Cybersecurity Controls Assurance & GRC Automation Analyst
Core
Validate, measure, and strengthen cybersecurity controls across a modern, highly regulated technology environment by performing risk-based control assessments and connecting technical security testing with practical risk insight.
Role type
Cybersecurity Controls Assurance & GRC Automation Analyst
Builds
Cybersecurity resilience and compliance posture for Blue Cross and Blue Shield of Nebraska members and communities
Domain
Healthcare / Cybersecurity & Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Cybersecurity control testing, technical assessments, configuration reviews, vulnerability validation, security assessments, NIST/CIS Controls/HITRUST/HIPAA/ISO 27001 frameworks, translating technical evidence into risk recommendations
Preferred skills
GRC or continuous-control-monitoring platforms, penetration testing/red/purple teaming/attack-path analysis, MITRE ATT&CK, cloud/identity/network/endpoint security, healthcare/financial services regulated industry experience, CISSP/CISM/CISA/CRISC/CGRC/Security+/OSCP certifications, cyber risk metrics/GRC dashboards/executive reporting, automation/scripting/workflow tools
Technologies
Penetration testing platforms, attack simulation platforms, cloud systems, identity systems, endpoint systems, network systems, infrastructure systems, application systems, vulnerability management systems, data-protection systems
Responsibilities
Perform risk-based control assessments to evaluate control design, implementation, and effectiveness; validate security posture and identify misconfigurations and control failures; assess attack paths and recommend remediation; support GRC and continuous-control-monitoring capabilities including automated evidence collection and reporting; partner with cybersecurity, technology, risk, audit, and business teams to investigate issues and support audits; participate in configuration testing, vulnerability validation, and purple-team exercises
Seniority
Mid-level, hands-on IC
