Director I - Cybersecurity Operations & Incident Response

Elevance Health

Indianapolis (IN)

Hybrid

USD 180,000 - 240,000

Full time

11 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Elevance Health is seeking a Director I for Cybersecurity Operations & Incident Response to lead enterprise monitoring, incident response, and investigations across the organization.

You will manage the 24x7 SOC/CSIRT, coordinate with stakeholders, and drive continuous improvement of security operations, governance, and risk controls in a hybrid work model.

Qualifications

  • BA/BS in Information Technology or related field and a minimum of 7 years IT management experience (or equivalent).
  • Experience leading enterprise Security Operations Center and Cyber Security Incident Response teams.
  • Strong knowledge of HIPAA, HITRUST, PCI DSS, NIST CSF, SOX, SEC cyber requirements.

Responsibilities

  • Lead the 24x7 SOC and CSIRT operations for enterprise cybersecurity monitoring and incident response.
  • Coordinate with Legal, Privacy, Compliance, HR, and technology teams during investigations.
  • Provide senior executive briefings on incidents, scope, impact, and recommended actions.
  • Oversee SIEM-based monitoring, alert triage, cloud security monitoring, and digital forensics.
  • Develop AI-enabled cybersecurity workflows with governance and risk controls.
  • Manage staffing, escalation paths, and communications during major incidents.
  • Support regulatory and audit activities with evidence of controls and methodologies.
  • Develop strategic recommendations and operational reporting for leadership.

Skills

Security leadership
Incident response
SOC operations
Regulatory compliance
Cross-functional collaboration

Education

BA/BS in IT or related field

Tools

SIEM platforms
Digital forensics tools

Job description

Director I - Cybersecurity Operations & Incident Response

This role requires associates to be in-office 3 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.

Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.

The Director, Cybersecurity Operations & Incident Response is responsible for leading enterprise cybersecurity monitoring, security incident response, and investigative operations across Elevance Health. This role leads the 24x7 Security Operations Center (SOC) and Cyber Security Incident Response Team (CSIRT), ensuring security events and incidents are rapidly identified, investigated, contained, remediated, and communicated. This Director is accountable for operational excellence across a follow-the-sun SOC model, effective execution of the cyber incident response lifecycle, development of highly capable cybersecurity professionals, and continuous improvement of security operations processes and capabilities.

How you will make an impact
  • Interfaces with key Information Technology (IT) solution teams and vendors. Lead and coordinate cybersecurity incident response activities with Legal, Privacy, Compliance, Human Resources, Corporate Security, technology teams, and other business stakeholders as required.
  • Support engagement with external parties, including law enforcement, regulatory authorities, cyber insurance providers, external counsel, and other third parties during significant cybersecurity investigations and incidents.
  • Provide timely and accurate briefings to the CISO and senior leadership regarding high-profile cybersecurity incidents, including incident scope, business impact, response status, key decisions, risks, and recommended actions.
  • Oversee enterprise security monitoring and investigation capabilities, including SIEM-based monitoring, security alert triage, cloud security monitoring, identity-related investigations, malware analysis, digital forensics, threat intelligence consumption, and other security operations functions within the team's scope.
  • Provide operational input into the design and adoption of AI-enabled cybersecurity workflows, ensuring solutions enhance analyst effectiveness while maintaining appropriate governance, human oversight, accuracy, and risk controls.
  • Manage operational readiness for major cybersecurity events, including surge staffing, escalation paths, communications, technical coordination, and transition between normal security operations and formal incident response activities.
  • Support regulatory, audit, and compliance activities by providing evidence of security monitoring and incident response controls and ensuring alignment with applicable frameworks and requirements, including HIPAA, HITRUST, PCI DSS, NIST Cybersecurity Framework, SOX, SEC cybersecurity requirements, and applicable breach notification obligations.
  • Develop business-level presentations, operational reporting, incident briefings, and strategic recommendations that enable senior leadership to understand cybersecurity risk, operational performance, capability gaps, and investment priorities.
  • Hires, trains, coaches, counsels, and evaluate performance of direct reports.
Minimum Requirements

Requires an BA/BS degree in Information Technology, Computer Science or related field of study and a minimum of 7 years of IT management experience; or any combination of education and experience, which would provide an equivalent background.

Preferred Skills, Capabilities and Experiences
  • Demonstrated experience leading enterprise Security Operations Center, Cyber Security Incident Response, or comparable cybersecurity operations functions is preferred.
  • Extensive experience managing cybersecurity incidents across the incident response lifecycle, including identification, triage, investigation, containment, eradication, recovery, evidence preservation, and post-incident review is preferred.
  • Cybersecurity certifications such as CISSP, CISM, GCIH, GCFA, GCIA, or comparable industry certifications are strongly preferred.
  • Demonstrated record of building high-performing security operations teams and improving operational maturity, investigation quality, analyst effectiveness, and incident response outcomes is preferred.
  • Prior experience leading a 24x7 enterprise Security Operations Center and Cyber Security Incident Response Team is strongly preferred.
  • Strong working knowledge of healthcare and cybersecurity regulatory and compliance requirements, including HIPAA, HITRUST, PCI DSS, NIST Cybersecurity Framework, SOX, SEC cybersecurity requirements, and state or federal breach notification requirements is strongly preferred.

Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.

Who We Are

Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.

How We Work

At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.

We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.

Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact elevancehealthjobssupport@elevancehealth.comfor assistance. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director I - Cybersecurity Operations & Incident Response
Director I - Cybersecurity Operations & Incident Response

The Elevance Health Companies, Inc. • Indianapolis (IN)

Hybrid
USD 160,000 - 230,000
Medical, dental, vision
401(k) + match
Stock purchase plan
+2
Information Security Advisor - Detection Engineer
Information Security Advisor - Detection Engineer

Elevance Health • Indianapolis (IN)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Competitive benefits
Information Security Advisor
Information Security Advisor

Elevance Health • Indianapolis (IN)

Hybrid
USD 110,000 - 170,000
Data Scientist
Data Scientist

Elevance Health • Indianapolis (IN)

Hybrid
USD 115,000 - 170,000
Merit increases
Paid holidays
Paid Time Off
+11
Principal Cloud Security Architect
Principal Cloud Security Architect

Elevance Health • Grand Prairie (TX)

Hybrid
USD 180,000 - 280,000
Hybrid work model
Cloud & AI Security Architect
Cloud & AI Security Architect

Elevance Health • Indianapolis (IN)

On-site
USD 140,000 - 190,000
Hybrid work model
Competitive benefits
Cybersecurity ServiceNow Application Senior Advisor
Cybersecurity ServiceNow Application Senior Advisor

Elevance Health • Atlanta (GA)

On-site
USD 120,000 - 180,000
Hybrid work model
Wellness programs
401(k) + match
Infrastructure Architect Executive
Infrastructure Architect Executive

Elevance Health • Atlanta (GA)

Hybrid
USD 140,000 - 190,000
401(k) match
Stock purchase plan
Wellness programs
+1
Principal Cloud Security Architect
Principal Cloud Security Architect

Elevance Health • Town of Florida (NY)

Hybrid
USD 180,000 - 240,000
Information Security Advisor - Data Protection
Information Security Advisor - Data Protection

The Elevance Health Companies, Inc. • Indianapolis (IN)

Hybrid
USD 120,000 - 170,000
Medical, dental, vision insurance
401(k) + match
Stock purchase plan
+2