AMVETS Jobs

Job Information

Elevance Health Threat Detection Engineer in ATLANTA, Georgia

Threat Detection Engineer

Location: This position will work a hybrid model (remote and office). The ideal candidate will live within 50 miles of one of our Elevance Health PulsePoint locations.

The Threat Detection Engineer is responsible for developing, maintaining, and improving detection capabilities within SIEM and other analytic platforms to safeguard our digital assets against various cyber threats. You'll work closely with cross-functional teams and leverage advanced technological tools to ensure an optimal cybersecurity environment.

How You Will Make An Impact:

  • Develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls.

  • Research emerging threats and vulnerabilities, perform gap analysis, and curate threat detection Use Cases.

  • Perform capability abstraction based on research of adversarial TTPs and build threat models and detectors,

  • Collaborate with threat hunters in purple team exercises to mature the organization’s detection capabilities.

  • Build and maintain threat detection library.

  • Analyze tactics, techniques, and procedures (TTPs) provided by the Threat Intelligence Group and establish detection capabilities based on these findings.

  • Develop advanced detection logics and algorithms which can efficiently spot and alert of any suspicious activity or potential threats.

  • Continuously maintain, update, and improve existing detection capabilities to ensure their effectiveness against evolving threats.

  • Collaborate with cross-functional cybersecurity teams to ensure comprehensive and integrated cybersecurity measures.

  • Conduct regular testing of detection logic and security controls and make necessary refinements.

  • Stay up-to-date with the latest cybersecurity trends, tools, and best practices to continually enhance detection capabilities.

  • Prepare and present detailed reports summarizing the effectiveness of detection measures and suggesting improvements, when necessary.

  • Leads system and network architecture support for information and network security technologies;

  • Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations; leads the development of requirements, system architecture, and software design of security products and services;

  • Leads the development of strategies for discovery, evaluation and response to new networking attacks;

  • Develops security incident response plans and strategies.

  • Provides trouble resolution and serves as point of technical escalation on complex problems.

  • Partner with key stakeholders to improve the security posture of the organization.

  • Serve as a mentor and help develop talent pipeline.

  • Ensure security solutions involving the use of technologies are well-conceived, designed and implemented in compliance with enterprise standards.

  • Provides system and network architecture support for information and network security technologies; provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies.

  • Maintains security incident response plans; represents major upgrades and business system replacements in change control.

  • Oversees Enterprise mix of vendor services; recommends changes and updates to strategy; may act a key contact for setting vendor strategy; designs & engineers repetitive technical solutions based on business requirements and defined technology standards.

  • Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security.

Minimum Requirements:

  • Requires BS/BA in information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required.

  • Requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background.

Preferred Skills, Capabilities & Experiences:

  • Strong programming and/or scripting skills preferred.

  • Strong understanding of various cybersecurity threats and appropriate detection measures preferred.

  • Knowledge of various security technologies, protocols, and applications.

  • Strong analytical, problem-solving, and decision-making skills preferred.

  • Reverse engineering experience preferred.

  • Security Certifications: OSCP, OSEP, GREM or other Offensive Security/ DFIR certifications are preferred.

DirectEmployers