1d ago
New

Sr. Information Security Risk Analyst

United StatesUnited States·ChattanoogaRemotesenior
Risk AnalystData & AI
3 views0 saves0 applied

Quick Summary

Overview

We are hiring a Senior Information Security Risk Analyst on our Governance, Risk & Compliance (GRC) team! In this role,

Technical Tools
Risk AnalystData & AI

We are hiring a Senior Information Security Risk Analyst on our Governance, Risk & Compliance (GRC) team!


In this role, you will serve as a technical subject matter expert in application security risk management, leading governance and oversight of our SAST/DAST application security scanning program, including static and dynamic application security testing. You will assess security vulnerabilities, evaluate findings from application and infrastructure scanning tools, and partner with application teams, incident management teams, and business stakeholders to prioritize and remediate risk. A key focus will be maximizing the value of the SAST/DAST platform, strengthening vulnerability management practices, improving risk visibility, and translating technical findings into actionable business risk insights. Successful candidates will bring strong expertise in application security testing, vulnerability management, and risk assessment, with hands-on experience using SAST/DAST platforms, a proven ability to drive remediation efforts, and a CISSP, CISM, CISA, CRISC, or comparable security certification.

 

Additionally, this role serves to support a high-visibility Data Governance initiative where you will help shape how enterprise data is governed, protected, and leveraged across the organization. You will partner with business leaders, data owners, security, privacy, compliance, and technology teams to establish governance standards, assess risk, monitor compliance, and strengthen data stewardship practices. This role provides the opportunity to influence enterprise-wide decisions and advance a mature Data Governance program. Successful candidates will be skilled relationship builders who can translate complex governance and regulatory requirements into practical business processes, drive accountability for data quality and policy adherence, and effectively balance regulatory expectations with business objectives.

 

Experience supporting SOC 2 audits, NIST frameworks and SSP development, third-party risk management, governance activities, and communicating complex security risks to both technical and non-technical audiences is highly valued. Strong collaboration, relationship-building, and influencing skills are essential, as this role will work across multiple teams to strengthen the organization's security posture.


Note:

  • Participation in on-call rotation is required for two weeks every 22 weeks.
  • Must be able to work Eastern Time business hours.
  • This is a remote, work-from-home position, but the final round of interviews will take place on-site in our Chattanooga, TN office.
  • Sponsorship is not available for this role.

Responsibilities

~1 min read
  • →Lead SOC 2 Audit Support – Coordinate audit activities including evidence collection, control validation, and auditor engagement.
  • →Manage and Validate Control Frameworks – Maintain control documentation, mappings, and narratives while partnering with control owners to ensure effectiveness and alignment with Trust Services Criteria and NIST frameworks.
  • →Track Audit & Remediation Activities – Oversee audit findings, remediation efforts, and timely closure of issues.
  • →Develop & Maintain NIST SSPs – Create and update System Security Plans (SSPs), including control implementations, inheritance, and system boundaries.
  • →Drive Security Awareness Programs – Design and manage training initiatives, including phishing simulations and targeted campaigns.
  • →Manage Policies & Governance Documentation – Oversee the full lifecycle of security policies, standards, and procedures to ensure compliance and audit readiness.
  • →Conduct Enterprise & Third-Party Risk Management – Perform risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation.
  • →Oversee Vulnerability Management – Track vulnerability remediation against SLAs and collaborate with teams to mitigate risks.
  • →Support Customer Security Assurance – Respond to RFPs and security questionnaires, ensuring accurate, compliant, and consistent security representations.
  • →Leadership – Leads by example, actively supporting initiatives across all GRC areas while fostering a culture of collaboration and shared accountability.

1

Employee

BCBST BlueCross BlueShield of Tennessee, Inc.

Applying for this job indicates your acknowledgement and understanding of the following statements:

BCBST will recruit, hire, train and promote individuals in all job classifications without regard to race, religion, color, age, sex, national origin, citizenship, pregnancy, veteran status, sexual orientation, physical or mental disability, gender identity, or any other characteristic protected by applicable law.

Further information regarding BCBST's EEO Policies/Notices may be found by reviewing the following page:

BCBST's EEO Policies/Notices

Location & Eligibility

Where is the job
Chattanooga, United States
Remote within one country
Who can apply
US

Listing Details

Posted
October 9, 2026
First seen
October 10, 2026
Last seen
October 10, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
65%
Scored at
October 10, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Sr. Information Security Risk Analyst