Sr Information Security Analyst (Cloud/Enterprise Security) - Hybrid (PA/NJ/DE)

Philadelphia, PA, US • Posted 30+ days ago • Updated 7 hours ago
Full Time
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Adaptability
  • UI
  • Expect
  • Collaboration
  • IT Management
  • Data Security
  • Process Improvement
  • Customer Experience
  • Security Operations
  • Log Analysis
  • International Relations
  • Investor Relations
  • Information Retrieval
  • Workflow
  • SAP GRC
  • Vendor Management
  • Documentation
  • Project Scoping
  • Cost Accounting
  • Cost-benefit Analysis
  • Stakeholder Engagement
  • Communication
  • Continuous Improvement
  • Innovation
  • Storage
  • Encryption
  • Security Controls
  • WAF
  • Auditing
  • Virtual Private Cloud
  • Cloud Computing
  • Operating Systems
  • Microsoft Windows Server
  • Microsoft Operating Systems
  • Hardening
  • Forensics
  • Electronic Discovery
  • Symantec
  • Palo Alto
  • Firewall
  • F5
  • SIEM
  • MDE
  • Data Lake
  • Qualys
  • OWASP
  • Testing
  • Available-to-promise
  • Multi-factor Authentication
  • DNS
  • Dragon NaturallySpeaking
  • Management
  • Network
  • Productivity
  • Microsoft Office
  • Microsoft Exchange
  • Microsoft SharePoint
  • Information Security
  • System Administration
  • Incident Management
  • System Monitoring
  • Risk Assessment
  • Privacy
  • Regulatory Compliance
  • Payment Card Industry
  • HIPAA
  • System On A Chip
  • Microsoft Windows
  • Linux
  • Unix
  • OS X
  • Vulnerability Assessment
  • Penetration Testing
  • Change Management
  • Project Management
  • Technical Writing
  • Presentations
  • IT Risk Management
  • IT Risk
  • Cisco Certifications
  • Cloud Security
  • Microsoft Azure
  • Amazon Web Services
  • Google Cloud
  • Google Cloud Platform
  • ISO/IEC 27001:2005
  • Jersey
  • Android
  • IOS Development
  • Microsoft

Summary

We are seeking a passionate, adaptable Information Security Analyst who will serve as a subject matter expert (SME) for business areas and technical teams, and act as the customer interface for the Information Security Operations function. You will strengthen our security posture by evaluating, testing, documenting, and operationalizing security solutions and controls across on?premises and cloud environments (Azure, AWS, Google Cloud Platform)-while enabling the business to innovate securely.

Continuous learning is a requirement to stay ahead of adversaries. This includes tracking modern attack techniques, and applying rigor to protect confidentiality, integrity, and availability of valued information assets. Expect close collaboration with audit/exam teams, technology management, and business stakeholders, plus meaningful contributions to incident preparedness and response.

Key Responsibilities:

Cloud & Enterprise Security (SME)
  • Serve as SME on security fundamentals, techniques, and technologies across Azure, AWS, Google Cloud Platform, and on?prem environments.
  • Guide cloud security architecture: IAM, encryption/key management, network controls, data protection, workload hardening.
  • Implement process improvements aligned to security frameworks (NIST CSF/800?53, ISO 27001) and business needs; optimize technology to improve customer experience.

Security Operations & Incident Response
  • Implement and monitor controls for unusual and suspicious activity across endpoints, networks, and cloud platforms.
  • Perform advanced monitoring, data/log analysis, threat hunting, and forensic investigations; contribute to SOC/IR workflows.
  • Plan, contribute to, and participate in incident plan exercises and tabletop scenarios.

Governance, Risk & Compliance (GRC)
  • Draft or revise local policies, standards, guidelines, and procedures to supplement enterprise frameworks; identify and remediate gaps based upon NIST standards.
  • Interface with internal/external auditors and examiners; maintain vendor management standards, questionnaires, and regulatory documentation (HITRUST, PCI, NIST, HIPAA, SOC2).
  • Review contracts and provide security guidance; support project scoping, costing, and cost-benefit analyses.

Stakeholder Engagement & Communication
  • Act as a liaison for the security team; clearly communicate business risk as it relates to information security.
  • Create technical documentation (reports, white papers, technical notes, implementation/configuration guides).
  • Use visual aids to convey complex topics to large, diverse audiences; communicate clearly in high?pressure, high?visibility situations.

