Demo

Lead Cyber Security Analyst (Hybrid)

CareFirst BlueCross BlueShield
Washington, DC Full Time
POSTED ON 1/30/2025
AVAILABLE BEFORE 4/28/2025
  • Resp & Qualifications
  • PURPOSE :
  • To ensure the organization's data remains protected from inappropriate access, disclosure and / or damage. To advocate for and execute the processes and practices of the Cybersecurity team while supporting business and customer needs.

    • ESSENTIAL FUNCTIONS :
    • Leads the team in regular assessments of network and system security for intrusion detection, vulnerability, and security configurations.
    • Develops procedures for assessing indicators using the research of cybersecurity policies, indicators, and protocols.
    • Designs technical solutions for network protection, endpoint security, access control, auditing, and log management. Uses technical expertise to resolve and identify issues through the analysis of technical problems.
    • Prevents network damage and restores computers and electronic communication systems.
    • Collaborates with the security community to obtain technical cyber threat intelligence. Researches emerging information security threats, vulnerabilities, and their countermeasures.
    • Leads the implementation of strategies for the detection and reporting of day-to-day security incidents.
    • Participates in the development of quality assurance policies.
    • QUALIFICATIONS :
    • Education Level :
    • Bachelor's Degree, Computer Science, Cyber Security, Information Technology, or related field OR in lieu of a Bachelor's degree, an additional 4 years of relevant work experience is required in addition to the required work experience.
    • Licenses / Certifications (Preferred)
    • CISSP - Certified Information Systems Security Professional
    • CISM - Certified Information Security Manager
    • CRISC - Certification in Risk and Information Systems Control
    • CISM - Certified Information Security Manager
    • CISA Certified Information Systems Auditor
    • SANS GIAC certifications in relevant security and risk areas
    • CASP - CompTIA Advanced Security Practitioner
    • CompTIA Security AWS Certifications
    • Experience :
    • 8 years related experience or cybersecurity certification and 5 years related experience.
    • cybersecurity certification and 5 years related experience.

    • Preferred Qualifications :
    • Advanced degree in IT or cybersecurity or equivalent experience.
    • Knowledge and work experience using several of the following frameworks / regulations : _

    • NIST Special Publication 800-53 Rev. 4 / 5 Security and Privacy Controls for Information Systems and Organizations
    • HIPAA Security and Privacy Final Rule (45 CFR Part 164)
    • NIST 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • HITRUST, FedRAMP
    • NIST CSF, NIST RMF, FedRAMP, HITRUST, CIS benchmarks, CIS Top 20, CSAs Cloud Controls Matrix (CCM), COBIT, CMMC, ISO 27001, FAIR
    • Various privacy frameworks : GDPR, CCPA, others
    • Knowledge of developing SSPs (system security plans) based on NIST 800-171, 800-53, and FedRAMP._

