Talent.com
Threat & Vulnerab Analyst II
Threat & Vulnerab Analyst IIHorizon Blue Cross Blue Shield of New Jersey • Newark, NJ, United States
No longer accepting applications
Threat & Vulnerab Analyst II

Threat & Vulnerab Analyst II

Horizon Blue Cross Blue Shield of New Jersey • Newark, NJ, United States
30+ days ago
Job type
  • Full-time
Job description

Horizon Blue Cross Blue Shield of New Jersey empowers our members to achieve their best health. For over 90 years, we have been New Jersey's health solutions leader driving innovations that improve health care quality, affordability, and member experience. Our members are our neighbors, our friends, and our families. It is this understanding that drives us to better serve and care for the 3.5 million people who place their trust in us. We pride ourselves on our best-in-class employees and strive to maintain an innovative and inclusive environment that allows them to thrive. When our employees bring their best and succeed, the Company succeeds.

The Threat and Vulnerability Analyst works with the Information Technology Division to develop and modify processes that identify and remediate vulnerabilities in Horizons technical environment. The TVM Analyst II is actively scanning the Enterprise environment both internally and externally, create standards, and handle false positives and exceptions. In addition, the TVM Analyst will work to create long term solutions to potential threats to our environment. The incumbent will stay current on industry standards, evaluating trends, and reporting back to senior management regarding activity that needs resolution.

Responsibilities :

  • Develop and enhance scanning strategies to ensure complete coverage of Horizons entire networked environment.
  • Partner with senior leaders within the IT Division to categorize vulnerabilities based on severity and risk for exploitation, and to categorize assets by criticality.
  • Partner with the IT Division to establish SLAs for the remediation of vulnerabilities based on the severity of the vulnerability and the criticality of the asset.
  • Partner with the IT Division to track vulnerability remediation.
  • Collaborate with IT leadership regarding false positive determination and exceptions processes
  • Converse with Senior Management at all levels as to the current state of risk posed by vulnerabilities in the Horizon environment and the proposed remediation of those vulnerabilities..
  • Create, maintain and present weekly and monthly metrics, to various audiences.
  • Create and modify processes / procedures as needed, such as those supporting vulnerability remediation and the processing of threat intelligence.
  • Ensure appropriate controls are being executed and policies / standards are enforced to satisfy Audit requirements.
  • Assist in building a threat hunting program by developing and documenting threat and response scenarios and use cases

Education / Experience :

  • High School Diploma / GED required
  • Bachelor degree preferred or relevant experience in lieu of degree
  • Minimum 5 years IT Security experience (3yrs of the 5 detecting and remediating vulnerabilities)
  • Additional licensing, certifications, registrations :

  • Requires one or more industry certifications : CISSP, GCTI or similar industry certification
  • Knowledge :

  • Knowledge of how to employ various security methodologies (Cyber-Kill-Chain, Defense-in-Depth, etc) in a security program.
  • Knowledge of Patch Management and Vulnerability Management, and the difference in processes needed to remediate vulnerabilities
  • A deep understanding of IOCs, threat hunting, and APTs, cyber-crime and associated tools, tactics and procedures
  • Excellent knowledge of IT and computer systems.
  • Experience working with operating systems (Windows,
  • Nix, and Mac)
  • Experience working with a vulnerability scanning application (Nexpose, Nessus, Qualys).
  • Skills and Abilities :

    Experience working with IT teams to prioritize both vulnerabilities and systems so that the most critical vulnerabilities are removed from the most critical systems in a short time span, including :

