Menu

Information Security Executive Advisor

at Elevance Health in CHICAGO, Illinois, United States

Job Description

Information Security Executive Advisor

Location: This position will work a hybrid model (remote and in office one day per week). Ideal candidates will live within 50 miles of one of our Pulse Point locations in Indianapolis, IN, Atlanta, GA, Chicago, IL, Richmond, VA, Norfolk, VA, Mason, OH, Portland, ME, St. Louis, MO, Wallingford, CT, Louisville, KY, Wilmington, DE, Tampa, FL or Nashville, TN.

The Information Security Executive Advisor is a technical role that develops and drives our Cloud Security Architecture models and strategies. This role will focus on organizing and rationalizing Elevance’s systems and information assets to ensure business and IT alignment with Security requirements standards. This position will also involve mentoring other teams and providing SME-level guidance, clearly communicating technical requirements to the implementation teams, and supporting the effort to secure Elevance’s resources in Microsoft Azure.

How you will make an impact:

+ Creates ServiceNOW dashboards and configures API integrations with cross-team ServiceNOW frameworks (e.g., APM, ESG) to ensure visibility into the GCP environment and process flows.

+ Provides strategic and tactical security control recommendations, operational security blueprints and roadmaps, reference architectures for security patterns, and general security technology/application assessments.

+ In collaboration with the Business, Application teams, and the CCOE, the Cloud Security Architect establishes overall Azure security architecture vision and ensures specific components are appropriately designed and leveraged.

+ Collaborates with IT and ensures that the construction of architecture components (e.g., domain architecture, solution architecture, and technical architecture) aligns with architecture strategies.

+ Develops innovative technology approaches to solve security and business problems and is usually sought out as an expert in this field.

+ Participates in the Cloud Governance processes and community of practice.

+ Recommends changes and updates to cloud security governance strategy based on NIST, regulatory and evolving threats drivers.

+ Proposes opportunities to improve security outcomes and reduce risks based on targeted or continuous assessments.

Minimum Requirements:

Requires BS/BA in Information Technology or related field of study and a minimum of 10 years’ experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.

Preferred skills, capabilities, and experiences:

+ Strong knowledge on CI/CD processes and tools, deploying, configuring, and automating CI-CD release pipeline strongly preferred.

+ Knowledge of Common DevOps scripting languages (Python, BASH, etc.) strongly preferred.

+ Experience with REST, JSON, SOAP/XML – Web services strongly preferred.

+ Experience with CI/CD tools – Jenkins, Bamboo, Git, Maven/Gradle, Sonar, Artifactory, Jira, Checkmarx, RabbitMQ strongly preferred.

+ Experience in implementing DevOps automation with Terraform and Ansible following Infrastructure as Code (IaC) concept strongly preferred.

+ Good understanding of agile and other development processes strongly preferred.

+ 7+ years of experience in Information Security-focused efforts, with demonstrated ability to distill complex security problems and drive toward creative solutions while complying with Enterprise policies strongly preferred.

+ Experience participating with Enterprise executives to establish strategic plans and objectives strongly preferred.

+ Demonstrated ability to communicate clearly with all constituents, serving as a mentor and SME strongly preferred.

+ Experience in analyzing both detailed design components and high-level architectural blueprints, ensuring compliance with Enterprise policy and guidelines strongly preferred.

+ Experience in designing, communicating, and driving security controls matrix that complies with Enterprise-level security standards strongly preferred.

+ Experience in designing, analyzing, and implementing testing plans to ensure security guardrails cannot be compromised strongly preferred.

+ Clear understanding of overall systems architecture and how to leverage specific components strongly preferred.

+ Understanding of Cloud infrastructure environments and the challenges associated with Enterprise integration, with demonstrated ability to grasp and contribute to big-picture strategy strongly preferred.

+ Experience in hands-on roles, with a focus on operational and security-focused tasks strongly preferred.

+ Experience with analyzing and securing Artificial Intelligence (AI) prior to Cloud migration strongly preferred.

+ Understanding of legal /regulatory requirements such as PCI-DSS, HIPAA, NIST, FISMA, etc. strongly preferred.

+ Experience in programmatic integration with ticketing and asset management systems strongly preferred.

+ Security Certifications: CISSP preferred, CCSP and other advanced technical security certifications (e.g., Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Certification and Accreditation or equivalent certifications); any level of training on Microsoft Azure, Cloud Security Alliance (CSA) Controls Matrix, and CIS benchmarks strongly preferred.

To view full details and how to apply, please login or create a Job Seeker account
How to Apply Copy Link

Job Posting: JC263186994

Posted On: Jul 26, 2024

Updated On: Jul 27, 2024

Please Wait ...