Sr. Information Risk Analyst

Posted An Hour Ago
Be an Early Applicant
Boston, MA, USA
In-Office
111K-136K Annually
Senior level
Healthtech
The Role
Leads third-party and technology risk assessments across vendors, applications, systems, and business processes. Evaluates contractual safeguards, compliance obligations, vulnerabilities, and emerging risks, translating technical findings into actionable business guidance and executive dashboards. Partners with Legal, Procurement, Information Security, and business stakeholders on mitigation strategies, HIPAA compliance, governance, KRIs, policy development, remediation tracking, and risk program improvements. Mentors colleagues and advises teams on embedding risk management throughout initiative planning and delivery.
Summary Generated by Built In
Ready to help us transform healthcare? Bring your true colors to blue. 

What we need

The Senior Information Risk Analyst is a risk management professional, a versatile technical risk and information security expert, and a highly valued partner within the Information Risk Management (IRM) team. In this role, you will evaluate the organization's technology risk posture by conducting objective, fact-based assessments of existing and emerging third parties, systems, and applications. By analyzing these findings through a pragmatic, risk-based framework, you will partner directly with business stakeholders to design practical mitigation strategies that align with the organization's overall risk tolerance and business objectives. A critical component of this position involves translating complex technology and digital threats into clear, actionable business insights.


This position is open to candidates based in Massachusetts as well as remote, US-based candidates.


Your Day to Day

  • Perform vendor risk assessments to identify, evaluate and communicate risks to ensure they are properly understood and managed in alignment with organizational risk appetite, as well as applicable legal, regulatory, contractual and organizational requirements throughout the lifecycle of the relationship with the vendor.
  • Function as a technology risk subject matter expert; possess a strong technical understanding of infrastructure resiliency, secure data transmission protocols, network architecture, and modern threat vectors.
  • Execute thorough and timely technology risk assessments, including compliance risk, AI risk, application risk, and other analyses, across applications, initiatives, and business processes.
  • Evaluate contractual protection documentation to ensure vendor agreements mitigate compliance, regulatory, and data risk, mandate appropriate technical and administrative safeguards that protect BCBSMA data within established risk tolerances.
  • Partner with Legal and Procurement teams to guide negotiations on contract language and mitigation strategies, bringing third-party risk to acceptable levels.
  • Translate complex HIPAA regulatory requirements and risk mitigations into plain language and guide business units in the implementation of appropriate data safeguarding strategies, ensuring compliance is achieved through practical, risk-based solutions.
  • Distill complex risk data into high-impact executive dashboards and advanced visual reports for senior leadership with a clear, quantitative understanding of the risk landscape.
  • Serve as a trusted risk advisor and consultant to business units, partnering with them during the development and coordination of business processes and systems to proactively embed risk management strategies.
  • Actively engage with business units to gain foresight into upcoming initiatives, ensuring technology risks are proactively managed and embedded from the planning phase.
  • Contribute expert-level guidance to cross-functional teams in the development of risk, compliance, and information protection policies, standards, and procedures.
  • Drive the regular review and enhancement of governance documents to ensure they remain practical, relevant, and aligned with our evolving business needs.
  • Lead targeted internal initiatives and process improvements as directed by leadership to help optimize the team's advisory capabilities and overall risk delivery framework.

This document is not an exhaustive list of all responsibilities, skills, duties, requirements, or working conditions associated with the job. Employees may be required to perform other job-related duties.


We’re Looking for:

  • In addition to third-party risk management or a cybersecurity generalist, expertise in one or more of the following: risk management, regulatory compliance, application risk analysis, data analytics, and visualizations.
  • Solutions-oriented business partner, leveraging a deep understanding of technical defense concepts, vulnerability landscapes, and system safeguard principles.
  • Strong personal drive, organization and execution skills, and ability to self-manage to a defined outcome, including project decomposition, task identification, leadership alignment, regular status points, and successful on-time completion.
  • Collaborator who develops and champions practical risk mitigation strategies rather than rigid technical blockers.
  • Ability to analyze and translate complex technical findings into clear, actionable business contexts, working collaboratively with stakeholders to mitigate risk and enable risk informed executive decisions
  • Experience assisting in the development and tracking of Key Risk Indicators (KRIs) and performance metrics to continuously monitor the health of the third-party ecosystem and the broader technology risk program.
  • Strong interpersonal skills to cultivate relationships and foster cross-team collaboration across the enterprise
  • Ability to serve as a mentor to team members, providing peer guidance, operational support, and coaching on technology risk management strategies and assessment processes.

