IT Governance Analyst

Blue Cross and Blue Shield of North Carolina
Durham, IN, United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$81,068.0 - $129,708.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Technology Audit IT Management

Job description

The IT Governance Analyst assists in the identification, assessment, monitoring, and risk mitigation associated with third-party vendors and suppliers. This role serves as a trusted advisor to business stakeholders, procurement teams, information security, legal, and compliance functions to ensure third-party relationships align with the organization’s risk appetite and regulatory obligations.

WhatYou’llDo

  • Assists with the identification and assessment of risks associated with third-party vendors, suppliers, business partners, and outsourced service providers, with a strong focus on technology, cybersecurity, data privacy, and regulatory risks

  • Provides support to business owners and project teams to increase awareness and understanding of risks and controls and assist in the development, assessment and monitoring of mitigation plans for IT-related risks, to ensure they are managed to an acceptable level. Identifies, evaluates and escalates issues that conflict with BCBSNC’s risk tolerance

  • Consults on projects and other initiatives to ensure third party risks are considered and addressed appropriately

  • Assess the effectiveness of vendor control environments through review of audit reports, certifications, questionnaires, security assessments, and other risk artifacts. Recommend improvements to strengthen risk management practices and reduce exposure.

  • Develop metrics, dashboards, and reporting materials that provide management and executive leadership with visibility into third-party risk exposure, emerging risks, remediation activities, and program effectiveness.

  • Deliver training, awareness sessions, and stakeholder guidance to promote a strong culture of third-party risk management and ensure consistent application of TPRM requirements across the organization

Requirements

  • Bachelor’s degree or advanced degree (where required)

  • 3+ years of experience in related field

  • In lieu of degree, 5+ years of experience in related field

Bonus Points

  • Experience conducting IT audits and supporting SOX (Sarbanes-Oxley) compliance audits

  • Professional certifications such as HITRUST, NIST, SOC 2, and ISO standards preferred

  • Industry-recognized certifications in IT audit, risk management, governance, or compliance, including CISA, CRISC, and CRMA, are a plus

Benefits & conditions

$81,068.00 - $129,708.00 parental leave, paid time off, tuition reimbursement, 401(k) United States, Indiana Jul 29, 2026, * The opportunity to work at thecutting edgeof health care delivery with a teamthat’sdeeply invested in the community

  • Work-life balance, flexibility, and the autonomy to dogreat work

  • Medical, dental, and vision coverage along withnumeroushealth and wellness programs

  • Parental leave and support plus adoption and surrogacyassistance

  • Career development programs and tuition reimbursement for continued education

  • 401k match including an annual company contribution

  • Learn more

Where You’ll Work

Our Hybrid Flex approach is built on presence with a purpose - giving you flexibility to work remotely with intentional in-person connection - that supports a workplace that’s flexible, connected, and future focused.

In a Hybrid-Flex role, you’ll work in the office at least two days a week for collaboration and connection. In a Remote Flex role, you’ll work virtually, with a few in-office visits each year for meaningful moments that matter.

Whether your role is Hybrid Flex or Remote Flex depends on the nature of the work and distance from our Durham headquarters. We welcome candidates from outside the local area and in any states listed on this job posting. Onsite expectations will be discussed during the interview process.

Salary Range

At Blue Cross NC, we take great pride in a fair and equitable compensation package that reflects market-price and our starting salaries are typically planned near the middle of the range listed. Compensation decisions are driven by factors including experience and training, specialized skill sets, licensure and certifications and other business and organizational needs.Our base salary is part of a robust Total Rewards package that includes an Annual Incentive Bonus*, 401(k) with employer match, Paid Time Off (PTO), and competitive health benefits and wellness programs.

*Based on annual corporate goal achievement and individual performance. $81,068.00 - $129,708.00

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:14 min

Establishing legal admissibility through immutable blockchain attestations

Frederik Gregaard Frederik Gregaard +1 · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · WWC 2021

Videos

See all

Related articles

See all