Anticipated End Date:
2026-09-30
Position Title:
Information Security Advisor
Job Description:
Information Security Advisor
Hybrid: This role requires associates to be in-office1 - 2days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Information Security Advisor is responsible for the delivery of strategic network security, access control and secure transaction/messaging solutions. Ensures security solutions involving the use of technologies are well-conceived, designed and implemented in compliance with enterprise standards.
How you will make an impact:
Provides first level engineering design functions and trouble resolution; provides trouble resolution and serves as point of technical escalation on complex problems; leads or plans implementations for access management and network security technologies; develops testing plans to ensure quality of implementation; leads the investigation and reporting of data security events and incidents; provides system and network architecture support for information and network security technologies; provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies; maintains security incident response plans; represents major upgrades and business system replacements in change control; oversees Enterprise mix of vendor services; recommends changes and updates to strategy; may act a key contact for setting vendor strategy; designs & engineers repetitive technical solutions based on business requirements and defined technology standards; develops support procedures and performance metrics reports; leads level 1 & 2 incident recoveries; may organize the efforts of other analysts as part of incident recovery; leads root cause analysis efforts.
Must be capable of providing top-tier support for 4 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security.
Minimum Qualification:
Requires BS/BA degree in Information Technology or related field of study and a minimum of 5 years of experience in systems support, system administration, system engineering, system security, access management, network security, network communications, computer networking, telecommunications, systems development and management, hardware, software, and/or data; or any combination of education and experience, which would provide an equivalent background.
Requires experience in planning and designing highly complex systems.
Preferred Skills, Capabilities, and Experiences:
Experience with multiple technical and business disciplines.
Security Certifications: CISSP or other technical security certifications (e.g. Systems Security Certified Practitioner, Certification and Accreditation Professional).
Strong understanding of IAM governance principles and frameworks.
Ability to perform governance assessments and maturity evaluations.
Knowledge of risk assessment methodologies and control frameworks.
Solid understanding of identity governance and administration (IGA).
Experience with one or more of: SOX, HIPAA, NIST 800-53, SOC.
If this job is assigned to any Government Business Division entity, the applicant and incumbent fall under a 'sensitive position' work designation and may be subject to additional requirements beyond those associates outside Government Business Divisions. Requirements include but are not limited to more stringent and frequent background checks and/or government clearances, segregation of duties principles, role specific training, monitoring of daily job functions, and sensitive data handling instructions. Associates in these jobs must follow the specific policies, procedures, guidelines, etc. as stated by the Government Business Division in which they are employed.
Job Level:
Non-Management Exempt
Workshift:
1st Shift (United States of America)
Job Family:
IFT > IT Security & Compliance
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.