Senior Information Security Analyst

Job ID: J117643
Company: HM Health Solutions Inc.
Location: Camp Hill, PA, United States
Full/Part Time: Full time
Job Type: Regular
Posted at: Feb 28, 2018

Share:

Description

This role is responsible for advancing the maturity of the Highmark application security program. The role will interface with senior leaders in the product development areas to ensure secure development practices. It will also serve as a technical lead on remediation of vulnerabilities and weaknesses within the application portfolio.

Ideal candidates will have Java development experience and demonstrated success in leading SDLC change. This position offers opportunities for developers looking to broaden their knowledge of secure development and secure architecture practices, or for security professionals looking to demonstrate leadership in growth towards management positions.

ESSENTIAL RESPONSIBILITIES 

  • Lead projects to advance SSDLC capabilities
  • Implement security governance over development activities
  • Serve in a consulting role on technical implementation of application security controls
  • Maintain application security controls in support of SOC2, HITRUST, PCI, and contractual compliance
  • Manage vendor relationships
  • Advocate for SSDLC changes with senior product leaders
  • Other duties as assigned or requested.

REQUIRED EDUCATION

  • Bachelor’s Degree in Information Security, Information Systems,  Information Assurance, Computer Science or related field

Substitutions 

  • 7 years of Information Security, Governance, Risk and/or Compliance, Information Technology or Business Analysis

PREFERRED EDUCATION

  • Master’s Degree in Computer Science, Information Security or related field

REQUIRED EXPERIENCE

  • 7 - 10 years of experience with Information Security and Systems Analysis
  • 5 - 7 years of experience with Information Security and/or Information Risk Management and/or Information Technology                  
  • 5 - 7 years of experience with Information Security Governance, Risk and/or Compliance functions and activities                  
  • 5 - 7 years of experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences                       
  • 5 - 7 years of experience with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms

PREFERRED EXPERIENCE

  • 5 years of Java development experience
  • 3 years of experience implementing SDLC change (e.g., adopting Agile, implementing SSDLC activities, CI/CD implementation)
  • In-depth understanding of the OWASP Top 10 and mitigations
  • Mentorship/coaching experience in a professional setting
  • Experience delivering reduced security defects in an effective SSDLC

PREFERRED LICENSES AND CERTIFICATIONS

  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Secure Software Programmer - Java (GSSP-JAVA)
  • GIAC Web Application Defender (GWEB)
  • Offensive Security Web Expert (OSWE)

SKILLS 

  • Operating SAST and DAST tools and understanding their output
  • Ability to research and solve problems
  • Familiarity with secure SDLC best practices and frameworks
  • Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.                 
  • Strong teamwork and inter-personal skills

TRAVEL REQUIREMENT:

0% - 25%

Referral Payout Level: 2

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.
EEO is The Law
Equal Opportunity Employer Minorities/Women/ProtectedVeterans/Disabled/Sexual Orientation/Gender Identity (http://www1.eeoc.gov/employers/upload/eeoc_self_print_poster.pdf)
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.
For accommodation requests, please call HR Services at 844-242-HR4U or visit HR Services Online at HRServices@highmarkhealth.org

Share:

Interested in working at the Highmark Health enterprise?
Take the first step by joining our Talent Network today!

Join Our Talent Network

Similar Jobs

Application Developer

Pittsburgh, PA, United States
IS/IT

Sr Application Developer

Pittsburgh, PA, United States
IS/IT

Team Manager, IT

Pittsburgh, PA, United States
IS/IT

Developer - Business Intelligence, Data Warehousing

Pittsburgh, PA, United States
IS/IT

Learning Experience Manager

Pittsburgh, PA, United States
IS/IT

Manager, IT

Pittsburgh, PA, United States
IS/IT

Denodo System Administrator

Pittsburgh, PA, United States
IS/IT

Sr Application Developer

Camp Hill, PA, United States
IS/IT

Senior Developer (Multiple Openings)

Pittsburgh, PA, United States
IS/IT

Senior Analytics Developer

Pittsburgh, PA, United States
IS/IT

Denodo System Administrator

Camp Hill, PA, United States
IS/IT

Information Security Analyst, Threat Management

Wilmington, DE, United States
IS/IT

Information Security Analyst, Threat Management

Camp Hill, PA, United States
IS/IT

Information Security Analyst, Threat Management

Pittsburgh, PA, United States
IS/IT

Information Security Analyst, Threat Management

Parkersburg, WV, United States
IS/IT

Information Security Analyst, Threat Management

Wilkes-Barre, PA, United States
IS/IT

Application Developer - Informatica

Harrisburg, PA, United States
IS/IT

Associate Consultant

Pittsburgh, PA, United States
IS/IT

IT Manager - Test Data Management

Pittsburgh, PA, United States
IS/IT

Financial Systems Analyst

Camp Hill, PA, United States
IS/IT

Mainframe Build Engineer

Pittsburgh, PA, United States
IS/IT

Mainframe Build Engineer

Camp Hill, PA, United States
IS/IT

IT Infrastructure Representative

Pittsburgh, PA, United States
IS/IT