Blue Cross and Blue Shield Association logo

Cyber Defense Specialist, Senior

Blue Cross and Blue Shield Association
  • Oakland, CA
    4 days ago

    Job Description

    Your Role

    The Information Security team is looking for a certified security professional to join our fast paced, highly collaborative, and diverse team of talent. Our mission is to provide operationally excellent next-generation information security event monitoring, threat hunting, and incident response services that protect our customers from adverse cyber events. The Cyber Defense Specialist, Senior will report to the Senior Manager of Information Security Operations. In this role you will utilize industry leading technology to detect, respond, and recover from advanced attacks and apply root cause analysis and lessons learned to proactively protect against known adversary tactics, techniques, and procedures, prevent impact of our customer's assets, and control recurrence of incidents.

    Qualifications

    Your Knowledge and Experience

    • Typically, requires advanced knowledge of job area typically obtained through advanced education combined with experience. May have practical knowledge of project management.

    • Typically, requires a college degree or equivalent experience and minimum 5 years of prior relevant experience.

    • GCIH certification preferred

    • CISSP certification preferred

    • Security event monitoring and incident response.

    • Security Information Event Management (SIEM) searching.

    • Intrusion detection and network tools; Wireshark, Nmap.

    • Anti-virus and malware detection.

    • Social engineering and phishing detection.

    • Identity & Access Management.

    • Incident Response

    • Managed Defense

    Hybrid

    This role requires employees to be in - office based on our hybrid workplace model, balancing purposeful in - person collaboration with flexibility. For most teams, this means coming into the office two days each week.

    Employees living more than 50 miles from an office location will work with their manager to determine in-office time based on business need.

    #LI-CP4

    Your Work

    In this role, you will:

    • Provide advanced network intrusion monitoring of and response including performing security incident risk assessment and severity declaration
    • Perform expert level endpoint detection and response (EDR)
    • Analyze application and web security events
    • Interpret logs for expert level threat hunting to identify and respond to indicators of compromise (IOCs) and threats including User and Event Behavioral Analytics (UEBA) using a security information and event management (SIEM) environment
    • Perform incident response containment
    • Utilize Security Orchestration, Automation, and Response (SOAR) of information security incidents
    • Respond and facilitate tier-3 incident management; mobilize security incident response team (SIRT) of key stakeholders; communicate and notify at all levels of the organization; perform post-incident activity involving root cause analysis (RCA) and lesson learned assessments and identify owners of correction action plans (CAP)
    • Formulation of security operation incident response plan, operational procedures, desk level procedures, and operational level agreements
    • Yield security compliance evidence of NIST 800-53 controls

    Your Work

    In this role, you will:

    • Provide advanced network intrusion monitoring of and response including performing security incident risk assessment and severity declaration
    • Perform expert level endpoint detection and response (EDR)
    • Analyze application and web security events
    • Interpret logs for expert level threat hunting to identify and respond to indicators of compromise (IOCs) and threats including User and Event Behavioral Analytics (UEBA) using a security information and event management (SIEM) environment
    • Perform incident response containment
    • Utilize Security Orchestration, Automation, and Response (SOAR) of information security incidents
    • Respond and facilitate tier-3 incident management; mobilize security incident response team (SIRT) of key stakeholders; communicate and notify at all levels of the organization; perform post-incident activity involving root cause analysis (RCA) and lesson learned assessments and identify owners of correction action plans (CAP)
    • Formulation of security operation incident response plan, operational procedures, desk level procedures, and operational level agreements
    • Yield security compliance evidence of NIST 800-53 controls

    Numbers & Facts

    LocationOakland, CA
    IndustryInsurance
    Company Size2,000 to 2,499 employees
    Websitehttps://www.bcbs.com/about-us/careers

    About Company

    At the Blue Cross and Blue Shield Association (BCBSA), we provide business strategy, technical support and consulting expertise to 36 Blue Cross and Blue Shield companies across the nation, employing more than 1,000 of the best strategic thinkers in the industry. We are a Brand manager that sets quality control standards for the 36 independent companies that use the Blue Cross and Blue Shield Brands, and we serve as a trade association that represents these Blue companies. It is through our involvement that the Blues companies share a united vision and strategy while also benefiting from the local strength of all member companies.

    Skills

    • Applications Securityunmatched
    • Automationunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Securityunmatched
    • Customer/Consumer Behaviorunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • Huntingunmatched
    • Identity Data Managementunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • NMapunmatched
    • Network Monitoringunmatched
    • Network Securityunmatched
    • Operations Managementunmatched
    • Operations Planningunmatched
    • Operations Processesunmatched
    • Project/Program Managementunmatched
    • Risk Analysisunmatched
    • Root Cause Analysisunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Team Playerunmatched
    • Technical Leadershipunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Web Analyticsunmatched
    • Wireshark (Ethereal)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder