Specialist - Cyber Security (remote)
Are you looking to make a difference in a patient’s life? At AmerisourceBergen, you will find an innovative and collaborative culture that is patient focused and dedicated to making a difference.
As an organization, we are united in our responsibility to create healthier futures. Join us and Apply today!
What you will be doing
Individuals within the Information Security role plan, execute, and manage multi-faceted projects related to risk management, mitigation and response, compliance, control assurance, and user awareness.
They are focused on developing and driving security strategies, policies / standards, ensuring the effectiveness of solutions, and providing security-focused consultative services to the organization.
These individuals provide expertise and assistance to ensure the company’s infrastructure and information assets are protected.
Individuals develop security policies and procedures such as user log-on and authentication rules, security breach escalation procedures, security assessment procedures and use of firewalls and encryption routines.
They perform security assessments and security attestations. To enforce security policies and procedures, they monitor data security profiles on all platforms by reviewing security violation reports and investigating security exceptions.
They update, maintain and document security controls and provide direct support to the business and internal IT groups. These professionals work directly with the customers, third parties and other internal departments and organizations to facilitate information security risk analysis and risk management processes and to identify acceptable levels of residual risk.
They also communicate and educate IT and the business about security policies and industry standards and provide solutions for enterprise / business security issues.
Develops and manages security for multiple Cybersecurity functional areas (e.g., Cyber Operations, Incident Response, Threat Intelligence, Threat Hunting, Forensics, Vulnerability Management, Data Analytics)
Develops and operates enterprise security services such as cyber incident response, cyber monitoring, network-based vulnerability scanning, threat intelligence, threat hunting, or forensics.
Contributes strategic and tactical direction on cybersecurity initiatives.
Under the direction of management, implements the enterprise wide security policies, procedures and standards to meet compliance responsibilities.
Ensures service-level agreements (SLAs) are met.
Ensures that security controls are developed, managed and maintained.
Monitors compliance with security policies, standards, guidelines and procedures.
Produces metrics and key performance indicators for executive review
Works with customers to identify security requirements using methods that may include risk and business impact assessments.
Consults with other business and technical staff on potential business impacts of proposed changes to the security environment.
Works closely with IT and development teams to assess secure infrastructure solutions and applications, facilitating the implementation of protective and mitigating controls.
Conducts business impact analysis to ensure resources are adequately protected with proper security measures.
Works directly with the customers, third parties and other internal departments and organizations to facilitate information security risk analysis and risk management processes and to identify acceptable levels of residual risk.
Assesses potential items of risk and opportunities of vulnerability in the network and on information technology infrastructure and applications;
develops plans to achieve security requirements and address identified risks.
Oversees technical risks assessments, such as vulnerability scanning and penetration testing.
Assesses threats and vulnerabilities regarding information assets and recommends the appropriate information security controls and measures.
Performs security assessments and security attestations.
Leads security investigations and compliance reviews.
Leads security monitoring to uncover possible security violations (e.g., breaches, unauthorized activity).
Leads the response to security alerts and escalates critical incidents to correct support teams.
Develops and leads incident response exercises.
Participates in the development of information security disaster recovery test plans, testing, and documentation for each application.
Coordinates the administration and logistical procedures for information security disaster recovery testing.
Monitors and analyzes information security performance reports and handles or escalates issues as needed.
May lead application security risk assessments for new or updated internal or third-party applications.
Interfaces with business and IT leaders communicating security issues and responding to requests for assistance and information. ?
May serve in an advisory role in application development and infrastructure projects to assess security requirements and controls and ensures that security controls are implemented as planned.
Conducts knowledge transfer training sessions to security operations team upon technology implementation.
Develops, reviews, and implements runbooks and procedures for cyber operations activities.
Performs related duties as assigned.
What your background should look like
Bachelor’s Degree in Cybersecurity, Risk Analysis, Computer Science, Information Systems or other related field, or equivalent work experience
Typically requires Five (5) or more years of combined IT and security work experience with a broad range of exposure to cybersecurity functions.
Requires hands-on experience with security tools, techniques, and incidents, and experience designing and implementing security solutions.
Requires security certification (i.e., Certified Information Systems Security Professional (CISSP) or equivalent.
Strong computer skills in order to operate effectively with company systems and programs; working knowledge of applicable computer applications used at ABC
Strong analytical and problem-solving skills
Ability to communicate effectively both orally and in writing
Good interpersonal skills
Ability to prioritize workload and consistently meet deadlines
Strong organizational skills; attention to detail
Working knowledge of network solutions and systems
Strong project management skills, including the ability to effectively deploy resources and manage multiple projects of various diverse scope in a cross-functional environment
Cybersecurity Operations roles also require :
Proficiency with the following security tool categories : SIEM, EDR, Email Security Gateway, SOAR, Firewall, Anti-virus
Skilled in running special investigations involving HR, Legal, and Corporate Security.
Experience leading major incident breach response activities.
Skilled in analyzing attack simulation reports and remediating gaps found
Skilled in developing cybersecurity tabletop scenarios
Skilled in assessing cyber tool health and identifying issues with detection and prevention
Skilled in design, tuning, and assessment of security detection policies in cyber tools
Ability to develop new cybersecurity operations procedures and train / implement with the team
Skilled in maintenance of document and evidence repositories
Demonstrated ability to oversee change controls related to cybersecurity tools and remediation's
Cyber TI / TH, Forensics roles also require :
Exceptional skill in the use of forensics tools and processes in strict adherence to all laws and best practices
Exceptional skill in managing and monitoring threat intelligence feeds and platforms
Exceptional skill in determining root cause of cyber incidents
Exceptional skill in hunting for undetected threats including APT activity
What AmerisourceBergen offers
We offer a competitive total rewards package which includes benefits and compensation. Our commitment to our eligible population of team members includes benefit programs that are comprehensive, affordable, diverse, and designed to meet the needs of our team members’ and their families.
Some of these programs include paid time off including paid parental leave, access to retirement savings vehicles, medical, dental, vision, and life insurance options, an employee stock purchase program, and other financial, health, and well-being focused benefits.
Because we take a balanced, global approach to our benefits, benefit offerings may vary by location, position, and / or business unit.
Some benefits are company-paid, while others are available through team member contributions. .
Schedule
Full time
Affiliated Companies
Affiliated Companies : AmerisourceBergen Services Corporation
Related Jobs
Specialist - Cyber Security (remote)
Security Officer
Security Guard
Container Security Engineer