation on complex problems.
  • Leads or plans implementations for access management and network security technologies.
  • Develops testing plans to ensure quality of implementation.
  • Leads the investigation and reporting of data security events and incidents.
  • Provides system and network architecture support for information and network security technologies.
  • Provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies.
  • Maintains security incident response plans.
  • Represents major upgrades and business system replacements in change control.
  • Oversees Enterprise mix of vendor services.
  • Recommends changes and updates to strategy.
  • May act a key contact for setting vendor strategy.
  • Designs & engineers repetitive technical solutions based on business requirements and defined technology standards.
  • Mentor junior analysts by providing guidance on assessment quality, evidence review, control interpretation, risk documentation, and stakeholder communication.
  • Contribute to continuous improvement of third-party cybersecurity risk management standards, procedures, workflows, assessment templates, risk scoring methodology, dashboards, and reporting.

Minimum Requirements: 

  • Requires BS/BA degree in Information Technology or related field of study and a minimum of 5 years experience in systems support, system administration, system engineering, system security, access management, network security, network communications, computer networking, telecommunications, systems development and management, hardware, software, and/or data; or any combination of education and experience, which would provide an equivalent background.

Preferred Skills, Capabilities and Experiences:

  • Requires experience in planning and designing highly complex systems.
  • Experience with multiple technical and business disciplines strongly preferred.
  • Security Certifications: CISSP or other technical security certifications (e.g. Systems Security Certified Practitioner, Certification and Accreditation Professional) strongly preferred.
  • Bachelor’s degree in cybersecurity, information systems, computer science, risk management, business, or a related field; or equivalent combination of education, training, and

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Elevance Health

View company profile →