CybersecurityJobs.io
← Back to all jobs

Job Description

Join Blue Cross and Blue Shield of Nebraska (BCBSNE) in a hybrid role based in Omaha, Nebraska where you can help validate and strengthen cybersecurity controls in a modern, highly regulated technology environment. This position combines hands-on security testing with GRC and continuous-control-monitoring to support audits, regulatory reviews, and remediation prioritization, with a clear focus on protecting members and the communities BCBSNE serves.

What you will do

  • Shape how BCBSNE validates, measures, and strengthens cybersecurity controls.
  • Conduct risk-based control assessments to evaluate control design, implementation, operating effectiveness, and evidence quality.
  • Translate technical security testing results into practical risk insight to identify strengths, gaps, and improvement priorities.
  • Work with automated penetration testing and attack simulation platforms to validate security posture.
  • Identify misconfigurations and control failures across cloud, identity, endpoint, network, infrastructure, application, vulnerability management, and data-protection systems.
  • Assess attack paths and recommend practical remediation actions.
  • Support GRC and continuous-control-monitoring capabilities, including automated evidence collection, control testing, remediation tracking, risk management processes, dashboards, metrics, and reporting.
  • Partner with cybersecurity, technology, risk, audit, and business teams to investigate issues.
  • Support audits and regulatory reviews and participate in approved validation activities such as configuration testing, vulnerability and exploitability validation, attack-path analysis, and purple-team exercises.
  • Convert findings into improvements that strengthen BCBSNE’s cyber resilience.

What you bring

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related field, or equivalent experience.
  • 3 to 5 years of experience in cybersecurity assurance, security operations, cybersecurity engineering, penetration testing, IT audit, GRC, risk management, or a related area.
  • Experience performing cybersecurity control testing and technical assessments such as configuration reviews, vulnerability validation, or security assessments.
  • Working knowledge of frameworks including NIST, CIS Controls, HITRUST, HIPAA, or ISO 27001.
  • Ability to interpret technical evidence and translate findings into practical risk and remediation recommendations.

Tools and standards you will use

  • NIST, CIS Controls, HITRUST, HIPAA, ISO 27001
  • MITRE ATT&CK

Location and travel

  • Live within driving distance of the Omaha, Nebraska office.
  • Remote flexibility with 1 to 2 days per week in the office.
  • If living in an approved state (Florida, Iowa, Kansas, Minnesota, Missouri, Nebraska, North Dakota, or Texas), travel to headquarters may be required based on business needs.

Additional strengths (preferred)

  • Experience with GRC or continuous-control-monitoring process platforms.
  • Experience with penetration testing, red or purple teaming, attack-path analysis, or adversary-informed testing.
  • Knowledge of MITRE ATT&CK and cloud, identity, and network and endpoint security concepts.
  • Experience in healthcare, financial services, or another highly regulated industry.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, Security+, OSCP, or similar.
  • Experience developing or improving cyber risk metrics, GRC dashboards, or executive-ready reporting.
  • Comfort using automation, scripting, or workflow tools to streamline evidence collection, control testing, or remediation tracking.
  • Ability to communicate technical cybersecurity issues clearly to both technical and non-technical stakeholders.

Visa sponsorship: BCBSNE is unable to sponsor or take over sponsorship of an employment visa at this time.

Similar Jobs