Centene Corporation Logo

Centene Corporation

Lead Incident Response Analyst

Posted 8 Days Ago
Be an Early Applicant
Remote
11 Locations
Senior level
Remote
11 Locations
Senior level
The Lead Incident Response Analyst investigates cybersecurity incidents, enhances security measures, and identifies attack patterns. This role focuses on Cloud security, requiring expertise in analyzing events, incident scoping, mitigation, and conducting post-mortem analyses. The analyst collaborates with teams, ensures compliance, and delivers presentations to leadership.
The summary above was generated by AI

You could be the one who changes everything for our 28 million members by using technology to improve health outcomes around the world.  As a diversified, national organization, Centene's technology professionals have access to competitive benefits including a fresh perspective on workplace flexibility.
 

Position Purpose:

Investigates cybersecurity incidents, recommending enhancements to improve security, identifying common attack patterns to publicly exposed aspects of the organization's environment, and contributing to the implementation of scalable and preventative security measures. This role has a primary focus on Cloud-based security investigations. The ideal candidate is expert in analyzing Cloud security events, is able to consistently investigate to identify root cause, can accurately scope an incident, and can identify and initiate mitigation and containment procedures.

  • Partners with business units to accomplish enterprise-wide remediation and develops and delivers presentations to senior leadership team.
  • Implements current configurations of Centene’s production information systems and networks against compliance standards.
  • Keeps abreast of security breaches and ensure incident and response management processes are initiated.
  • Implements security service audit schedules, review access authorization, and perform the required access controls testing to identify security shortfalls.
  • Designs of automated scripts, contingency plans, and other programmed responses which are launched when an attack against Centene’s systems has been detected.
  • Collaborates with Information Security Architects, Information Security Engineers, and software or hardware stakeholders at Centene.
  • Notifies internal and/or external teams according to agreed alert priority levels, escalation trees, triaging of security alerts, events, and notifications.
  • Ties third party attack monitoring services and threat reporting services, into internal CIRT (Cyber Incident Response Team) communications systems.
  • Performs post-mortem analysis with logs, network traffic flows, and other recorded information to identify intrusions by unauthorized parties, as well as unauthorized activities of authorized users.
  • Performs other duties as assigned.
  • Complies with all policies and standards.

Education/Experience:

A Bachelor's degree in a quantitative or business field (e.g., statistics, mathematics, engineering, computer science).
Requires 5 – 7 years of related experience.
Or equivalent experience acquired through accomplishments of applicable knowledge, duties, scope and skill reflective of the level of this position.
Technical Skills:

  • 3+ years of cloud IR experience is preferred
  • Strong understanding of Cloud infrastructure (AWS & Azure)
  • Understanding of the Cloud attack surface
  • Understanding of Cloud mitigation procedures
  • Knowledge of tools, techniques and processes (TTP) used by threat actors
  • Knowledge of indicators of compromise (IOC)
  • Experience with endpoint protection and enterprise detection & response software (such as CrowdStrike or MS Defender)
  • Knowledge of network and infrastructure technologies including routers, switches, firewalls, etc.

Soft Skills:

  • Intermediate - Seeks to acquire knowledge in area of specialty
  • Intermediate - Ability to identify basic problems and procedural irregularities, collect data, establish facts, and draw valid conclusions
  • Intermediate - Ability to work independently
  • Intermediate - Demonstrated analytical skills
  • Intermediate - Demonstrated project management skills
  • Intermediate - Demonstrates a high level of accuracy, even under pressure
  • Intermediate - Demonstrates excellent judgment and decision making skills
  • Intermediate - Ability to communicate and make recommendations to upper management
  • Intermediate - Ability to drive multiple projects to successful completion
  • Intermediate - Possesses technical aptitude

Pay Range: $100,900.00 - $186,800.00 per year

Centene offers a comprehensive benefits package including: competitive pay, health insurance, 401K and stock purchase plans, tuition reimbursement, paid time off plus holidays, and a flexible approach to work with remote, hybrid, field or office work schedules.  Actual pay will be adjusted based on an individual's skills, experience, education, and other job-related factors permitted by law.  Total compensation may also include additional forms of incentives.

Centene is an equal opportunity employer that is committed to diversity, and values the ways in which we are different. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or other characteristic protected by applicable law.

Qualified applicants with arrest or conviction records will be considered in accordance with the LA County Ordinance and the California Fair Chance Act

Top Skills

AWS
Azure
Cloud

Similar Jobs

Yesterday
Remote
8 Locations
Internship
Internship
Retail
The Cybersecurity Intern will assist with daily security operations tasks, vulnerability management, and incident response, while developing knowledge in IT retail systems and cybersecurity concepts. Collaboration with IT teams will be essential to deliver secure environments and ensure system integrity, confidentiality, and availability.
Top Skills: Windows
2 Days Ago
Remote
11 Locations
Senior level
Senior level
Big Data • Cloud • Information Technology
The ServiceNow Developer will develop and maintain the ServiceNow platform, focusing on the Strategic Portfolio Management (SPM) module. Responsibilities include customizing and configuring the system, creating and maintaining integrations, developing scripts and workflows, and enhancing business efficiency in an Agile environment.
Top Skills: JavaScript
4 Days Ago
Remote
Casablanca, MAR
Entry level
Entry level
Information Technology • Consulting
ALTER SOLUTIONS invites spontaneous applications for IT services roles. They emphasize community involvement and CSR initiatives while looking for diverse individuals who align with their mission of providing top solutions to clients globally.

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account