Senior Information Security Analyst

Job ID: J120078
Company: HM Health Solutions Inc.
Location: Pittsburgh, PA, United States
Full/Part Time: Full time
Job Type: Regular
Posted at: Sep 9, 2018

Share:

Description

This role is responsible for advancing the maturity of the Highmark application security program. The role will interface with senior leaders in the product development areas to ensure secure development practices. It will also serve as a technical lead on remediation of vulnerabilities and weaknesses within the application portfolio.

Ideal candidates will have Java development experience and demonstrated success in leading SDLC change. This position offers opportunities for developers looking to broaden their knowledge of secure development and secure architecture practices, or for security professionals looking to demonstrate leadership in growth towards management positions.

ESSENTIAL RESPONSIBILITIES 

  • Lead projects to advance SSDLC capabilities
  • Implement security governance over development activities
  • Serve in a consulting role on technical implementation of application security controls
  • Maintain application security controls in support of SOC2, HITRUST, PCI, and contractual compliance
  • Manage vendor relationships
  • Advocate for SSDLC changes with senior product leaders
  • Other duties as assigned or requested.

REQUIRED EDUCATION

  • Bachelor’s Degree in Information Security, Information Systems,  Information Assurance, Computer Science or related field

Substitutions 

  • 7 years of Information Security, Governance, Risk and/or Compliance, Information Technology or Business Analysis

PREFERRED EDUCATION

  • Master’s Degree in Computer Science, Information Security or related field

REQUIRED EXPERIENCE

  • 7 - 10 years of experience with Information Security and Systems Analysis
  • 5 - 7 years of experience with Information Security and/or Information Risk Management and/or Information Technology                  
  • 5 - 7 years of experience with Information Security Governance, Risk and/or Compliance functions and activities                  
  • 5 - 7 years of experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences                       
  • 5 - 7 years of experience with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms

PREFERRED EXPERIENCE

  • 5 years of Java development experience
  • 3 years of experience implementing SDLC change (e.g., adopting Agile, implementing SSDLC activities, CI/CD implementation)
  • In-depth understanding of the OWASP Top 10 and mitigations
  • Mentorship/coaching experience in a professional setting
  • Experience delivering reduced security defects in an effective SSDLC

PREFERRED LICENSES AND CERTIFICATIONS

  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer - Java (GSSP-JAVA)
  • GIAC Web Application Defender (GWEB)
  • Offensive Security Web Expert (OSWE)

SKILLS 

  • Operating SAST and DAST tools and understanding their output
  • Ability to research and solve problems
  • Familiarity with secure SDLC best practices and frameworks
  • Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.                 
  • Strong teamwork and inter-personal skills

TRAVEL REQUIREMENT:

0% - 25%

Referral Payout Level: 4

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.
EEO is The Law
Equal Opportunity Employer Minorities/Women/ProtectedVeterans/Disabled/Sexual Orientation/Gender Identity (http://www1.eeoc.gov/employers/upload/eeoc_self_print_poster.pdf)
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.
For accommodation requests, please call HR Services at 844-242-HR4U or visit HR Services Online at HRServices@highmarkhealth.org

Share:

Interested in working at the Highmark Health enterprise?
Take the first step by joining our Talent Network today!

Join Our Talent Network

Similar Jobs

Senior Application Developer

Pittsburgh, PA, United States
IS/IT

Application Developer - Angular JS

Pittsburgh, PA, United States
IS/IT

IT Systems Analyst - Associate

Pittsburgh, PA, United States
IS/IT

Release Management Manager

Camp Hill, PA, United States
IS/IT

Informatica Developer

Pittsburgh, PA, United States
IS/IT

Release Management Manager

Pittsburgh, PA, United States
IS/IT

Application Developer - Angular JS

Camp Hill, PA, United States
IS/IT

Sr Architect - Data integration

Pittsburgh, PA, United States
IS/IT

Application Development Consultant EIA CM/MDM

Pittsburgh, PA, United States
IS/IT

DATA ARCHITECT

Pittsburgh, PA, United States
IS/IT

Salesforce Consultant - Senior Markets

Pittsburgh, PA, United States
IS/IT

Mgr IT - Data Management and Analytics

Pittsburgh, PA, United States
IS/IT

Sr Architect - Data integration

Camp Hill, PA, United States
IS/IT

Associate Business Systems Analyst

Pittsburgh, PA, United States
IS/IT

IT Team Manager, Customer Care Center

Pittsburgh, PA, United States
IS/IT

Sr IT Architect

Pittsburgh, PA, United States
IS/IT

Architect - Enterprise GRC Technology Archer

Pittsburgh, PA, United States
IS/IT

IT Team Manager, Customer Care Center

Camp Hill, PA, United States
IS/IT

Business System Analyst

Pittsburgh, PA, United States
IS/IT

Application Developer - Java

Camp Hill, PA, United States
IS/IT

Application Developer - Java

Wilkes-Barre, PA, United States
IS/IT

Application Developer - Java

Pittsburgh, PA, United States
IS/IT

Consultant - Client Delivery

Pittsburgh, PA, United States
IS/IT

Consultant

Pittsburgh, PA, United States
IS/IT

Principal Consultant

Pittsburgh, PA, United States
IS/IT