Jobs and Careers
BL

Manager Gov Risk & IT Complnce

Blue Cross Blue Shield of Michigan
United States, United Statesfull_timeVerifiedPosted 6 Nov 2024
💰 $171,500/yr($102,400/yr$171,500/yr)

About the role

This position coordinates all activities of personnel engaged in and responsible for the creation, implementation, and execution of strategies and programs designed to reduce and mitigate information security risk across the enterprise. The role supports enterprise-wide information security and assurance function, ensuring that confidentiality, integrity, and availability requirements of information systems and assets are identified and managed appropriately.

Essential Duties and Responsibilities:

  1. Responsible for identifying risks through a practical but comprehensive evaluation process.
  2. Responsible for improving the content, quality and timing of governance, risk and compliance analysis and reporting.
  3. Responsible for implementation of a proactive approach to risk management.
  4. Accountable to control the growth of governance, risk and compliance-related expenses.
  5. Responsible to direct and establish a timely and consistent approach to assess and improve compliance programs across the business.
  6. Responsible for establishing an enterprise-wide view of gaps and improve risk response strategies.
  7. Responsible for streamlining compliance programs across the enterprise to gain efficiencies and improve effectiveness.
  8. Responsible for establishing consistent policies and standards across the enterprise to enforce ownership and accountability.
  9. Leverages technology to aggregate controls, risk and compliance information to rapidly identify and report exceptions.
  10. Responsible for conducting Operational Risk Assessments and Compliance Reviews.
  11. Responsible for conducting and directing ERM assessments.
  12. Conducts business unit self-assessments and reporting package development. 
  13. Responsible for strategy, operations and management in several functional areas in order to have a broad understanding of risk and compliance management. 
  14. Provides vision, leadership, planning, project coordination and management for the development of a cost-effective department while concurrently facilitating efficient operations to meet current and future business needs within the organization.
  15. Represents company in community and industry, programs and conferences.
  16. Upon request, functions as the department head in the absence of the executive leader.
  17. Participates in the development of programs as a strategic partner that supports the company plan.
  18. Participates in development of annual departmental budget, monitor budget and identify budget discrepancies.  Researches cause and make recommendations.

EDUCATION AND EXPERIENCE:

  1. Bachelor’s degree in computer science or related field.  Relevant combination of education and experience may be considered in lieu of degree. 
  2. 7 years of experience leading information risk, security and governance teams, transforming functions and changing culture.
  3. Experience with leading the response to incidents, crises, and investigations with sensitivity, tenacity, and a focus on detail. 
  4. Extensive experience in information security architecture, consultative stakeholder management, and strategic planning. 
  5. Experience with classified networks, information classification, and confidentiality requirements associated with high security environments. 
  6. Demonstrated experience in information security program management required. HITRUST experience desired.

QUALIFICATIONS 

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

OTHER SKILLS AND ABILITIES:

  1. Ability to utilize industry standards and best practices to assess, advise, design, and/or recommend complex, enterprise-wide, regulatory compliance, risk management, and/or internal audit organization structures, policies and procedures, methodologies, toolkits, and templates.
  2. Ability to perform the following as it relates to Governance, Risk Management, and Compliance strategy, organization, policy and governance: program evaluation, risk assessment, controls identification and testing, state/federal regulatory audits, industry specific regulatory compliance (e.g., PCI, HIPAA, HiTrust etc.). 
  3. Ability to identify and address client needs: actively participating in client discussions and meetings; managing engagements including preparing concise, a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Blue Cross Blue Shield of Michigan

View company profile →