2

Remote Security Control Assessor Jobs in Tennessee

IT Security Engineer SR

Goodlettsville, TN · Remote

$107K - $147K/yr

... access control. * Develop and enforce security policies related to network security (Palo Alto ... In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and ...

next page

Showing results 1-20

Remote Security Control Assessor information

What is a Remote Security Control Assessor job?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What are the key skills and qualifications needed to thrive in the Remote Security Control Assessor position, and why are they important?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are some typical responsibilities of a Remote Security Control Assessor on a day-to-day basis?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.

What are popular job titles related to Remote Security Control Assessor jobs in Tennessee? For Remote Security Control Assessor jobs in Tennessee, the most frequently searched job titles are:
What job categories do people searching Remote Security Control Assessor jobs in Tennessee look for? The top searched job categories for Remote Security Control Assessor jobs in Tennessee are:
What cities in Tennessee are hiring for Remote Security Control Assessor jobs? Cities in Tennessee with the most Remote Security Control Assessor job openings:
Infographic showing various Remote Security Control Assessor job openings in Tennessee as of July 2026, with employment types broken down into 6% As Needed, 69% Full Time, 19% Part Time, and 6% Contract. Highlights an 100% Remote job distribution.

Sr. Information Security Governance, Risk and Compliance Analyst

BlueCross BlueShield of Tennessee

Chattanooga, TN • Remote

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

We are hiring a Sr. Information Security Governance, Risk, and Compliance (GRC) Analyst at BlueCross BlueShield of Tennessee!
In this role, you will help strengthen and mature BCBST's information security governance program by leading risk management, compliance, and assurance initiatives across the enterprise. You will serve as a key contributor in developing and maintaining Systems Security Plans (SSPs), beginning with enterprise-level security plans and extending into application-specific security documentation. You'll partner with technology and business stakeholders to support audit readiness efforts, manage security controls, assess risk, and ensure alignment with industry frameworks and regulatory requirements. This role plays an important part in protecting organizational assets while helping BCBST maintain a strong security and compliance posture.
To be successful in this role, in addition to the core job requirements, you'll bring strong cybersecurity knowledge, exceptional technical writing skills, and experience translating complex security requirements into clear, actionable documentation. You will be a strong candidate for this role if you have experience developing Systems Security Plans (SSPs), supporting audit and compliance activities, working with security frameworks and control management programs, and collaborating across technical teams to manage risk. Professional certifications such as CISA, CISM, or CISSP are highly preferred and will help distinguish top candidates.
Note:
  • This is a remote, work-from-home position, but the final round of interviews will take place on-site in our Chattanooga, TN office.
  • Candidates must be able to work Eastern Time Zone business hours.
  • Participation in an on-call rotation is required for approximately two weeks every 30 weeks.
  • Sponsorship is not available for this role.

Job Responsibilities

  • Lead SOC 2 Audit Support - Coordinate audit activities including evidence collection, control validation, and auditor engagement.
  • Manage and Validate Control Frameworks - Maintain control documentation, mappings, and narratives while partnering with control owners to ensure effectiveness and alignment with Trust Services Criteria and NIST frameworks.
  • Track Audit & Remediation Activities - Oversee audit findings, remediation efforts, and timely closure of issues.
  • Develop & Maintain NIST SSPs - Create and update System Security Plans (SSPs), including control implementations, inheritance, and system boundaries.
  • Drive Security Awareness Programs - Design and manage training initiatives, including phishing simulations and targeted campaigns.
  • Manage Policies & Governance Documentation - Oversee the full lifecycle of security policies, standards, and procedures to ensure compliance and audit readiness.
  • Conduct Enterprise & Third-Party Risk Management - Perform risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation.
  • Oversee Vulnerability Management - Track vulnerability remediation against SLAs and collaborate with teams to mitigate risks.
  • Support Customer Security Assurance - Respond to RFPs and security questionnaires, ensuring accurate, compliant, and consistent security representations.
  • Leadership - Leads by example, actively supporting initiatives across all GRC areas while fostering a culture of collaboration and shared accountability.

Job Qualifications
Education

  • Bachelor's degree in a relevant field or an equivalent of four years of experience is required.

Experience

  • 5 years - Professional experience in Information Security or related IT roles with security-related responsibilities, including at least 2 years focused on Governance, Risk, and Compliance (GRC) functions.
  • Experience leveraging AI-enabled tools to automate and enhance GRC processes, improving efficiency, consistency, and scalability of governance, risk, and compliance activities preferred.

Skills/Certifications

  • Preferred, one or more of the following certifications required: CISSP, CRISC, CISA, or CISM.
  • Ability to assess and document organizational risks, including identifying impacts and recommending mitigation strategies.
  • Ability to interpret and apply regulatory requirements and industry frameworks (e.g., NIST, SOC 2, HIPAA) to organizational controls.
  • Ability to analyze security, compliance, and risk metrics to identify trends and drive continuous improvement.
  • Ability to communicate complex risk and compliance concepts clearly to both technical and non-technical stakeholders.
  • Ability to collaborate effectively across cross-functional teams to integrate governance, risk, and compliance practices into business processes.
  • Exceptional time management skills.
  • Excellent oral and written communication skills.
  • Strong interpersonal skills and ability to cultivate relationships with internal and external stakeholders, promoting diversity of people, perspectives and ideas.
  • Ability to work with all levels of staff and management.

N/A

Number of Openings Available

1

Worker Type:

Employee

Company:

BCBST BlueCross BlueShield of Tennessee, Inc.

Applying for this job indicates your acknowledgement and understanding of the following statements:

BCBST will recruit, hire, train and promote individuals in all job classifications without regard to race, religion, color, age, sex, national origin, citizenship, pregnancy, veteran status, sexual orientation, physical or mental disability, gender identity, or any other characteristic protected by applicable law.

Further information regarding BCBST's EEO Policies/Notices may be found by reviewing the following page:

BCBST's EEO Policies/Notices

BlueCross BlueShield of Tennessee is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at BlueCross BlueShield of Tennessee via-email, the Internet or any other method without a valid, written Direct Placement Agreement in place for this position from BlueCross BlueShield of Tennessee HR/Talent Acquisition will not be considered. No fee will be paid in the event the applicant is hired by BlueCross BlueShield of Tennessee as a result of the referral or through other means.