Tim Shen
AeroLeads people directory · profile

Tim Shen Email & Phone Number

Senior Business Information Security Officer (BISO) at Health Care Service Corporation
Location: Greater Chicago Area, United States 5 work roles 1 school
LinkedIn matched
✓ Verified July 2026 3 data sources Profile completeness 86%

Contact Signals

LinkedIn Profile matched
3 free lookups remaining · No credit card
Role
Senior Business Information Security Officer (BISO)
Location
Greater Chicago Area, United States
Company size

Who is Tim Shen? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Tim Shen is listed as Senior Business Information Security Officer (BISO) at Health Care Service Corporation, a with 1470 employees, based in Greater Chicago Area, United States. AeroLeads shows a matched LinkedIn profile for Tim Shen.

Tim Shen previously worked as GRC Analyst and Lead of Cyber Risk Management Program in Governance, Risk and Compliance (GRC) at Trustmark and Senior Advisor, Information Security-Governance Risk and Compliance (GRC) (2nd Line of Defense) at Transunion. Tim Shen holds Master'S Degree, Information System And Computer Science from Depaul University.

Company email context

Email format at Health Care Service Corporation

This section adds company-level context without repeating Tim Shen's masked contact details.

Health Care Service Corporation

Review company-level records connected to Tim Shen before choosing the right outreach path.

Profile bio

About Tim Shen

• Versatile and highly accomplished IT security and risk compliance advisor with over 10 years of experience in global cybersecurity Governance, Risk and Compliance (GRC), aligning business and IT strategies and priorities.• Build and lead the technology and security risk management and policy exception program, focusing on identifying risks, conducting business impact risk assessments across IT controls and applications, prioritizing top risks, and reducing risk levels throughout the risk lifecycle. • A Senior Business Information Security Officer (BISO) acting as a liaison between business units and IT cybersecurity teams, advising business and IT control owners on information security policies, regulatory compliance requirements, and IT control standards.• Utilizes strong cross-functional collaboration, analytical thinking, attention to detail, and problem-solving skills to define and manage IT control requirements, ensuring that project deliverables and milestones are achieved on time and within budget. • Trusted risk advisor on third-party risk management (TPRM) governance.• Performs IT control audits to ensure compliance with security standards, data privacy requirements, and regulations.

Current workplace

Tim Shen's current company

Company context helps verify the profile and gives searchers a useful next step.

Health Care Service Corporation
Health Care Service Corporation
Senior Business Information Security Officer (BISO)
Chicago, IL, US
Employees
1470
AeroLeads page
5 roles

Tim Shen work experience

A career timeline built from the work history available for this profile.

Grc Analyst And Lead Of Cyber Risk Management Program In Governance, Risk And Compliance (Grc)

Current

Illinois, United States

• Leads the IT risk and policy exception management program in cybersecurity Governance, Risk and Compliance (GRC) organization.• Establishes a roadmap and matures an IT risk management program (NIST Risk Management Framework).• Advises business and IT leadership on AI governance, manages and monitors Microsoft Copilot related risks.• Serves as a business liaison and security subject matter expert for cross-functional teams, assesses IT control gaps, approves policy exceptions, and validates effective IT controls in place and HIPAA compliance for the million-dollar project- Trustmark’s Microsoft Dynamics cloud-based call center.• Regularly identifies and assesses IT risks on vulnerabilities and security threats within a cloud environment (Microsoft Azure). Additionally, identify effective IT controls to safeguard PHI and PII,and protect the continuity of healthcare benefit operations and customer service for insurance policyholders.• Engages business, IT project teams, application owners and security architects to understand security risks and translates cybersecurity requirements into technical specifications.• Validates that the IT controls following relevant regulations (HIPAA, NYDFS, GDPR), standards (NIST 800-53, CIS, ISO 27001, HITRUST) and SOC2 audit readiness.• Maintains the risk register in ServiceNow, and continuously monitors changes in the IT risk profile of critical systems and technology.• Supports security incident response to protect PHI/PII and customer data.• Facilitates IT Risk Review Committee regular meetings to discuss the risk remediation plans and status.• Develops and presents IT risk executive reports including Key Risk Indicators (KRI) to senior leadership (CISO and CIO) monthly meetings in support of leadership risk-based decisions.• Trains IT control owners and mentor junior team members in identifying and managing IT risks in support of cybersecurity program.

