Cybersecurity Controls Assurance & GRC Automation Analyst
Job Description
Join Blue Cross and Blue Shield of Nebraska (BCBSNE) in a hybrid role based in Omaha, Nebraska where you can help validate and strengthen cybersecurity controls in a modern, highly regulated technology environment. This position combines hands-on security testing with GRC and continuous-control-monitoring to support audits, regulatory reviews, and remediation prioritization, with a clear focus on protecting members and the communities BCBSNE serves.
What you will do
- Shape how BCBSNE validates, measures, and strengthens cybersecurity controls.
- Conduct risk-based control assessments to evaluate control design, implementation, operating effectiveness, and evidence quality.
- Translate technical security testing results into practical risk insight to identify strengths, gaps, and improvement priorities.
- Work with automated penetration testing and attack simulation platforms to validate security posture.
- Identify misconfigurations and control failures across cloud, identity, endpoint, network, infrastructure, application, vulnerability management, and data-protection systems.
- Assess attack paths and recommend practical remediation actions.
- Support GRC and continuous-control-monitoring capabilities, including automated evidence collection, control testing, remediation tracking, risk management processes, dashboards, metrics, and reporting.
- Partner with cybersecurity, technology, risk, audit, and business teams to investigate issues.
- Support audits and regulatory reviews and participate in approved validation activities such as configuration testing, vulnerability and exploitability validation, attack-path analysis, and purple-team exercises.
- Convert findings into improvements that strengthen BCBSNE’s cyber resilience.
What you bring
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related field, or equivalent experience.
- 3 to 5 years of experience in cybersecurity assurance, security operations, cybersecurity engineering, penetration testing, IT audit, GRC, risk management, or a related area.
- Experience performing cybersecurity control testing and technical assessments such as configuration reviews, vulnerability validation, or security assessments.
- Working knowledge of frameworks including NIST, CIS Controls, HITRUST, HIPAA, or ISO 27001.
- Ability to interpret technical evidence and translate findings into practical risk and remediation recommendations.
Tools and standards you will use
- NIST, CIS Controls, HITRUST, HIPAA, ISO 27001
- MITRE ATT&CK
Location and travel
- Live within driving distance of the Omaha, Nebraska office.
- Remote flexibility with 1 to 2 days per week in the office.
- If living in an approved state (Florida, Iowa, Kansas, Minnesota, Missouri, Nebraska, North Dakota, or Texas), travel to headquarters may be required based on business needs.
Additional strengths (preferred)
- Experience with GRC or continuous-control-monitoring process platforms.
- Experience with penetration testing, red or purple teaming, attack-path analysis, or adversary-informed testing.
- Knowledge of MITRE ATT&CK and cloud, identity, and network and endpoint security concepts.
- Experience in healthcare, financial services, or another highly regulated industry.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, Security+, OSCP, or similar.
- Experience developing or improving cyber risk metrics, GRC dashboards, or executive-ready reporting.
- Comfort using automation, scripting, or workflow tools to streamline evidence collection, control testing, or remediation tracking.
- Ability to communicate technical cybersecurity issues clearly to both technical and non-technical stakeholders.
Visa sponsorship: BCBSNE is unable to sponsor or take over sponsorship of an employment visa at this time.
Similar Jobs
P