Horizon Blue Cross Blue Shield of New Jersey logo
Horizon Blue Cross Blue Shield of New JerseyPosted 3 weeks ago

Cybersecurity Threat & Vulnerability Analyst

$97,800–$133,455 year

RemoteNewark, New Jersey, United States

Full TimeLarge

Job Summary

Develop and enhance vulnerability scanning strategies to ensure comprehensive coverage across Horizon's enterprise environment. Conduct internal and external vulnerability assessments, validate scan results, and apply established standards to classify findings based on severity and business risk. Partner with EBTS teams to develop remediation plans, track activities, and ensure timely resolution while communicating risk exposure and recommendations to senior leadership. Create executive reports, maintain security policies, and assist in maturing threat hunting programs by documenting scenarios and response playbooks.

Required Qualifications

  • High School Diploma or GED
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field
  • Relevant experience in lieu of a degree
  • Minimum of five (5) years of Information Security experience
  • At least three (3) years of experience focused on vulnerability identification, assessment, and remediation
  • One or more of the following certifications: CISSP (Certified Information Systems Security Professional), GCTI (GIAC Cyber Threat Intelligence), GIAC certifications, CompTIA Security+, Certified Ethical Hacker (CEH)
  • Strong understanding of cybersecurity frameworks and methodologies, including Cyber Kill Chain, Defense-in-Depth, and related security models
  • Comprehensive knowledge of vulnerability management and patch management processes and their respective remediation approaches
  • Deep understanding of indicators of compromise (IOCs), advanced persistent threats (APTs), cybercrime techniques, and attacker tactics, techniques, and procedures (TTPs)
  • Knowledge of operating systems including Windows, Linux/Unix, and macOS
  • Experience with vulnerability management platforms such as Nessus, Qualys, InsightVM (Nexpose), or similar solutions
  • Knowledge of Center for Internet Security (CIS) benchmarks and Critical Security Controls
  • Understanding of audit, regulatory, and compliance requirements related to cybersecurity programs
  • Proven ability to prioritize vulnerabilities and systems based on risk, asset criticality, and business impact
  • Experience utilizing CVSS scoring and risk-based vulnerability management methodologies
  • Demonstrated attention to detail and commitment to operational excellence
  • Self-motivated and capable of working independently while maintaining effective communication with stakeholders
  • Strong interpersonal skills with the ability to build partnerships and influence outcomes across the organization
  • Horizon Blue Cross Blue Shield of New Jersey employees must live in New Jersey, New York, Pennsylvania, Connecticut or Delaware

Desired Qualifications

  • Experience working within a large enterprise environment
  • Experience supporting security audits, regulatory compliance reviews, and risk management programs
  • Experience creating executive-level dashboards, scorecards, and presentations using tools such as Microsoft PowerPoint, Visio, and Excel
  • Experience developing and documenting security processes, standards, and procedures
  • Ability to facilitate cross-functional collaboration and drive vulnerability remediation efforts across multiple teams
  • Experience negotiating remediation plans, exception requests, SLA extensions, and false-positive determinations
  • Strong project management, organizational, and time-management skills
  • Ability to manage multiple priorities in a fast-paced environment
  • Strong analytical, investigative, and problem-solving skills
  • Excellent verbal and written communication skills, including the ability to present technical information to both technical and non-technical audiences
  • Experience with threat intelligence platforms and sources such as Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, and similar resources
  • Experience in a fast-paced environment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce