Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk and Governance Specialist, Senior

$102.74k - $154.22k

Blue Shield Of California

Information Security Risk & Governance Specialist, Senior

The Technology and Data Trust Assurance Services team drives BSC technology and information security adherence to regulatory standards, as well as policies, standards, and controls development, with the goal of evaluating, directing and monitoring IT vendor performance, while safeguarding company assets and maintaining and securing the confidentiality, integrity, and availability of Blue Shield of California data. The Technology Risk and External Assurance program runs technology governance forums including the Artificial Intelligence (AI) Governance function and manages technology risk from identification to risk consequence management for BSC. The Information Security Risk & Governance Specialist, Senior will report to the Senior Manager, Technology External Assurance. In this role, you will be a key individual contributor to the Technology Risk and External Assurance team and Blue Shield's overall strategy and goals by providing consistent, coordinated SOC 2 and PCI-DSS audit and compliance support, information security oversight including NIST CSF maturity assessments, AI governance and technology risk assessment support, and risk reporting in partnership with leaders, stakeholders, and Stellarus.

Responsibilities

In this role, you will:

  • Maintain, grow, and modify as needed a Blue Shield of California technology external assurance, risk management and AI governance knowledge bases, with a focus on improving technology risk management and security awareness organizational behavior, policies and standards, governance metrics, processes, and related workflows and tools.
  • Provide excellent customer service to all of Technology Risk and External Assurance's internal and external business stakeholders (including the Stellarus and Promise AI Governance functions) and collaborate with our Stellarus partners to meet customer needs and technology and security assurance requirements.
  • Create and maintain security and technology risk management knowledge bases, web pages, playbook(s), processes, and procedures for guiding various technology risk and assurance processes, including security shared services tracking and ticketing queue metrics, security and risk management project support.
  • Responsible for managing, triaging, and executing operational work queues for information security and AI governance within our ticketing system, security tools, and email intakes in partnership with Stellarus asset and service owners and business owners and requesters to ensure quality and timeliness.
  • Engage with stakeholders across the organization to identify service quality needs, draft requirements, assist in the development of service enhancements, tracking, monitoring, and reporting of the overall health of our services provided to the Ascendiun family of companies.
  • Perform impact analysis and root cause analysis of regulatory issues, security incidents, business requests, corrective action plans, and system changes on Technology Risk and External Assurance programs.
  • Assist with research and preparation of materials for regular core team meeting and governance forums (e.g., board and committee meetings, AI governance forums, audits and assessment, team meetings, project meetings, stakeholder communications, etc.).
  • Facilitate collaboration and coordination of security controls and frameworks, AI use cases, and technology requests, intakes, workstreams, high priority engagements, security incidents and escalated issues.
  • Promote and participate in security, compliance and AI acceptable use awareness and training initiatives.
Qualifications

Your Knowledge and Experience

  • Requires a bachelor's degree or equivalent experience and 5+ years of prior relevant experience
  • 2+ years of experience with technology service management, IT project management
  • 2+ years of experience with information security awareness and training or IT user training
  • Knowledge of Artificial Intelligence (AI) governance and monitoring practices is preferred
  • Ability to provide excellent customer service and to conduct user awareness training
  • Knowledge of various information technology governance and control frameworks and industry standards such as COBIT and NIST
  • Problem-solving and critical-thinking skills to recognize and comprehend complex issues, policies, regulatory requirements, and industry information affecting the business environment
  • Ability to communicate and articulate complex analysis in a clear, precise, and actionable manner
  • Proven collaborator with strong interpersonal skills, works collaboratively within the team and outside the team
  • Proficient in developing presentations and in written and verbal communication
  • Proficiency in Microsoft Office products
  • Experience managing workflows and queues in ticketing systems
  • GCIH and CISSP certification preferred

Hybrid

This role requires employees to be in - office based on our hybrid workplace model, balancing purposeful in - person collaboration with flexibility. For most teams, this means coming into the office two days each week.

Employees living more than 50 miles from an office location will work with their manager to determine in-office time based on business need.

About Us

About Blue Shield of California and the Ascendiun Family of Companies

As of January 2025, Blue Shield of California became a subsidiary of Ascendiun. Ascendiun is a nonprofit corporate entity that is the parent to a family of organizations including Blue Shield of California and its subsidiary, Blue Shield of California Promise Health Plan; Altais, a clinical services company; and Stellarus, a company designed to scale healthcare solutions. Together, these organizations are referred to as the Ascendiun Family of Companies.

At Ascendiun, we believe in a brighter future for healthcare. As the parent to a family of four innovative healthcare companies, we're reimagining what's possible. Ascendiun is guided by the goal of transforming a dysfunctional American health care system into one worthy of our family and friends and sustainably affordable for everyone.