  • Identifying the most critical systems
  • Classifying vulnerabilities by CVSS score
  • Experience preparing & presenting metrics to all levels in an organization, including :
  • The use of various visualization techniques, and understanding where / when appropriate
  • The appropriate level of detail for the intended audience
  • The use of tools , such as MS-PowerPoint, Visio, etc
  • Experience in developing and modifying security policies, standards and processes
  • Defining the need for a new / changed process
  • Documenting the process flow using a tool such as Visio
  • Working with other teams to implement
  • Establishing SLAs to determine effectiveness.
  • Experience identifying system vulnerabilities and working with appropriate teams to remediate them.
  • Experience defining Operating System Baseline Configuration standards, including :
  • Mapping to standards such as the Center for Internet Security (CIS) Critical Security Controls
  • Scanning, and working with appropriate teams to remediate.
  • Experience working with Internal and External Auditors to ensure that documented controls / policies / and standards are being adhered to
  • Experience utilizing various threat intelligence collection and reporting applications and sources such as ThreatStream, NH-ISAC, NJCCIC
  • Experience negotiating with teams regarding operational processes and procedures, including false positives, remediation exceptions, SLA extensions, etc.
  • Ability to work in a large corporate environment as well as some experience analyzing emerging threats and emerging risks is important.
  • Requires exceptional analytical thinking skills or analytical and problem solving skills
  • Requires excellent verbal and written communication skills
  • Requires excellent interpersonal skills and the ability to work effectively with others as a team
  • Requires excellent PC skills and demonstrated proficiency with MS Office Suite
  • Requires the ability to handle multiple tasks and prioritize effectively
  • Detail oriented and excellent organizational, time and stress management skills
  • Ability to work well individually as well as in a team environment
  • Self-starter with demonstrated ability to make decisions as necessary, escalating when appropriate, and ensuring that there is communication to all teams
  • Horizon BCBSNJ employees must live in New Jersey, New York, Pennsylvania, Connecticut or Delaware

    Salary Range : $96,300 - $131,565

    This compensation range is specific to the job level and takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to : education, experience, licensure, certifications, geographic location, and internal equity. This range has been created in good faith based on information known to Horizon at the time of posting. Compensation decisions are dependent on the circumstances of each case. Horizon also provides a comprehensive compensation and benefits package which includes :

    Comprehensive health benefits (Medical / Dental / Vision)

    Retirement Plans

    Generous PTO

    Incentive Plans

    Wellness Programs

    Paid Volunteer Time Off

    Tuition Reimbursement

    Disclaimer :

    This job summary has been designed to indicate the general nature and level of work performed by colleagues within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of colleagues assigned to this job.

    Horizon Blue Cross Blue Shield of New Jersey is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, protected veteran status or status as an individual with a disability and any other protected class as required by federal, state or local law. Horizon will consider reasonable accommodation requests as part of the recruiting and hiring process.

    Create a job alert for this search

    Threat Analyst • Newark, NJ, United States

    Related jobs
    Cyber Threat Detection and Hunting, AVP

    Cyber Threat Detection and Hunting, AVP

    MUFG Bank, Ltd. • Jersey City, NJ, United States
    Full-time
    Do you want your voice heard and your actions to count?.Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150...Show more
    Last updated: 3 hours ago • Promoted • New!
    Forensic Engineer

    Forensic Engineer

    The Vertex Companies, LLC • Branchburg, NJ, US
    Part-time
    The Vertex Companies, LLC (VERTEX) is a global $150M professional services firm that offers integrated forensic consulting, expert witness services, construction project advisory, and compliance an...Show more
    Last updated: 1 day ago
    Director - Cybersecurity & Network Security Vendor Lead

    Director - Cybersecurity & Network Security Vendor Lead

    Climb Global Solutions • Eatontown, NJ, US
    Full-time
    The Cybersecurity Vendor Director will lead Climb’s North American cybersecurity and network security business unit for a leading global vendor, driving significant revenue growth within the ...Show more
    Last updated: 1 day ago • Promoted
    Asset Protection Specialist

    Asset Protection Specialist

    Home Depot (Retail) • Bound Brook, NJ, US
    Full-time
    The Asset Protection Specialist is primarily responsible for preventing financial loss caused by theft and fraud and supporting safety and environmental program compliance in their assigned store / m...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer, Insider Threat Detection & Response

    Security Engineer, Insider Threat Detection & Response

    OpenAI • New York, NY, United States
    Full-time
    Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products.We are...Show more
    Last updated: 1 hour ago • Promoted • New!
    Cyber Warfare Technician

    Cyber Warfare Technician

    US Navy • Newark, NJ, US
    Full-time +1
    Languages are more than just communication-they're cultural codes that need to be analyzed and in some cases, broken.As a Cryptologic Technician Interpretive (CTI) you're more than a linguist-you'r...Show more
    Last updated: 6 hours ago • Promoted • New!
    Sr. Information Security Governance Analyst- Bridgewater, NJ or Morrisville, NC (Hybrid)

