Information Security Sr Advisor

Elevance Health
Atlanta, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 229K

Job location

Atlanta, United States of America

Tech stack

Amazon Web Services (AWS)
Azure
Cloud Computing
Computer Security
Information Systems
Computer Networks
Databases
Data Masking
DevOps
Identity and Access Management
IT Management
Key Management
Network Security
Network Architecture
PCI Data Security Standards
Public Key Infrastructure
Systems Development Life Cycle
RSA (Cryptosystem)
Software Engineering
Systems Architecture
Systems Integration
Tokenization
Transport Layer Security
Google Cloud Platform
Enterprise Software Applications
Cloud Platform System
Cyberark
Software Security
Kubernetes
Information Technology
Hashicorp
Api Design

Job description

Develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls. This role will be responsible for designing, implementing, and supporting enterprise key management and data protection solutions across hybrid and cloud environments. The ideal candidate will combine deep technical expertise in encryption technologies with strong solution engineering and stakeholder engagement skills.

How You Will Make an Impact:

  • Leads system and network architecture support for information and network security technologies
  • Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations
  • Leads the development of requirements, system architecture, and software design of security products and services
  • Leads the development of strategies for discovery, evaluation and response to new networking attacks
  • Develops security incident response plans and strategies
  • Provides trouble resolution and serves as point of technical escalation on complex problems
  • Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise
  • Sets vendor strategy and direction
  • May be assigned to project teams for technical consultation to business partners and developers
  • Designs & engineers comprehensive access management and network security technical solutions based on business requirements and defined technology standards; works with architecture to update technology direction & strategy
  • Develops reports supporting strategy and direction for management
  • Capable of serving as technical merger & acquisition lead
  • Acts as a subject matter expert among peers, with manager and senior management
  • Design, deploy, and maintain enterprise encryption and key management solutions using Thales CipherTrust Manager (CTM) and related Thales products (HSMs, key vaults, tokenization, etc.).
  • Architect secure key lifecycle management processes, including key generation, rotation, escrow, revocation, and destruction.
  • Integrate encryption and key management solutions with enterprise applications, databases, cloud platforms (AWS, Azure, GCP), and on-prem systems.
  • Implement and support KMIP integrations and API-based key management solutions.
  • Partner with security architecture, DevOps, infrastructure, and application teams to ensure encryption best practices are embedded into system designs.
  • Conduct encryption posture assessments and recommend remediation plans.
  • Support compliance initiatives (PCI-DSS, HIPAA, SOX, GDPR, etc.) related to data protection and cryptographic controls.
  • Troubleshoot and resolve complex encryption and key management issues.
  • Develop technical documentation, architecture diagrams, and operational runbooks.
  • Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security

Requirements

  • Requires BS/BA in information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background., * Thales certifications (CipherTrust, Luna HSM, etc.) preferred
  • Experience with container and DevOps environments (Kubernetes, CI/CD pipelines) preferred
  • Familiarity with secrets management tools (HashiCorp Vault, CyberArk, etc.) preferred
  • Experience with tokenization and data masking technologies preferred
  • Security certifications such as CISSP, CISM, or CCSP preferred
  • Hands-on experience with:
  • Thales CipherTrust Manager (CTM)
  • Thales HSMs (e.g., Luna HSM)
  • Enterprise key management and encryption platforms
  • Strong understanding of:
  • Cryptographic algorithms (AES, RSA, ECC, SHA-2/3)
  • PKI concepts and certificate lifecycle management
  • KMIP protocol
  • TLS/SSL and secure communications
  • Experience integrating encryption solutions in cloud environments (AWS KMS, Azure Key Vault, GCP KMS) preferred
  • Knowledge of compliance frameworks and cryptographic regulatory requirements preferred
  • Strong troubleshooting and root cause analysis skills preferred

Benefits & conditions

For candidates working in person or virtually in the below location(s), the salary* range for this specific position is $127,200 to $228,960

Locations: California; Illinois; New York; Washington State

In addition to your salary, Elevance Health offers benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). The salary offered for this specific position is based on a number of legitimate, non-discriminatory factors set by the Company. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of gender, race, or any other category protected by federal, state, and local pay equity laws.

  • The salary range is the range Elevance Health in good faith believes is the range of possible compensation for this role at the time of this posting. This range may be modified in the future and actual compensation may vary from posting based on geographic location, work experience, education and/or skill level. Even within the range, the actual compensation will vary depending on the above factors as well as market/business considerations. No amount is considered to be wages or compensation until such amount is earned, vested, and determinable under the terms and conditions of the applicable policies and plans. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee

Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health., At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.

We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.

About the company

Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.

Apply for this position