To achieve our mission, we foster an environment where all employees can thrive and contribute fully to address the needs of the various communities we serve. We are committed to creating and maintaining a supportive workplace that upholds our values and advances our goals.

Our Values:

  • Honest. We hold ourselves to the highest ethical and integrity standards. We build trust by doing what we say we're going to do and by acknowledging and correcting where we fall short.
  • Human. We strive to listen and communicate effectively, and showing empathy by understanding others' perspectives.
  • Courageous. We stand up for what we believe in and are committed to the hard work necessary to achieve our ambitious goals.

Our Workplace Model:

We believe in fostering a workplace environment that balances purposeful in-person collaboration with flexibility - providing clear expectations while respecting the diverse needs of our workforce. Our workplace model is designed around intentional in-person interaction, collaboration, connection, creativity and flexibility:

  • For most teams, this means coming into the office two days per week.

  • Employees living more than 50 miles from an office location, out of state employees, and employees in certain member-facing roles should work with their manager to determine in-office time based on business need.

  • For employees with medical conditions that may impact their ability to work in-office, we are committed to engaging in an interactive process and providing reasonable accommodations to ensure their work environment is conducive to their success and well-being.

The Company reserves the right to require more presence in the office based on business needs, and requirements are subject to change with periodic reviews.

Physical Requirements:

Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.

Please click here for further physical requirement detail.

Equal Employment Opportunity:

External hires must pass a background check/drug screen. Qualified applicants with arrest records and/or conviction records will be considered for employment in a manner consistent with Federal, State and local laws, including but not limited to the San Francisco Fair Chance Ordinance. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, national origin, sexual orientation, gender identity, protected veteran status or disability status and any other classification protected by Federal, State and local laws.

Job Info
  • Job Identification 20260989
  • Job Category Information Technology
  • Apply Before 06/20/2026, 07:00 AM
  • Job Schedule Full time
  • Locations El Dorado Hills, CA, United States CA, United States Long Beach, CA, United States Oakland, CA, United States Rancho Cordova, CA, United States Woodland Hills, CA, United States
  • Pay Range for California $102740.00 to $154220.00
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Risk and Governance Specialist, Senior in Oakland, CA vacancy
  •  ...drives BSC technology and information security adherence to regulatory standards...  ...data. The Technology Risk and External Assurance program runs technology governance forums including the Artificial...  ...Security Risk & Governance Specialist, Senior will report to the Senior... 
    Senior
    Risk
    Work at office
    2 days per week

    Blue Shield of CA

    Oakland, CA
    23 hours ago
  • $193k - $220k

     ...Senior Manager, Governance Risk & Compliance (GRC) Andersen is scaling its information security function, and this is a critical hire for the program's next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief... 
    Senior
    Risk
    Full time
    H1b
    Local area
    Immediate start
    Work visa

    Andersen

    San Francisco, CA
    23 hours ago
  • $55 - $59 per hour

     ...Senior Specialist – Medical Affairs Location: 2901 Harbor Bay Parkway, Alameda, CA 94502...  ...investigational brochures, protocols, informed consent forms, case report forms, and reports...  ...Clinical, Regulatory Affairs, Quality, Risk Management, and Project Management.... 
    Senior
    Risk
    Hourly pay

    Experis

    Alameda, CA
    3 days ago
  • $365k - $390k

     ...join their elite digital governance and litigation practice.  § Title : Senior Privacy, Cybersecurity...  ...commerce. Frequently securing Tier 1 national rankings...  ...Partners for Data Privacy and Information Security, this firm is...  ...mitigate institutional risk. ⨖ Managing the legal... 
    Senior
    Risk
    Full time
    Fixed term contract

    Percy Towers

    San Francisco, CA
    7 days ago
  •  ...designed to keep the electric grid secure and reliable, even during...  ...Form Energy is seeking a Senior Staff Technical Program Manager...  ...strategically mitigate program risks and dependencies,...  ...articulate complex technical information and strategic recommendations... 
    Senior
    Risk
    Full time

    Form Energy, Inc.

