Sr. Mgr. Cybersecurity Risk
Horizon Blue Cross Blue Shield of New JerseyAbout the role
Horizon Blue Cross Blue Shield of New Jersey empowers our members to achieve their best health. For over 90 years, we have been New Jersey’s health solutions leader driving innovations that improve health care quality, affordability, and member experience. Our members are our neighbors, our friends, and our families. It is this understanding that drives us to better serve and care for the 3.5 million people who place their trust in us. We pride ourselves on our best-in-class employees and strive to maintain an innovative and inclusive environment that allows them to thrive. When our employees bring their best and succeed, the Company succeeds.
About the Role
This position is responsible for overseeing both the development and management of the Information Security Risk program and framework, as well as the technical implementation and ongoing support of the eGRC program. The role serves as a key representative on governance bodies, including the Third Party Oversight and Governance Council and the Broker Oversight and Governance Council.The incumbent is accountable for the overall health of Horizon BCBSNJ’s information protection environment, encompassing customers/members, subsidiaries, and suppliers. In partnership with the CSO, CISO, CCO, and other senior leaders, this role regularly engages with executive stakeholders across the organization’s supply chain to articulate risks and drive effective mitigation strategies.
This position coordinates cross-functional efforts to maximize the value of the Enterprise and Operational Risk Management framework, including the design, delivery, and execution of a consistent risk reporting model. The role collaborates closely with Information Security, Legal, Audit, Enterprise Risk Management, Vendor Management, and other key departments to optimize the use of the eGRC platform and to implement information security and risk management frameworks, policies, standards, and best practices.
Additionally, this role manages a team of professionals and serves as the primary point of contact for internal stakeholders on matters related to Information Security Risk and eGRC. It is also responsible for overseeing and reporting on regulatory and contractual compliance requirements.
What You'll Do
Define, lead, and manage all aspects of the Third Party Risk Management (TPRM) Program.
Identify, document, and communicate security risks and control deficiencies to business and IT stakeholders, driving awareness of emerging and relevant risks across Horizon BCBSNJ’s third-party landscape.
Establish and maintain third-party privacy and security policies and standards, and oversee program effectiveness through measurement, governance, and continuous improvement.
Serve as the primary information security risk interface to leadership teams, providing strategic guidance and insight on third-party and enterprise risk exposures.
Direct and manage the Information Security Risk Management (ISRM) program, including team leadership, budget planning, resource allocation, and development of enterprise risk metrics and reporting.
Ensure IT project risk assessments, application security reviews, and vendor risk assessments are integrated into the eGRC platform to support compliance with corporate information security policies and standards.
Act as a trusted advisor to business stakeholders by maintaining ongoing awareness and alignment on identified and emerging risks.
Partner with Internal Audit, Corporate Compliance, Office of General Counsel, and Risk Management to remediate identified issues, and track security-related findings within the eGRC system.
Provide subject matter expertise and security risk consulting for third-party contracts (MSAs, BAAs, SOWs) and hosted services (SaaS, PaaS, IaaS) across all Strategic Sourcing engagements.
Serve as the liaison to Enterprise Risk Management (ERM) for technology and cybersecurity risks, including collaboration on annual risk quantification for Horizon BCBSNJ’s Own Risk and Solvency Assessment (ORSA).
Collaborate with the Director of Information Security and key stakeholders to enhance eGRC program procedures, controls, and the overall ISRM framework.
Lead and manage security initiatives that address identified risks and business requirements, ensuring compliance with regulatory, legal, and industry best practices.
What You Bring
Education/Experience:
Minimum high school diploma or GED
Industry certifications required (e.g., CISSP, CISA, CRISC, or equivalent).
Experience establishing & maintaining relationships with individuals at all lev
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s