Information Security Sr Advisor - Automation Engineer

Elevance Health
Louisville, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Louisville, United States of America

Tech stack

Java
API
Cloud Computing
Cloud Computing Security
Cloud Engineering
Static Program Analysis
Computer Security
Information Systems
Computer Networks
Distributed Systems
Middleware
Fault Tolerance
Github
Identity and Access Management
IT Management
Information Systems Security Architecture Professional
Python
Key Management
Network Security
Enterprise Messaging Systems
Network Architecture
Systems Development Life Cycle
Secure Coding
Amazon Web Services (AWS)
Software Engineering
Systems Architecture
Systems Integration
Cloud Platform System
Software Security
Event Driven Architecture
Containerization
Gitlab-ci
Kubernetes
Infrastructure Automation Frameworks
Information Technology
Enterprise Integration
Kafka
REST
Amazon Web Services (AWS)
Terraform
Devsecops
Docker
Jenkins
ServiceNow

Job description

Develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and integration solutions necessary to support secure cloud account provisioning, enterprise security platforms, and data at rest protection capabilities in compliance with established company policies, regulatory requirements, and generally accepted information security controls. Responsible for the design, development, and delivery of scalable cloud-native integration services, secure API frameworks, and automation solutions supporting enterprise encryption, access control, and secure transaction/messaging platforms across hybrid and cloud environments.

How You Will Make an Impact:

  • Supports system and network architecture initiatives for information and network security technologies
  • Supports the development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations
  • Contributes to requirements gathering, system architecture, and software design activities for security products and services
  • Assists with the discovery, evaluation, and response to emerging networking threats and security vulnerabilities
  • Develops security incident response plans and strategies
  • Provides trouble resolution and serves as point of technical escalation on complex problems
  • Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise
  • May be assigned to project teams for technical consultation to business partners and developers
  • Designs & engineers comprehensive access management and network security technical solutions based on business requirements and defined technology standards; works with architecture to update technology direction & strategy
  • Develops reports supporting strategy and direction for management
  • Capable of serving as technical merger & acquisition lead
  • Acts as a subject matter expert among peers, with manager and senior management
  • Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security
  • Designs and develops secure integration services connecting cloud account/project provisioning systems, ServiceNow workflows, middleware platforms, and enterprise security tooling through APIs
  • Builds resilient cloud-native automation services with observability, retry logic, fault tolerance, and secure service-to-service communication across distributed systems
  • Develops and deploys containerized applications leveraging Kubernetes/EKS, CI/CD pipelines, Infrastructure as Code, and DevSecOps best practices

Requirements

  • Requires BS/BA in information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background., * Experience developing integrations and automation services using Python, Java, or Go
  • Experience building and consuming REST APIs and integrating with enterprise security platforms via APIs
  • Experience with AWS cloud technologies including EKS, IAM, and secure cloud-native architectures
  • Must have experience with Docker, Kubernetes, and containerized application deployments
  • Preferred experience with CI/CD pipelines including GitHub Actions, Jenkins, or GitLab CI
  • Preferred experience with Infrastructure as Code tools such as Terraform
  • Strongly preferred experience implementing secure development practices including secrets management, dependency scanning, and code analysis
  • Preferred experience with ServiceNow integrations, workflows, and middleware orchestration platforms
  • Preferred experience with event-driven architectures including Kafka, SNS, and SQS
  • Strongly preferred understanding of distributed systems, resiliency patterns, fault tolerance, and observability practices
  • Must be a team player and participate as a team member in the automation and development process
  • Security Certifications: CISSP and other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Security Engineering Professional, Certification and Accreditation Professional, or equivalent certifications) strongly preferred

Benefits & conditions

At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.

We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.

About the company

Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.

Apply for this position