Feb 2024 - Present

Senior Advisor, Information Security-Governance Risk And Compliance (Grc) (2Nd Line Of Defense)

Greater Chicago Area

• Developed and executed a global information security risk management process (NIST Risk Management Framework) for 6,000 associates across more than 30 countries.• Collaborated with first-line defense teams and business to identify IT risks and conducted risk assessments on IT control gaps, vulnerabilities and threats to sensitive data, critical business and applications.• Acted as a business liaison and security subject matter expert for cross-functional teams—including business units, architecture groups, IT control owners, security, and project teams—to identify security requirements, assess, and monitor IT control gaps and PCI DSS compliance risks throughout a four-year, $1 billion AWS cloud migration project.• Served as the primary point of contact for business stakeholders, collaborated closely with security teams, application architects, project managers, IT control owners, and product owners to identify security and PCI DSS compliance risks and implement risk remediation plans for a three-year, $100 million M&A project.• Trusted advisor on TPRM governance.• Built and maintained the global risk register in Archer, monitored changes in the risk profile.• Established common IT controls (NIST SP 800-53) to ensure their effectiveness.• Supported security incident response and controls to protect sensitive data.• Developed and presented monthly IT risk executive reports with key risk indicator (KRI) metrics to the Security Technology and Risk Committee (STRC), effectively influenced senior leadership (CIO, CISO) and business executives on high-risk decisions and prioritization.• Trained GRC team and IT control owners in risk identification and communication. • Supported audits for HIPAA, PCI DSS, and ISO 27001 compliance, including clients and regulatory bodies such as the Consumer Financial Protection Bureau (CFPB), New York Department of Financial Services (NYDFS), and the FTC.• Advised on remediating the SOX IT general controls (ITGC) deficiencies.

Jan 2018 - Feb 2024

Global It Security Compliance Manager

Jll

Greater Chicago Area

• Documented and maintained the Global IT security policies and standards for 70+ countries across all regions (the Americas, Europe, Middle East and Africa, and Asia Pacific.)• Supported internal and clients' audits for SOX, HIPAA and ISO 27001

Jun 2017 - Jan 2018

Ibm It Security Risk And Compliance Consultant

Ibm

Columbia, Missouri And Chicago, Il

o The Senior IBM Business Information Security Consultant was responsible for ensuring that over 100 IBM applications complied with HIPAA and HCSC security policies for Blue Cross and Blue Shield across Illinois, Montana, New Mexico, Oklahoma, and Texas.o Collaborated with business and IT teams (across 1st and 2nd lines of defense) to identify and conduct risk assessments on third party IT risks (TPRM), and reviewed IT security exceptions and acceptance requests.o Advised Fortune 500 IBM clients on the implementation of security policies, IT risk and compliance management in support of SOX, HIPAA, FISMA, NIST 800-53, PCI DSS, ISO 27001 and SOC 2.

Nov 1998 - Jun 2017
Team & coworkers

Colleagues at Health Care Service Corporation

Other employees you can reach at trustmarkbenefits.com. View company contacts for 1470 employees →

1 education record

Tim Shen education

FAQ

Frequently asked questions about Tim Shen

Quick answers generated from the profile data available on this page.

What company does Tim Shen work for?

Tim Shen works for Health Care Service Corporation.

What is Tim Shen's role at Health Care Service Corporation?

Tim Shen is listed as Senior Business Information Security Officer (BISO) at Health Care Service Corporation.

Where is Tim Shen based?

Tim Shen is based in Greater Chicago Area, United States while working with Health Care Service Corporation.

What companies has Tim Shen worked for?

Tim Shen has worked for Health Care Service Corporation, Trustmark, Transunion, Jll, and Ibm.

Who are Tim Shen's colleagues at Health Care Service Corporation?

Tim Shen's colleagues at Health Care Service Corporation include Ebony Bagby, Kimberley Rixen, Carolyn Wharton, Cory Ann Gentry, and Duane Holder.

How can I contact Tim Shen?

You can use AeroLeads to view verified contact signals for Tim Shen at Health Care Service Corporation, including work email, phone, and LinkedIn data when available.

What schools did Tim Shen attend?

Tim Shen holds Master'S Degree, Information System And Computer Science from Depaul University.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.

People with similar names

Check these profiles if this is not the Tim Shen you were looking for.

View similar profiles