What You Bring:

  • BA or BS degree in Risk Management, Technology, Business Administration, Information Security, a related field, or equivalent practical experience.
  • 8+ years of experience in third-party risk management, technology, IT, or risk management functions.
  • 5+ years of dedicated experience executing risk assessments, vendor evaluations, or risk management programs within an information protection framework.
  • CRISC, CTPRP (Certified Third-Party Risk Professional), or C3PRMP strongly preferred.
  • Demonstrated experience navigating healthcare regulatory and compliance frameworks, specifically HIPAA and HITRUST.
  • Hands-on experience utilizing enterprise GRC platforms and Third-Party Risk Management tools (e.g., Whistic, RiskRecon, ServiceNow, or similar).
  • Relevant audit, general GRC, or high-level protection certifications are a plus (e.g., CISSP, CISA, GRCP, CGRC, CISM).

               

What You’ll Gain:


The Senior Information Risk Analyst plays a vital role in executing the organization's third-party risk management program. This includes leading the evaluation of technology risks associated with our vendor ecosystem, driving the negotiation of contractual protection requirements, monitoring the remediation of identified vulnerabilities, and conducting ongoing risk alignment assessments of BCBSMA applications and data


As a member of a highly collaborative team of seasoned analysts, you will act as a strategic advisor to cross-functional partners across Legal, Privacy, Audit, Information Security, Procurement, Vendor Management, and Account teams. By championing a risk-based approach, you will help safeguard the confidentiality and integrity of BCBSMA information, ensuring that our digital risk posture supports and enables business initiatives rather than hindering them. As a subject matter expert, you will actively shape the policies, standards, and procedures that govern our third-party and information risk landscape and be instrumental in the continuous maturity of the Information Risk Management team.


Minimum Education Requirements:

High school degree or equivalent required unless otherwise noted above

LocationBostonTime TypeFull time

Salary Range: $110,970.00 - $135,630.00


The job posting range is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting.  We may ultimately pay more or less than the posted range, and the range may be modified in the future.  An employee’s pay position within the salary range will be based on several factors including, but limited to, relevant education, qualifications, certifications, experience, skills, performance, shift, travel requirements, sales or revenue-based metrics, and business or organizational needs and affordability.

This job is also eligible for variable pay.

We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and a suite of well-being benefits to eligible employees.

Note:  No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

WHY Blue Cross Blue Shield of MA?

We understand that the confidence gap and imposter syndrome can  prevent  amazing candidates coming our way, so please don’t hesitate to apply. We’d love to hear from you. You might be just what we need for this role or possibly another one at Blue Cross Blue Shield of MA. The more voices we have represented and amplified in our business, the more we will all thrive, contribute, and be brilliant. We encourage you to bring us your true colors, , your perspectives, and your experiences. It’s in our differences that we will remain relentless in our pursuit to transform healthcare for ALL.

As an employer, we are committed to investing in your development and providing the necessary resources to enable your success. Learn how we are dedicated to creating an inclusive and rewarding workplace that promotes excellence and provides opportunities for employees to forge their unique career path by visiting our Company Culture page. If this sounds like something you’d like to be a part of, we’d love to hear from you. You can also join our Talent Community to stay “in the know” on all things Blue.

At Blue Cross Blue Shield of Massachusetts, we believe in wellness and that work/life balance is a key part of associate wellbeing. For more information on how we work and support that work/life balance visit our "How We Work" Page.

