Cyber Security analyst
Apply on
Availability Status
This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.
Need consultants who worked with health clients previously
Abilities/Skills (candidate should possess most of these):
Ability to identify and resolve complex issues and develop security solutions to meet CareFirst s business and technology goals.
Strong written documentation skills and technical writing are required.
Excellent presentation and verbal communication skills.
Ability to effectively lead/complete tasks with a minimal level of supervision.
Strong computer skills, including knowledge of Microsoft Windows, various e-mail systems (Microsoft Exchange)
Possess broad understanding of the following systems/skill sets:
System hardening concepts and techniques
Network and remote access controls
Unix, Linux, Web application servers
Virtualization technologies
Encryption technologies and key management
Familiarity with access control methodologies (MAC, DAC. RBAC)
Preferred:
Significant understanding of NIST Risk Management Framework and Information Security Risk Management methodologies including FAIR quantitative model
Experience with Cybersecurity Governance, Risk, and Compliance (eGRC) Programs and Platforms.
Proven ability to translate technical requirements to the business.
Specific knowledge of CareFirst business and BlueCross BlueShield corporate structure.
An understanding of the relationships among various units within the corporation.
Ability to understand, develop, and socialize security policies, standards, and procedures.
Proficiency with security controls for cloud environments (Azure and AWS) including FedRAMP requirements.
Familiarity with security tools such as wireless and network scanning applications, vulnerability assessment applications and concepts, IDS/IPS, Data Loss Prevention, and other appropriate security related tools and capabilities.
Experience working with Information Security tools in a large, complex, multi-platform environment.
Familiarity with HIPAA Security Rule and compliance requirements.
Understands complex cybersecurity issues as well as emerging technologies and develop creative solutions while ensuring compliance with cyber security laws and regulations
Experience in risk management, compliance, audit, or third-party assessments