    • Experience with a wide variety of security tools such as IPS / IDS systems, firewalls, SIEM, web application firewalls, network and application vulnerability scanners (SAST, DAST, IAST), red / blue team exercises, EDR and XDR platforms, CSPM / CNAPP platforms, Amazon Web Services tools and technologies (Security Hub, Macie, Guard Duty, others), CASB platforms, PKI / HSMs, wireless technologies and platforms, NAC, secure email systems, network detection and response platforms, SOAR.
    • Experience in conducting and managing security and privacy risk assessments, audits, completing risk exception and acceptance requests.This work may be supervised by the Information Security Audit Manager.
    • Familiarity with SIG, SOC2 Type 2, and other security attestation documents to support vendor assessments and third-party risk management.
    • Skilled at working with a variety of stakeholders (internal and external to the organization) to assess cybersecurity strengths, weaknesses, and gaps in adherence to controls with the ability to develop solutions and documentation to address identified security coverage gaps with a proven ability to elicit, document, analyze, and verify requirements.
    • Disciplined and seasoned in change management practices.
    • Cyber security business and systems subject matter management expertise in Application Security, Data Security, Data Governance, and Network Security domains.
    • Experience with responding to internal and external audit requests, working with, and communicating to auditors and assessors, understanding the extent of appropriate evidence needed to satisfy audit and assessment requests.
    • Experience with working with enterprise or cybersecurity specific risk registers and analyzing risks to the organization on a cost / benefit basis.
    • Experience with GRC (Governance, Risk, and Compliance) systems or ITRM (Information Technology Risk Management) systems.
    • Excellent written skills to develop, review, and refine cybersecurity standards, SOPs, and policies with communication skills (verbal and written) to communicate to all levels of the organization.
    • Excellent interpersonal skills including the ability to build consensus and agreement and bring resolution to contentious issues and entrenched interests.
    • Proven experience supporting security risk teams and peer management with demonstrated business process, workflow, task analysis, and metrics / results measurement. Exposure to user-acceptance testing and requirements analysis knowledge desired.
    • Advanced written and verbal communication skills.
    • Excellent organizational, analytic, and problem-solving skills with the ability to set priorities and handle multiple projects concurrently with attention to detail.
    • Ability to anticipate security governance needs and take action before they become organizational problems.
    • Knowledge of AGILE and / or Waterfall SDLC methodologies.
    • Excellent knowledge of MS Office tool set MS Word, MS Excel, MS Project, and MS Visio.
    • Understanding of data analysis and modelling.
    • Knowledge of cloud security controls (AWS / Azure).
    • Experience with healthcare insurance industry, especially BCBS plans.
    • Knowledge, Skills, and Abilities (KSAs)
    • Ability to manage multiple tasks and deliverables with minimal supervision.
    • Ability to explain technical information to technical and nontechnical personnel.
    • Knowledge of cyber security related risk management techniques.
    • Knowledge of network architecture and firewall security.
    • Understanding of business needs and commitment to delivering high-quality, prompt, and efficient service.
    • Must be able to effectively work in a fast-paced environment with frequently changing priorities, deadlines, and workloads that can be variable for long periods of time. Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence. Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging.
    • Salary Range :
    • 107,136 - $212,784
    • Salary Range Disclaimer
    • The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the work is being performed. This compensation range is specific and considers factors such as (but not limited to) the scope and responsibilites of the position, the candidate's work experience, education / training, internal peer equity, and market and business consideration. It is not typical for an individual to be hired at the top of the range, as compensation decisions depend on each case's facts and circumstances, including but not limited to experience, internal equity, and location. In addition to your compensation, CareFirst offers a comprehensive benefits package, various incentive programs / plans, and 401k contribution programs / plans (all benefits / incentives are subject to eligibility requirements).

    • Department
    • Security Governance and Report

    • Equal Employment Opportunity
    • CareFirst BlueCross BlueShield is an Equal Opportunity (EEO) employer. It is the policy of the Company to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

    • Where To Apply
    • Please visit our website to apply : www.carefirst.com / careers

    • Federal Disc / Physical Demand
    • Note : The incumbent is required to immediately disclose any debarment, exclusion, or other event that makes him / her ineligible to perform work directly or indirectly on Federal health care programs.

    • PHYSICAL DEMANDS :
    • The associate is primarily seated while performing the duties of the position. Occasional walking or standing is required. The hands are regularly used to write, type, key and handle or feel small controls and objects. The associate must frequently talk and hear. Weights up to 25 pounds are occasionally lifted.

    • Sponsorship in US
    • Must be eligible to work in the U.S. without Sponsorship

      LI-RC1

      REQNUMBER : 20012

    Salary : $107,136 - $212,784

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Lead Cyber Security Analyst (Hybrid)?

    Sign up to receive alerts about other jobs on the Lead Cyber Security Analyst (Hybrid) career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $125,027 - $157,872
    Income Estimation: 
    $149,432 - $188,965
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $164,835 - $201,088
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at CareFirst BlueCross BlueShield

    CareFirst BlueCross BlueShield
    Hired Organization Address Baltimore, MD Full Time
    Resp & Qualifications PURPOSE: The role of the Proposal Development Specialist II is to develop and deliver on-time, hig...
    CareFirst BlueCross BlueShield
    Hired Organization Address Baltimore, MD Intern
    Resp & Qualifications CareFirsts Strategy & Growth division is accepting internship applications for our Summer 2025 pro...
    CareFirst BlueCross BlueShield
    Hired Organization Address Baltimore, MD Full Time
    Resp & Qualifications PURPOSE : Develops and implements security solutions. Administers security technology systems by a...
    CareFirst BlueCross BlueShield
    Hired Organization Address Baltimore, MD Full Time
    Resp & Qualifications PURPOSE: This position is a critical resource for large accounts within the Account Management Tea...

    Not the job you're looking for? Here are some other Lead Cyber Security Analyst (Hybrid) jobs in the Washington, DC area that may be a better fit.

    Cyber Security Analyst

    UltraViolet Cyber, Arlington, VA

    AI Assistant is available now!

    Feel free to start your new journey!