Leads system and network architecture support for information and network security technologies; Develops technical security controls and secure configuration baselines for public cloud resources in AWS, Azure, and GCP. Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations. Support Information Technology, Information Security, and the business in the evaluation and understanding of complex technical issues impacting... more details
Anticipated End Date:
2024-07-26
Position Title:
Senior IT Security Advisor - Cloud Vulnerability Management
Job Description:
Senior IT Security Advisor - Cloud Vulnerability Management
Location: This position will work in a hybrid model (remote and office). The ideal candidate will live within 50 miles of one of our Elevance Health PulsePoint locations.
The Senior IT Security Advisor - Cloud Vulnerability Management develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls. This role will provide expertise within the Cloud Vulnerability Management and Secure Configuration Assessment program to include Cloud Security Posture Management (CSPM).
How you will make an impact:
- Leads system and network architecture support for information and network security technologies; Develops technical security controls and secure configuration baselines for public cloud resources in AWS, Azure, and GCP.
- Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations.
- Support Information Technology, Information Security, and the business in the evaluation and understanding of complex technical issues impacting the prevention, detection, and/or remediation of vulnerabilities and misconfigurations.
- Leads the development of strategies for discovery, evaluation, and response to new networking attacks. Develops security incident response plans and strategies.
- Provides trouble resolution and serves as a point of technical escalation on complex issues related to data ingestion and data quality; drives ownership and timely remediation of issues identified in Prisma Cloud.
- Sets vendor strategy and direction.
- Technical expert supporting vulnerability management and stakeholders for areas including system administration, network infrastructure, IT operations, and data administration; provide Subject Matter Expertise on cloud security, container security, vulnerability risk, remediation, and mitigation.
- Designs & engineers comprehensive access management and network security technical solutions based on business requirements and defined technology standards; works with architecture to update technology direction & strategy.
- Build and maintain effective relationships with business and technology partners to drive improvement and promote strategic objectives of vulnerability management program. Build and present metrics that are reported to the board of directors.
- Prepare audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions; develop reports supporting strategy and direction for management.
- Capable of serving as technical merger & acquisition lead.
- Acts as a subject matter expert among peers, with manager and senior management; provides mentorship, professional development, and coaching for associates at all levels of the vulnerability management program.
Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets:
Access Control, Application Security, Business Continuity and Disaster Recovery Planning, Cryptography, Information Security and Risk Management, Legal Regulations, Compliance and Investigations, Operations Security, Physical (Environmental) Security, Security Architecture and Design, Telecommunications and Network Security
Minimum Requirements:
Requires BS/BA in Information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities, and Experiences:
- Security Certifications: CISSP and other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Security Engineering Professional, Certification and Accreditation Professional, or equivalent certifications) are strongly preferred.
- Vendor-specific cloud security certifications such as AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer are strongly preferred.
- Experience working with vulnerability management and configuration assessment tools such as Prisma, Azure Defender, Qualys, Tanium, and Splunk.
- Experience working with Prisma Cloud Compute or equivalent technology in the Cloud Vulnerability Management domain.
- Experience supporting security tooling deployed in DevOps pipelines (e.g. Azure DevOps, GitHub Actions).
- Experience working with multiple Cloud Service Providers (CSPs) including AWS, Azure, and GCP.
- Knowledge of relevant compliance standards such as PCI DSS, HIPAA, and NIST.
- Knowledge of data analytics and visualization tools such as Splunk, ELK, Snowflake, or Tableau
- Containerization technologies (e.g., Docker, Kubernetes, OpenShift).
- Tool expertise: Prisma Cloud and Compute, ServiceNow, EKS/ECS/Fargate, OpenShift/ROSA.
For candidates working in person or remotely in the below location(s), the salary* range for this specific position is $140,668 - $211,002
Location: District of Columbia (Washington, DC)
In addition to your salary, Elevance Health offers benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). The salary offered for this specific position is based on a number of legitimate, non-discriminatory factors set by the Company. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of gender, race, or any other category protected by federal, state, and local pay equity laws.
* The salary range is the range Elevance Health in good faith believes is the range of possible compensation for this role at the time of this posting. This range may be modified in the future and actual compensation may vary from posting based on geographic location, work experience, education and/or skill level. Even within the range, the actual compensation will vary depending on the above factors as well as market/business considerations. No amount is considered to be wages or compensation until such amount is earned, vested, and determinable under the terms and conditions of the applicable policies and plans. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.
Job Level:
Non-Management Exempt
Workshift:
1st Shift (United States of America)
Job Family:
IFT > IT Security & Compliance
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities – and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process. Candidates must reside within 50 miles or 1-hour commute each way of a relevant Elevance Health location.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact elevancehealthjobssupport@elevancehealth.com for assistance.