IT Governance Risk Compliance (GRC) Specialist - Hybrid

Posted 2025-04-06
Remote, USA Full-time Immediate Start

About the position

The GRC Specialist at Blue Cross Blue Shield of Arizona is responsible for the administration and development of the Governance, Risk, and Compliance (GRC) platform, along with associated IT processes and risk management. This role involves creating, editing, and publishing corporate policies and procedures, serving as a liaison for internal and external audits, and managing compliance and governance issues. The GRC Specialist will also perform analytics, manage remediation items, and report on the compliance health of assigned projects, all while fostering a culture of continuous process improvement.

Responsibilities
• Administer and develop the GRC platform and associated IT processes.
,
• Create, edit, and publish corporate and desktop policies, procedures, and standards.
,
• Serve as the IT internal and external audit liaison for regulatory issues, IT compliance, and governance.
,
• Perform analytics and manage remediation items related to compliance health of projects.
,
• Maintain a continuous process improvement work environment leveraging industry standards and best practices.
,
• Develop and maintain ongoing annual reviews of information security policies, standards, procedures, and processes.
,
• Conduct GRC tool user training sessions and provide ongoing support to end users.
,
• Perform risk and control effectiveness tests, risk analyses, and assessments.
,
• Assist in enhancing third-party risk management activities through refined assessment methodologies.
,
• Develop and maintain security awareness training for new hires and annual refreshers.
,
• Collaborate with internal and external auditors to facilitate security audits and assessments.

Requirements
• Bachelor's Degree in computer science, information systems, business, or related field.
,
• Certified Information Systems Security Practitioner (CISSP) certification.
,
• Certified Information Security Manager (CISM) certification.
,
• Certified Information Security Auditor (CISA) certification.
,
• 2-8 years of experience in information technology or computer systems depending on the level.
,
• 1-6 years of experience in information security and/or compliance depending on the level.
,
• 1-4 years of experience in IT audit and/or risk management depending on the level.

Nice-to-haves
• Master's Degree in computer science, information systems, business, or related field.
,
• Certified Risk and Information Systems Control (CRISC) certification.
,
• Experience with current and upcoming governance, risk, and compliance technologies.

Benefits
• Health insurance coverage
,
• 401k retirement savings plan
,
• Paid holidays
,
• Flexible scheduling options
,
• Professional development opportunities

Apply Job!

 

Similar Jobs

Back to Job Board