    Sr. Information Security Governance Analyst- Bridgewater, NJ or Morrisville, NC (Hybrid)

    Syneos Health / inVentiv Health Commercial LLC • Bridgewater, NJ, United States
    Full-time
    Information Security Governance Analyst- Bridgewater, NJ or Morrisville, NC (Hybrid).Syneos Health is a leading fully integrated biopharmaceutical solutions organization built to accelerate custome...Show more
    Last updated: 18 days ago • Promoted
    Command Center Analyst

    Command Center Analyst

    Insight Global • Clifton, NJ, United States
    Temporary
    Duration : 6 month contract (potential extensions, potential hire).Shift : Wed / Thurs‑Sat, 7am – 7pm.Day‑to‑day monitoring of network and infrastructure operations. Provide customer service and trouble...Show more
    Last updated: 28 days ago • Promoted
    Junior Analyst

    Junior Analyst

    LaunchPointPEO • New York, NY, US
    Full-time
    Old Dominion Strategies (ODS) is a professional services firm supporting the U.Department of Homeland Security and its components through mission-focused program management, administrative, and tec...Show more
    Last updated: 17 hours ago • Promoted • New!
    Information Security Analyst

    Information Security Analyst

    Spectraforce Technologies • Newark, NJ, United States
    Full-time
    Job Title : Information Security Analyst.Location : Newark, NJ (Hybrid 3 days onsite).Focus on highest risk controls first, then medium risk (definition in progress). Coordination with AppOwners and c...Show more
    Last updated: 28 days ago • Promoted
    Senior HUMINT Analyst

    Senior HUMINT Analyst

    Core One • Fort Lee, NJ, United States
    Full-time
    Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges.Core One value...Show more
    Last updated: 1 day ago • Promoted
    Sr. Risk Analyst - Cyber

    Sr. Risk Analyst - Cyber

    Munich RE • Princeton, NJ, United States
    Full-time
    Amelia, United States; Hartford, United States; Princeton, United States;.Hiring Manager : Warren Meilicke.Hybrid position and will be require to be in office 40-50% (Cincinnati, OH, Princeton, NJ, ...Show more
    Last updated: 14 days ago • Promoted
    Epic Lumens Analyst

    Epic Lumens Analyst

    TEKsystems • Newark, NJ, United States
    Full-time
    Must be certified in Epic Lumens •.Must have prior Epic implementation experience •.Our client is going live with Epic in 3 waves. They are looking for consultants that can help with Command Center su...Show more
    Last updated: 3 days ago • Promoted
    Cyber Threat Detection and Hunting, AVP

    Cyber Threat Detection and Hunting, AVP

    MUFG • Jersey City, NJ, United States
    Full-time
    Do you want your voice heard and your actions to count?.Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150...Show more
    Last updated: 1 day ago • Promoted
    Information Security Analyst

    Information Security Analyst

    TradeJobsWorkForce • 10710 Yonkers, NY, US
    Full-time
    Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...Show more
    Last updated: 30+ days ago • Promoted
    Analytical Scientist

    Analytical Scientist

    Astrix • Middlesex County, NJ, US
    Full-time
    We are seeking an Analytical Scientist to join a reputable pharmaceutical manufacturing company to conduct routine and non-routine analyses of in-process materials, raw materials, environmental sam...Show more
    Last updated: 30+ days ago • Promoted
    SOC Analyst

    SOC Analyst

    Gulf Coast Automation Group • New York, New York, United States
    Remote
    Full-time
    Quick Apply
    Security Operations Center (SOC) Analyst (NYC, BOS, ATL).Remote (Must Reside in ATL, BOS, NYC).Full-Time, 2nd Shift (3 : 00 PM 12 : 00 AM ET, Monday Friday). TalentFish is casting a line for a.Security ...Show more
    Last updated: 16 days ago
    Senior Cyber Security Incident Response Analyst

    Senior Cyber Security Incident Response Analyst

    FIS • New York, NY, United States
    Full-time
    Experienced (relevant combo of work and education).Our technology powers the world’s economy and our teams bring innovation to life. We champion diversity to deliver the best products and solutions ...Show more
    Last updated: 30+ days ago • Promoted