    Berkeley, CA
    4 days ago
  • $105k

     ...Job Category: Compliance / Risk / Quality Assurance; Business...  ...Compliance organization provides governance, oversight, and strategic direction...  ...Position Summary: As a Senior Risk and Compliance consultant...  ...FERC, NERC, WECC) and how they inform enterprise compliance strategy... 
    Senior
    Risk
    Work experience placement
    Work at office
    Work from home
    Flexible hours
    2 days per week
    3 days per week

    PG&E

    Oakland, CA
    1 day ago
  • $159k

     ...Operations / Strategy  Job Level: Senior Manager Business Unit:...  ...Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction...  ...complex issues with minimal information or supervision of a manager or director... 
    Senior
    Risk
    Contract work
    Work experience placement
    Work at office
    Flexible hours
    2 days per week
    3 days per week

    PG&E Corporation

    Orinda, CA
    1 day ago
  • $105k

     ...Job Category: Compliance / Risk / Quality Assurance Job Level...  ...of Internal Audit, the Senior IT Auditor is responsible for...  ...: ~ Bachelors Degree in Information Systems, Computer Science, Accounting...  ...Information Systems Security Professional (CISSP), or post... 
    Senior
    Risk
    Work at office
    Remote work

    PG&E

    Oakland, CA
    4 days ago
  • $159k

     ...Operations / Strategy; Compliance / Risk / Quality Assurance Job Level: Senior Manager Business Unit: Strategy...  ...Compliance organization provides governance, oversight, and strategic...  ...CPUC, FERC, NERC, WECC) and how they inform enterprise compliance strategy... 
    Senior
    Risk
    Work experience placement
    Work at office
    Flexible hours

    PG&E

    Oakland, CA
    1 day ago
  •  ...Description Your Role The Information Security team is looking for a certified...  ...cyber events. The Cyber Defense Specialist, Consultant will report to the Senior Manager of Information Security...  ...improvement opportunities to reduce risk and improve effectiveness... 
    Risk
    Full time
    Part time
    Work at office
    Local area
    Work from home
    Home office
    2 days per week

    Blue Shield Of California

    Oakland, CA
    4 days ago
  • $200k - $280k

     ...architecting, building, and governing enterprise network and security infrastructure across a...  ...environment. The Senior Manager blends deep technical...  ...timely remediation and report risk to stakeholders....  ...degree in Computer Science, Information Technology, Network Engineering... 
    Senior
    Risk
    Contract work

    Atomic Machines

    Emeryville, CA
    24 days ago
  • $144.5k - $175.1k

     ...Senior Therapeutic Area Specialist, Oncology/Hematology - San Francisco, CA Working with...  ...and to dynamically inform call plans. Provides feedback...  ...regulations, and policies that govern the conduct of BMS. Required...  ...; and, 3) a driving risk level deemed acceptable by... 
    Senior
    Risk
    Private practice
    Work at office

    Bristol-Myers Squibb

    San Francisco, CA
    2 days ago
  •  ...leader will establish standards, governance, and best practices for...  ...planning), including assumptions, risks/opportunities, and version...  ...based models and statistically informed approaches where appropriate....  ...strongly preferred. For a Senior Director we require a BA/BS... 
    Senior
    Risk
    Work experience placement

    BeOne Medicines

    Emeryville, CA
    4 days ago
  • $30.76 per hour

     ...Senior Registration Specialist Primary Care Clinic - Hayward, CA 94545 Overview Salary Range $3...  ...Proactively communicate identified risks to the supervisor to minimize risk when...  ...Utilize the principles of trauma-informed care and communication throughout all... 
    Senior
    Risk
    Hourly pay
    Full time
    Immediate start
    Flexible hours

    Southern Alameda County Comite for Raza Mental Health

    Hayward, CA
    4 days ago
  •  ...Job Description:- As the Senior Cyber Risk Manager, you will be responsible...  ...technology infrastructure remains secure, compliant, and resilient to emerging...  ..., regulations, and guidelines governing technology risk management and information security. Monitor regulatory... 
    Senior
    Risk
    Contract work
    Remote work

    Avant Digital Inc

    San Francisco, CA
    2 days ago
  • $144.5k - $175.1k

     ...and to dynamically inform call plans. Provides...  ..., and policies that govern the conduct of BMS....  ...; and, 3) a driving risk level deemed acceptable...  ..., or social security numbers during our application...  ...R1602375 : EG-90 - Senior Therapeutic Area Specialist, Oncology (San... 
    Senior
    Risk
    Hourly pay
    Full time
    Temporary work
    Part time
    For contractors
    Summer work
    Private practice
    Live in
    Work at office
    Local area
    Remote work
    Flexible hours
    Shift work

    Bristol-Myers Squibb

    San Francisco, CA
    2 days ago
  • $90k - $120k

     ...Job Title: Senior Buyer / Planner / Commodity Specialist Location: San Francisco, CA (On-site) Salary: $90,000 - $120,000 LANTANA LED, Inc. LANTANA...  ...— aligned with cost, quality, lead time, and risk objectives. • Identify, qualify, and onboard suppliers... 
    Senior
    Risk
    Contract work
    Remote work

