Director I – Cybersecurity Operations, Incident Response

Jobtailor

Kentucky

On-site

USD 150,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Elevance Health is seeking a Lead for enterprise cybersecurity monitoring, incident response, and investigative operations. You will head the 24x7 SOC and CSIRT, ensure rapid identification, containment, and remediation of incidents, and interface with IT solution teams and vendors.

You will drive continuous improvement of security operations processes, supervise staff, coordinate with Legal, Privacy, Compliance, HR, and executives, and report to the CISO with actionable recommendations.

Qualifications

  • 7+ years of IT security/management experience.
  • Experience leading enterprise SOC/CSIRT functions.
  • Familiar with HIPAA, HITRUST, PCI DSS, NIST CSF, SOX and SEC cybersecurity requirements.
  • CISSP, CISM, GCIH, GCFA, GCIA certifications preferred.

Responsibilities

  • Lead the 24x7 SOC and CSIRT operations and incident response lifecycle.
  • Coordinate incident response activities with Legal, Privacy, Compliance, HR, and other stakeholders.
  • Brief the CISO and senior leadership on high-profile cybersecurity incidents.
  • Drive operational excellence and readiness for major cybersecurity events.

Skills

Cybersecurity Incident Response
SOC Leadership
Healthcare Regulatory Compliance
Incident Response Lifecycle
Threat Intelligence
Digital Forensics

Education

BA/BS in Information Technology or Computer Science

Tools

SIEM
Cloud Security Monitoring

Job description

Lead enterprise cybersecurity monitoring, security incident response, and investigative operations across Elevance Health
Lead the 24x7 Security Operations Center and Cyber Security Incident Response Team
Ensure security events and incidents are identified, investigated, contained, remediated, and communicated rapidly
Drive operational excellence across a follow-the-sun SOC model
Lead execution of the cyber incident response lifecycle
Develop cybersecurity professionals and continuously improve security operations processes and capabilities
Interface with IT solution teams and vendors
Coordinate incident response activities with Legal, Privacy, Compliance, Human Resources, Corporate Security, technology teams, and other stakeholders
Support engagement with law enforcement, regulatory authorities, cyber insurance providers, external counsel, and other third parties
Brief the CISO and senior leadership on high-profile cybersecurity incidents
Oversee SIEM-based monitoring, security alert triage, cloud security monitoring, identity-related investigations, malware analysis, digital forensics, threat intelligence consumption, and related security operations
Provide operational input into AI-enabled cybersecurity workflows with appropriate governance, human oversight, accuracy, and risk controls
Manage operational readiness for major cybersecurity events, including surge staffing, escalation paths, communications, technical coordination, and transitions to formal incident response
Support regulatory, audit, and compliance activities by providing security monitoring and incident response evidence
Develop business-level presentations, operational reporting, incident briefings, and strategic recommendations
Hire, train, coach, counsel, and evaluate direct reports

Requirements
  • BA/BS degree in Information Technology, Computer Science or related field of study
  • Minimum of 7 years of IT management experience
  • Any combination of education and experience providing an equivalent background
  • Demonstrated experience leading enterprise Security Operations Center, Cyber Security Incident Response, or comparable cybersecurity operations functions is preferred
  • Extensive experience managing cybersecurity incidents across the incident response lifecycle is preferred
  • Cybersecurity certifications such as CISSP, CISM, GCIH, GCFA, GCIA, or comparable industry certifications are strongly preferred
  • Demonstrated record of building high-performing security operations teams and improving operational maturity, investigation quality, analyst effectiveness, and incident response outcomes is preferred
  • Prior experience leading a 24x7 enterprise Security Operations Center and Cyber Security Incident Response Team is strongly preferred
  • Strong working knowledge of healthcare and cybersecurity regulatory and compliance requirements, including HIPAA, HITRUST, PCI DSS, NIST Cybersecurity Framework, SOX, SEC cybersecurity requirements, and state or federal breach notification requirements is strongly preferred
  • Must be within a reasonable commuting distance from the posting location(s), unless an accommodation is granted as required by law
Core Competencies

Demonstrates expertise in leading cybersecurity operations, including incident response and security monitoring, while ensuring compliance with healthcare regulations. Proven ability to develop and manage high-performing teams and improve operational maturity in cybersecurity practices.

Highest-signal resume keywords
  • Cybersecurity Incident Response
  • Security Operations Center Leadership
  • Cybersecurity Certifications (CISSP, CISM, GCIH, GCFA, GCIA)
  • Healthcare Regulatory Compliance (HIPAA, HITRUST, PCI DSS)
  • Operational Excellence in Cybersecurity
Hard Skills
  • Incident Response Lifecycle Management
  • SIEM-Based Monitoring
  • Malware Analysis
  • Digital Forensics
  • Threat Intelligence Consumption
  • Cloud Security Monitoring
  • Security Alert Triage
  • Identity-Related Investigations
  • Operational Readiness Management
  • Cybersecurity Process Improvement
Soft Skills
  • Team Building
  • Coaching and Mentoring
  • Communication with Senior Leadership
  • Collaboration with Stakeholders
  • Presentation Development
Certifications & Qualifications
  • CISSP
  • CISM
  • GCIH
  • GCFA
  • GCIA
Industry Keywords
  • Cybersecurity
  • Healthcare Compliance
  • NIST Cybersecurity Framework
  • SOX
  • SEC Cybersecurity Requirements
  • Breach Notification Requirements
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager – Cybersecurity Fusion Center
Manager – Cybersecurity Fusion Center

Jobtailor • West Valley City (UT)

On-site
USD 190,000 - 240,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

Jobtailor • Dearborn (MO)

On-site
USD 140,000 - 190,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Director I - Cybersecurity Operations & Incident Response
Director I - Cybersecurity Operations & Incident Response

The Elevance Health Companies, Inc. • Indianapolis (IN)

Hybrid
USD 160,000 - 230,000
Medical, dental, vision
401(k) + match
Stock purchase plan
+2
Executive Director Cybersecurity
Executive Director Cybersecurity

The Security Executive Council • Miami (FL)

On-site
USD 100,000 - 130,000
Competitive salary
Health insurance
Professional development opportunities
Cybersecurity Operations Director
Cybersecurity Operations Director

Pearl Companies • United States

Remote
USD 130,000 - 160,000
Manager, Cybersecurity
Manager, Cybersecurity

Central Ohio Primary Care Physicians, Inc. • Westerville (OH), Northern (KY)

Hybrid
USD 140,000 - 170,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1