Cyber Security Manager; Remote
Hagerstown, Washington County, Maryland, 21740, USA
Listed on 2026-06-29
-
IT/Tech
Cybersecurity, IT Project Manager, Information Security
Purpose
The Manager, Cybersecurity Governance, Risk & Compliance (GRC) is responsible for leading and executing the organization’s cybersecurity risk management, governance, and compliance programs. This role ensures alignment with regulatory requirements, industry standards, and internal policies while enabling the business to manage cyber risk effectively. The Manager partners closely with technology, legal, privacy, audit, and business leaders to identify, assess, mitigate, and report cybersecurity risks.
This position includes direct people leadership and plays a critical role in maturing cybersecurity risk management practices across the enterprise. The Manager is also responsible for planning, monitoring, and managing the organization’s budget to ensure strategic alignment and fiscal responsibility.
- Lead the development, implementation, and ongoing maturity of the cybersecurity governance, risk, and compliance program.
- Establish and maintain cybersecurity policies, standards, procedures, and control frameworks aligned with business objectives.
- Serve as a trusted advisor to technology and business stakeholders on cybersecurity risk and control effectiveness.
- Oversee cybersecurity risk assessments, including application, infrastructure, cloud, data, and third‑party risks.
- Maintain cybersecurity risk registers, policy exception and risk acceptance processes, and remediation tracking.
- Partner with business and technology teams to develop practical risk mitigation strategies aligned to organizational risk appetite.
- Monitor emerging cyber threats, regulatory changes, and industry trends to proactively adjust risk posture.
- Ensure compliance with applicable regulations and frameworks such as NIST (800-53, 800-171, CSF), HIPAA, HITRUST, SOC, ISO 27001, and other relevant standards.
- Support internal and external audits and assessments, including evidence collection, issue management, and remediation validation.
- Act as a primary point of coordination for cybersecurity‑related regulatory and assurance activities.
- Lead or support third‑party cybersecurity risk assessments, including review of SOC reports, vendor questionnaires, and other security attestations.
- Partner with procurement, legal, and business teams to ensure appropriate cybersecurity requirements are embedded into vendor engagements.
- Define and maintain key risk and compliance metrics and dashboards to measure program effectiveness.
- Prepare clear, concise risk reporting for senior leadership and governance forums.
- Drive continuous improvement through process optimization, automation, and use of GRC tooling.
- Lead, mentor, and develop a team of cybersecurity risk and compliance professionals.
- Set priorities, manage workload, and support professional growth and performance management.
- Foster a collaborative, accountable, and results‑driven team culture.
Education Level: Bachelor’s Degree in Computer Science, Information Technology, or a related field, or an additional four years of relevant work experience in lieu of a bachelor’s degree.
Experience: 5 years of related professional experience; 1 year of supervisory or progressive leadership experience.
Preferred Qualifications- Master’s Degree
- Ability to multitask and manage multiple relationships.
- Ability to lead and work as part of a team.
- Ability to execute technology and tool automation processes.
- Deep knowledge of risk treatment and mitigation strategies.
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity.
- Thorough understanding of cyber threats and vulnerabilities.
- Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence. Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging.
- Proven experience leading a large multidisciplinary organization.
- Proven experience leading the end‑to‑end implementation of an enterprise GRC tool, including requirements gathering, configuration, integration with existing systems, user training, and ongoing optimization.
$146,560 – $272,052
Equal Employment OpportunityCare First Blue Cross Blue Shield is an Equal Opportunity (EEO) employer. It is the policy of Care First to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).