    LANTANA LED

    San Francisco, CA
    3 days ago
  • $160k - $180k

     ...Peet's is seeking a Senior Manager, Cyber Security to lead and mature the company...  ...day-to-day management of information security capabilities that...  ...business outcomes while managing risk in a pragmatic, business-...  ...information security governance through implementation of... 
    Senior
    Risk
    Full time
    Temporary work
    For contractors
    Local area
    Flexible hours

    Peet's

    Emeryville, CA
    4 days ago
  • $155k - $190k

     ...That starts with you! Job Summary: Miller Kaplan’s Risk Advisory team is looking for a Senior Manager to join our Cybersecurity practice. The...  ...specifically initial infosec assessments, fractional Chief Information Security Officer (or vCISO) consulting, cybersecurity... 
    Senior
    Risk
    Work at office
    Local area
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours
    Day shift

    Miller Kaplan Arase LLP

    San Francisco, CA
    17 days ago
  • $110k - $140k

     ...will help lead and evolve the governance engine of a global, mid-sized...  ...the CISO and be responsible for security assurance, compliance operations, and technology risk management. You will help...  ...Assist in drafting and maintaining information security policies and... 
    Risk
    Full time
    Work at office

    BTIG

    San Francisco, CA
    3 days ago
  •  ...Role We’re looking for a Senior Engineering Manager to lead the...  ...with Compliance and Security to ensure frontend patterns meet...  ...accordance with the organization’s information security policies, to include...  ...or potential events or other risks to the organization.... 
    Senior
    Risk
    Work at office
    Local area

    COMMURE Incorporated

    San Francisco, CA
    23 hours ago
  •  ...Description Job Description The QC Specialist (Data Review & Investigations) is responsible...  ...cause analysis using scientific and risk-based approaches.   ~ Collaborate with...  ...made by humans. If you would like more information about how your data is processed, please... 
    Risk
    Contract work

    GeneFab

    Alameda, CA
    24 days ago
  • $72k - $184.44k

     ...Senior Associate, Digital Assets At PwC, our people in audit...  ..., and other assurable information enhancing the credibility and...  ...regulations including assessing governance and risk management processes and...  ...and controls, cyber security measures, data and AI systems... 
    Senior
    Risk
    Full time
    H1b
    Work at office

    PwC (US)

    San Francisco, CA
    4 days ago
  • $77k - $202k

     ...Senior Associate, Enterprise Risk And Controls Solutions At PwC, our people in audit...  ..., and other assurable information enhancing the credibility...  ...regulations including assessing governance and risk management...  ...with Oracle, SAP, and security technologies- Understanding... 
    Senior
    Risk

    PwC (US)

    San Francisco, CA
    4 days ago
  • $225k - $290k

     ...wide standards for data quality, contracts, and governance; designing scalable reliability and...  ...ensure long-term scalability, reduce systemic risk, and eliminate classes of failure across the data landscape. As a senior technical leader, you will also guide cross-team... 
    Senior
    Risk
    Flexible hours

    Circle

    San Francisco, CA
    3 days ago
  • $275k - $300k

     ...vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and...  ...-Functional Partnership: Operate as a senior technical leader across Product Security,... 
    Risk
    Work at office
    Flexible hours
    3 days per week

    Postman

    San Francisco, CA
    1 day ago
  • $75k - $100k

     ...than 500,000 patients worldwide. Overview The Heartflow Information Security team is responsible for security across our corporate and...  ...Perform security reviews of third‑party vendors to identify risks and ensure they meet company standards. What You Bring... 
    Senior
    Risk
    Local area
    Worldwide
    Relocation

    Isc2 Eastbay Chapter

    San Francisco, CA
    23 hours ago
  • $72k - $184.44k

     ...Assurance Management Level Senior Associate Job...  ...controls, and other assurable information enhancing the credibility and...  ...including assessing governance and risk management processes and related...  ...processes and controls, cyber security measures, data and AI... 
    Senior
    Risk
    Full time
    H1b
    Work at office

    PricewaterhouseCoopers

    San Francisco, CA
    3 days ago
  • $170k - $230k

     ...Employees will act in accordance with the organization’s information security policies, to include but not limited to protecting assets from...  ...security office any confirmed or potential events or other risks to the organization. Employees will be required to attest to... 
    Senior
    Risk
    Work at office
    Immediate start

    Commure

    San Francisco, CA
    4 days ago
  • $160k - $195k

     ...for an experienced workforce governance and employment compliance practitioner...  ...compliance, and regulatory risk programs across the People...  ..., Sales, Operations, and Security to implement and monitor workforce...  ..., disability, genetic information, pregnancy, citizenship, marital... 
    Senior
    Risk
    Temporary work
    For contractors
    Fixed term contract
    Local area

    Crusoe

    San Francisco, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk and Governance Specialist, Senior. Be the first to apply!