> Markdown version of [/jobs/ext/1507476-it-governance-analyst](https://www.wearedevelopers.com/jobs/ext/1507476-it-governance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Governance Analyst - **Company:** Blue Cross and Blue Shield of North Carolina - **Location:** Durham, IA, United States (Remote available) - **Experience:** Experienced - **Salary:** $81,068.0 - $129,708.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Technology Audit, IT Management - **Published:** July 30, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17741203?backUrl=%2Fcareer%2F17741203%2FIt-Governance-Analyst-Iowa ## About the Role * Bachelor's degree or advanced degree (where required) * 3+ years of experience in related field * In lieu of degree, 5+ years of experience in related field Bonus Points * Experience conducting IT audits and supporting SOX (Sarbanes-Oxley) compliance audits * Professional certifications such as HITRUST, NIST, SOC 2, and ISO standards preferred * Industry-recognized certifications in IT audit, risk management, governance, or compliance, including CISA, CRISC, and CRMA, are a plus ## Description The IT Governance Analyst assists in the identification, assessment, monitoring, and risk mitigation associated with third-party vendors and suppliers. This role serves as a trusted advisor to business stakeholders, procurement teams, information security, legal, and compliance functions to ensure third-party relationships align with the organization's risk appetite and regulatory obligations. WhatYou'llDo * Assists with the identification and assessment of risks associated with third-party vendors, suppliers, business partners, and outsourced service providers, with a strong focus on technology, cybersecurity, data privacy, and regulatory risks * Provides support to business owners and project teams to increase awareness and understanding of risks and controls and assist in the development, assessment and monitoring of mitigation plans for IT-related risks, to ensure they are managed to an acceptable level. Identifies, evaluates and escalates issues that conflict with BCBSNC's risk tolerance * Consults on projects and other initiatives to ensure third party risks are considered and addressed appropriately * Assess the effectiveness of vendor control environments through review of audit reports, certifications, questionnaires, security assessments, and other risk artifacts. Recommend improvements to strengthen risk management practices and reduce exposure. * Develop metrics, dashboards, and reporting materials that provide management and executive leadership with visibility into third-party risk exposure, emerging risks, remediation activities, and program effectiveness. * Deliver training, awareness sessions, and stakeholder guidance to promote a strong culture of third-party risk management and ensure consistent application of TPRM requirements across the organization ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fireside Chat: AI and Sustainability - Thorsten Jonas](https://www.wearedevelopers.com/videos/1769-fireside-chat-ai-and-sustainability-thorsten-jonas) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany)