Security Engineer Sr.
Job Summary
At Blue Cross and Blue Shield of Minnesota we are committed to paving the way for everyone to achieve their healthiest life. We are looking for dedicated and motivated individuals who share our vision of transforming healthcare. As a Blue Cross associate you are joining a culture that is built on values of succeeding together finding a better way and doing the right thing. If you are ready to make a difference join us.
- Own the CTEM lifecycle scoping discovery prioritization validation and mobilization across cloud on-prem and hybrid environments aligning practices to the CTEM framework.
- Administer and optimize vulnerability scanning platforms (e.g. Tenable Qualys Rapid7) including scan policy design credential scanning agent deployment and coverage gap analysis.
- Integrate scanning and exposure data into ticketing SIEM CMDB and GRC platforms to automate workflows and reduce manual triage.
- Monitor vulnerability and exposure management activity analyze scanner findings and threat intelligence and support timely investigation remediation exception review and validation of risk reduction efforts.
- Conduct security assessments control reviews and scan coverage reviews to evaluate effectiveness identify improvement opportunities reduce false positives and validate remediation outcomes.
- Partner with business infrastructure cloud application and technology stakeholders to document findings develop remediation plans and implement solutions that reduce exploitable risk across the enterprise.
- Provide guidance and consultation on vulnerability remediation exposure management practices scanning standards risk prioritization and security control expectations.
- Develop and maintain vulnerability management procedures scanning standards remediation guidance dashboards reports and technical documentation that support consistent program execution.
- Participate in risk assessments audits and continuous improvement initiatives by supplying vulnerability evidence monitoring remediation progress and recommending enhancements to tools workflows and reporting.
- Performs additional responsibilities consistent with the scope and level of the role as assigned
- 5 years of related IT Security professional experience.
- Bachelors degree; in lieu of a degree an additional two years of relevant experience beyond the qualifications listed above may be accepted.
- Experience building or maturing a CTEM/vulnerability management program from the ground up.
- Experience administering or supporting vulnerability scanning assessment endpoint cloud security or exposure management technologies.
- Knowledge of security standards frameworks regulatory requirements vulnerability remediation lifecycles and scan validation practices.
- Ability to communicate complex topics clearly and concisely actively listen to anticipate stakeholder needs and align others to drive informed decisions.
- Ability to analyze complex information evaluate options and work cross-functionally to drive resolution and prevent recurrence.
- Ability to effectively organize work balance competing priorities and manage time across complex assignments and competing deadlines.
Microsoft Certified Azure Fundamentals (AZ-900) - Microsoft
Certified Cloud Security Professional (CCSP) - International Information System Security Certification Consortium (ISC2)
Certified Information Systems Security Professional (CISSP) - International Information System Security Certification Consortium (ISC2)
Amazon AWS Cloud Practitioner - Amazon
Role designation definition:
- Teleworking is working full time remote.
- Hybrid is a minimum of 2 days onsite.
- Onsite is full-time onsite.
Anchored in Connection
Our hybrid approach is designed to balance flexibility with meaningful in-person connection and collaboration. We come together in the office two days each week most teams designate at least one anchor day to ensure team interaction. These in-person moments foster relationships creativity and alignment. The rest of the week you are empowered to work remote.
Pay is based on several factors which vary based on position including skills ability and knowledge the selected individual is bringing to the specific job.
We offer a comprehensive benefits package which may include:
Medical dental and vision insurance
Life insurance
401k
Paid Time Off (PTO)
Volunteer Paid Time Off (VPTO)
And more
To discover more about what we have to offer please review our benefits page.
At Blue Cross and Blue Shield of Minnesota we are committed to paving the way for everyone to achieve their healthiest life. Blue Cross of Minnesota is an Equal Opportunity Employer and maintains an Affirmative Action plan as required by Minnesota law applicable to state contractors. All qualified applications will receive consideration for employment without regard to and will not be discriminated against based on any legally protected characteristic.
Individuals with a disability who need a reasonable accommodation in order to apply please contact us at:
Blue Cross and Blue Shield of Minnesota and Blue Plus are nonprofit independent licensees of the Blue Cross and Blue Shield Association.
Required Experience:
Senior IC