Continuous Improvement
  • Recommend new security solutions and improvements that do not impede innovation.
  • Stay current with the evolving threat landscape; consistently learn and grow to remain a step ahead of attackers.

Technical Expertise

Cloud Security (Azure, AWS, Google Cloud Platform)
  • Azure: Defender for Cloud, Microsoft Sentinel, Entra ID (Azure AD), Conditional Access, Key Vault, NSGs/Azure Firewall, storage encryption, Defender for Endpoint integration.
  • AWS: IAM roles/policies, Security Hub, GuardDuty, KMS, CloudTrail/CloudWatch, VPC security controls, AWS WAF, Secrets Manager.
  • Google Cloud Platform: IAM, Security Command Center, Cloud Audit Logs, VPC Service Controls, CMEK/KMS, Cloud Armor, Workload Identity; container security (GKE).

Additional Technologies
  • Operating Systems: Linux, Windows Server, Windows Desktop; hardening, patching, CIS Benchmarks.
  • Forensics & eDiscovery: Symantec, Purview, Proofpoint; email/file discovery; incident response.
  • Network & Perimeter: Palo Alto firewalls, URL filtering, DNS blackhole/geo?filtering, WildFire; F5 AWAF.
  • SIEM & Logging: MS Sentinel, MDE, Elastic; Endpoint management/log forwarding. Microsoft Data Lake, CRIBL
  • Vulnerability & AppSec: Qualys, NexusIQ; OWASP?aligned testing and remediation.
  • Endpoint: Microsoft Defender, Microsoft ATP/Defender for Endpoint.
  • Identity & MFA: Okta, Microsoft (Entra ID MFA).
  • Core Services: DNS zone management; network micro?segmentation; zero trust?aligned controls.
  • Secure Productivity: Securing Microsoft 365 (Exchange Online, SharePoint/OneDrive, Teams, Purview).

Qualifications:

Required
  • 5-8 years of relevant information security experience (or 3-5 years in IT systems administration with strong security responsibilities).
  • Expertise in incident response, system monitoring/analysis, and risk assessments aligned with compliance and privacy laws.
  • Knowledge with compliance requirements: HITRUST, PCI, NIST, HIPAA, SOC2.
  • Knowledge across multiple platforms: Windows, Linux/Unix, macOS; networks and endpoints.
  • Experience with vulnerability assessment and penetration testing engagements.
  • Experience with change management and project management.
  • Excellent technical writing and presentation skills; ability to translate technical risk to business impact.

Preferred
  • CCSP preferred; other certs: AZ?500, AWS Security Specialty, Google Cloud Platform Professional Cloud Security Engineer.
  • Experience securing Azure, AWS, Google Cloud Platform in enterprise/hybrid environments.
  • Familiarity with NIST CSF, ISO 27001, CIS Benchmarks, MITRE ATT&CK.


Hybrid

Independence has implemented a "Hybrid" model which consists of Associates working in the office 3 days a week (Tuesday, Wednesday & Thursday) and remotely 2 days a week (Monday & Friday). This role is designated as a role that fits into the "Hybrid" model. While associates may work remotely on our designated remote days, the work must be performed in the Tri-State Area of Delaware, New Jersey or Pennsylvania.

IBX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to their age, race, color, religion, sex, national origin, sexual orientation, protected veteran status, or disability.

Must have an Android or iOS device which is compatible with the free Microsoft Authenticator app.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: ibxpa
  • Position Id: 260054-1
  • Posted 30+ days ago

Company Info

About Independence Blue Cross, LLC

Serving more than 8 million people nationwide and nearly 2.5 million in the region, Independence Health Group is the leading health insurance company in the Philadelphia region, and we re expanding across the country. Our mission to build healthier lives for you, your family, and your employees shapes our actions and decisions every day.


Careers
About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Philadelphia, Pennsylvania

Today

Full-time

Depends on Experience

Philadelphia, Pennsylvania

Today

Full-time

Depends on Experience

No location provided

Today

Full-time

Depends on Experience

Philadelphia, Pennsylvania

Today

Full-time

Depends on Experience

Search all similar jobs