Cybersecurity Controls Assurance & GRC Automation Analyst

Posted 2 Days Ago
Be an Early Applicant
Omaha, NE, USA
In-Office
Mid level
Healthtech • Insurance
The Role
Performs risk-based cybersecurity control assessments, technical validation, configuration reviews, vulnerability and exploitability testing, attack-path analysis, and audit support. The role uses GRC and continuous-control-monitoring processes to automate evidence collection, track remediation, develop risk metrics, and improve reporting. Partners with cybersecurity, technology, risk, audit, and business teams to translate technical findings into practical remediation and strengthen cyber resilience.
Summary Generated by Built In

At Blue Cross and Blue Shield of Nebraska, we are a mission-driven organization dedicated to championing the health and well-being of our members and the communities we serve.

Our team is the power behind that promise. And, as the industry rapidly evolves and we seek ways to optimize business processes and customer experiences, there’s no greater time for forward-thinking professionals like you to join us in delivering on it! As a member of Team Blue, you’ll find purpose, opportunities and the support you need to build a meaningful career and make a powerful impact in our community.

In this role, you will help shape how BCBSNE validates, measures, and strengthens cybersecurity controls across a modern, highly regulated technology environment. You will perform risk-based control assessments that go beyond checklist compliance—evaluating whether controls are well designed, properly implemented, operating effectively, and supported by strong evidence. Your work will connect technical security testing with practical risk insight, helping the organization understand where defenses are strong, where gaps exist, and how to prioritize meaningful improvements.

The ideal candidate will live within driving distance of the Omaha, Nebraska office. This position allows remote flexibility but will have 1-2 days per week in the office.


If living in one of our approved states (Florida, Iowa, Kansas, Minnesota, Missouri, Nebraska, North Dakota, and Texas) – this person may travel to our headquarters based on business needs.


You will work hands-on with emerging, automated penetration testing and attack simulation platforms, and with cloud, identity, endpoint, network, infrastructure, application, vulnerability management, and data-protection systems to validate security posture, identify misconfigurations and control failures, assess attack paths, and recommend practical remediation. You will also support GRC and continuous-control-monitoring capabilities, including automated evidence collection, control testing, remediation tracking, risk management processes, dashboards, metrics, and reporting that make cybersecurity risk easier to see, explain, and act on.


This is an opportunity for a cyber/GRC analyst who enjoys bridging technical exploration with governance impact. You will partner with cybersecurity, technology, risk, audit, and business teams to investigate issues, support audits and regulatory reviews, participate in approved validation activities such as configuration testing, vulnerability and exploitability validation, attack-path analysis, and purple-team exercises, and help turn findings into improvements that strengthen BCBSNE’s cyber resilience and protect the members and communities we serve.

To be considered for this position you must have:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or related field, or equivalent experience.
  • Three to five years of experience in cybersecurity assurance, security operations, cybersecurity engineering, penetration testing, IT audit, GRC, risk management, or related experience.
  • Experience performing cybersecurity control testing, technical assessments, configuration reviews, vulnerability validation, or security assessments.
  • Working knowledge of cybersecurity frameworks such as NIST, CIS Controls, HITRUST, HIPAA, or ISO 27001.
  • Experience interpreting technical evidence and translating cybersecurity findings into practical risk and remediation recommendations.

The strongest candidates will also have:

  • Experience with GRC or continuous-control-monitoring processes platforms.
  • Experience with penetration testing, red/purple teaming, attack-path analysis, or adversary-informed testing.
  • Knowledge of MITRE ATT&CK and cloud, identity, network, and endpoint security concepts.
  • Experience in healthcare, financial services, or another highly regulated industry.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, Security+, OSCP, or similar.
  • Experience developing or improving cyber risk metrics, GRC dashboards, or executive-ready reporting.
  • Comfort using automation, scripting, or workflow tools to streamline evidence collection, control testing, or remediation tracking.
  • Ability to communicate technical cybersecurity issues clearly to both technical teams and non-technical stakeholders.

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Other duties may be assigned.


Ready to make an impact? Join a team where your skills, attitude, and ideas are valued—and where you’ll help shape the future of healthcare technology.

Learn more about what makes BCBSNE such an exceptional place to work by visiting NebraskaBlue.com/Careers.


We strongly believe that diversity of experience, perspective and background will lead to a better workplace for our employees and a better product for our customers and members.
**We are unable to sponsor or take over sponsorship of an employment visa at this time**


Learn more about what makes BCBSNE such an exceptional place to work by visiting NebraskaBlue.com/Careers.

We strongly believe that diversity of experience, perspective and background will lead to a better workplace for our employees and a better product for our customers and members.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related field, or equivalent experience.
  • Three to five years of experience in cybersecurity assurance, security operations, cybersecurity engineering, penetration testing, IT audit, GRC, risk management, or related experience.
  • Experience performing cybersecurity control testing, technical assessments, configuration reviews, vulnerability validation, or security assessments.
  • Working knowledge of cybersecurity frameworks such as NIST, CIS Controls, HITRUST, HIPAA, or ISO 27001.
  • Experience interpreting technical evidence and translating cybersecurity findings into practical risk and remediation recommendations.
  • Experience with GRC or continuous-control-monitoring platforms.
  • Experience with penetration testing, red or purple teaming, attack-path analysis, or adversary-informed testing.
  • Knowledge of MITRE ATT&CK and cloud, identity, network, and endpoint security concepts.
  • Experience in healthcare, financial services, or another highly regulated industry.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, CGRC, Security+, OSCP, or similar.
  • Experience developing or improving cyber risk metrics, GRC dashboards, or executive-ready reporting.
  • Comfort using automation, scripting, or workflow tools to streamline evidence collection, control testing, or remediation tracking.
  • Ability to communicate technical cybersecurity issues clearly to technical and non-technical stakeholders.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Omaha, NE
1,098 Employees
Year Founded: 1939

What We Do

To millions of Americans, Blue Cross and Blue Shield symbolizes peace of mind when it's needed most. That’s because, collectively, the Blue Cross and Blue Shield brands represent the largest and most experienced health care benefit companies in the country. At Blue Cross and Blue Shield of Nebraska, our story is all about you – the people we’ve been serving since 1939. As a company born and raised in Nebraska, we believe it’s our responsibility to be an active member of the communities where we live and work alongside our customers. We envision a health care world without confusion that adds more good years to peoples' lives, and we consider it an honor to be there for you when you need us. Thank you for letting us be part of your story. 1939 was the beginning of a long tradition of health care coverage in Nebraska. Blue Cross and Blue Shield of Nebraska is a mid-size Nebraska business whose mission is to lead the way in supporting patient-focused care. We see the future of healthcare as one without confusion that adds more good years to peoples'​ lives. As a Nebraska-based company, we believe it’s our responsibility to be an active member of the communities in which our customers live and work.

Similar Jobs

Samsara Logo Samsara

Accounting Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
83K-139K Annually

BlackLine Logo BlackLine

Senior Software Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
USA
1810 Employees
146K-183K Annually

Coursera + Udemy  Logo Coursera + Udemy

Chief Of Staff

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
181K-273K Annually

SambaSafety Logo SambaSafety

Director, Customer Success

Insurance • Logistics • Software • Transportation • Business Intelligence
Remote or Hybrid
United States
300 Employees
120K-150K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account