Cyber Security Manager (Remote)
CareFirst, Inc.
- Baltimore, Maryland, United States
- Baltimore, Maryland, United States
About
Governance & Program Leadership
Lead the development, implementation, and ongoing maturity of the cybersecurity governance, risk, and compliance program.
Establish and maintain cybersecurity policies, standards, procedures, and control frameworks aligned with business objectives.
Serve as a trusted advisor to technology and business stakeholders on cybersecurity risk and control effectiveness.
Risk Management
Oversee cybersecurity risk assessments, including application, infrastructure, cloud, data, and third‑party risks.
Maintain cybersecurity risk registers, policy exception and risk acceptance processes, and remediation tracking.
Partner with business and technology teams to develop practical risk mitigation strategies aligned to organizational risk appetite.
Monitor emerging cyber threats, regulatory changes, and industry trends to proactively adjust risk posture.
Compliance & Regulatory Alignment
Ensure compliance with applicable regulations and frameworks such as NIST (800-53, 800-171, CSF), HIPAA, HITRUST, SOC, ISO 27001, and other relevant standards.
Support internal and external audits and assessments, including evidence collection, issue management, and remediation validation.
Act as a primary point of coordination for cybersecurity‑related regulatory and assurance activities.
Third‑Party Risk Management
Lead or support third‑party cybersecurity risk assessments, including review of SOC reports, vendor questionnaires, and other security attestations.
Partner with procurement, legal, and business teams to ensure appropriate cybersecurity requirements are embedded into vendor engagements.
Metrics, Reporting & Continuous Improvement
Define and maintain key risk and compliance metrics and dashboards to measure program effectiveness.
Prepare clear, concise risk reporting for senior leadership and governance forums.
Drive continuous improvement through process optimization, automation, and use of GRC tooling.
People Leadership
Lead, mentor, and develop a team of cybersecurity risk and compliance professionals.
Set priorities, manage workload, and support professional growth and performance management.
Foster a collaborative, accountable, and results‑driven team culture.
Qualifications Education Level:
Bachelor’s Degree in Computer Science, Information Technology, or a related field, or an additional four years of relevant work experience in lieu of a bachelor’s degree.
Experience:
5 years of related professional experience; 1 year of supervisory or progressive leadership experience.
Preferred Qualifications
Master’s Degree
Knowledge, Skills, and Abilities
Ability to multitask and manage multiple relationships.
Ability to lead and work as part of a team.
Ability to execute technology and tool automation processes.
Deep knowledge of risk treatment and mitigation strategies.
Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity.
Thorough understanding of cyber threats and vulnerabilities.
Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence. Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging.
Proven experience leading a large multidisciplinary organization.
Proven experience leading the end‑to‑end implementation of an enterprise GRC tool, including requirements gathering, configuration, integration with existing systems, user training, and ongoing optimization.
Salary Range $146,560 – $272,052
Equal Employment Opportunity CareFirst BlueCross BlueShield is an Equal Opportunity (EEO) employer. It is the policy of CareFirst to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
#J-18808-Ljbffr
Languages
- English
Notice for Users
This job comes from a TieTalent partner platform. Click "Apply Now" to submit your application directly on their site.