Skills Required

  • Bachelor’s degree in Risk Management, Technology, Business Administration, Information Security, a related field, or equivalent practical experience
  • 8+ years of experience in third-party risk management, technology, IT, or risk management functions
  • 5+ years of dedicated experience executing risk assessments, vendor evaluations, or risk management programs within an information protection framework
  • Experience with third-party risk management or cybersecurity generalist responsibilities
  • Expertise in one or more of risk management, regulatory compliance, application risk analysis, data analytics, and visualizations
  • Experience developing and tracking Key Risk Indicators and performance metrics
  • Experience navigating healthcare regulatory and compliance frameworks, specifically HIPAA and HITRUST
  • Hands-on experience using enterprise GRC platforms and third-party risk management tools such as Whistic, RiskRecon, ServiceNow, or similar
  • Strong understanding of technical defense concepts, vulnerability landscapes, infrastructure resiliency, secure data transmission protocols, and network architecture
  • Ability to analyze and translate complex technical findings into actionable business contexts
  • Ability to develop practical risk mitigation strategies and collaborate across teams
  • Ability to mentor team members and provide guidance on technology risk management and assessment processes
  • CRISC, CTPRP, or C3PRMP certification
  • Relevant audit, GRC, or information protection certifications such as CISSP, CISA, GRCP, CGRC, or CISM

Blue Cross Blue Shield of Massachusetts Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Blue Cross Blue Shield of Massachusetts and has not been reviewed or approved by Blue Cross Blue Shield of Massachusetts.

  • Healthcare Strength Healthcare coverage is positioned as a standout, with strong medical/dental/vision options and added mental-health tools. Wellness centers and company-funded health accounts further strengthen the overall health offering.
  • Retirement Support Retirement benefits are framed as robust, with a 401(k) that includes both company contributions and a match. Added financial-wellness supports like 1:1 CFP coaching and student-loan repayment contribute to the broader rewards package.
  • Wellbeing & Lifestyle Benefits Wellbeing benefits appear notably broad, including wellness reimbursements and subsidies (e.g., fitness and ergonomic support). Backup care and discount programs add lifestyle value beyond core insurance.

Blue Cross Blue Shield of Massachusetts Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
3,932 Employees
Year Founded: 1932

What We Do

Blue Cross Blue Shield of Massachusetts is a community-focused, tax-paying, not-for-profit health plan headquartered in Boston. We have been a market leader for over 80 years, and are consistently ranked among the nation's best health plans. Our daily efforts are dedicated to effectively serving our 3 million members, and consistently offering security, stability, and peace of mind to both our members and associates. As an employer, we are committed to investing in your development and providing the necessary resources to enable your success. We are dedicated to creating an inclusive and rewarding workplace that promotes excellence and provides opportunities for employees to forge their unique career path. We take pride in our diverse, community-centric, wellness-focused culture and believe every member of our team deserves to enjoy a positive work-life balance. Blue Cross Blue Shield of Massachusetts is an Independent Licensee of the Blue Cross and Blue Shield Association. Blue Cross Blue Shield of Massachusetts complies with applicable federal civil rights laws and does not discriminate on the basis of race, color, national origin, age, disability, sex, sexual orientation or gender identity. ATTENTION: If you don’t speak English, language assistance services, free of charge, are available to you. Call Member Services at the number on your ID Card (TTY: 711). ATENCIÓN: Si habla español, tiene a su disposición servicios gratuitos de asistencia con el idioma. Llame al número de Servicio al Cliente que figura en su tarjeta de identificación (TTY: 711). ATENÇÃO: Se fala português, são-lhe disponibilizados gratuitamente serviços de assistência de idiomas. Telefone para os Serviços aos Membros, através do número no seu cartão ID (TTY: 711

Similar Jobs

Zscaler Logo Zscaler

Principal Product Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
USA
8697 Employees
172K-245K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Burlington, MA, USA
16000 Employees
15-20 Hourly

WHOOP Logo WHOOP

Electrical Engineering Lead

Fitness • Hardware • Healthtech • Sports • Wearables
Hybrid
Boston, MA, USA
500 Employees
140K-195K Annually

WHOOP Logo WHOOP

Senior Electrical Engineer

Fitness • Hardware • Healthtech • Sports • Wearables
Hybrid
Boston, MA, USA
500 Employees
140K-195K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account