Director I - Cybersecurity Operations & Incident Response

Elevance HealthIndianapolis, IN
Hybrid

About The Position

The Director, Cybersecurity Operations & Incident Response is responsible for leading enterprise cybersecurity monitoring, security incident response, and investigative operations across Elevance Health. This role leads the 24x7 Security Operations Center (SOC) and Cyber Security Incident Response Team (CSIRT), ensuring security events and incidents are rapidly identified, investigated, contained, remediated, and communicated. This Director is accountable for operational excellence across a follow-the-sun SOC model, effective execution of the cyber incident response lifecycle, development of highly capable cybersecurity professionals, and continuous improvement of security operations processes and capabilities.

Requirements

  • Requires an BA/BS degree in Information Technology, Computer Science or related field of study and a minimum of 7 years of IT management experience; or any combination of education and experience, which would provide an equivalent background.

Nice To Haves

  • Demonstrated experience leading enterprise Security Operations Center, Cyber Security Incident Response, or comparable cybersecurity operations functions is preferred.
  • Extensive experience managing cybersecurity incidents across the incident response lifecycle, including identification, triage, investigation, containment, eradication, recovery, evidence preservation, and post-incident review is preferred.
  • Cybersecurity certifications such as CISSP, CISM, GCIH, GCFA, GCIA, or comparable industry certifications are strongly preferred.
  • Demonstrated record of building high-performing security operations teams and improving operational maturity, investigation quality, analyst effectiveness, and incident response outcomes is preferred.
  • Prior experience leading a 24x7 enterprise Security Operations Center and Cyber Security Incident Response Team is strongly preferred.
  • Strong working knowledge of healthcare and cybersecurity regulatory and compliance requirements, including HIPAA, HITRUST, PCI DSS, NIST Cybersecurity Framework, SOX, SEC cybersecurity requirements, and state or federal breach notification requirements is strongly preferred.

Responsibilities

  • Interfaces with key Information Technology (IT) solution teams and vendors.
  • Lead and coordinate cybersecurity incident response activities with Legal, Privacy, Compliance, Human Resources, Corporate Security, technology teams, and other business stakeholders as required.
  • Support engagement with external parties, including law enforcement, regulatory authorities, cyber insurance providers, external counsel, and other third parties during significant cybersecurity investigations and incidents.
  • Provide timely and accurate briefings to the CISO and senior leadership regarding high-profile cybersecurity incidents, including incident scope, business impact, response status, key decisions, risks, and recommended actions.
  • Oversee enterprise security monitoring and investigation capabilities, including SIEM-based monitoring, security alert triage, cloud security monitoring, identity-related investigations, malware analysis, digital forensics, threat intelligence consumption, and other security operations functions within the team’s scope.
  • Provide operational input into the design and adoption of AI-enabled cybersecurity workflows, ensuring solutions enhance analyst effectiveness while maintaining appropriate governance, human oversight, accuracy, and risk controls.
  • Manage operational readiness for major cybersecurity events, including surge staffing, escalation paths, communications, technical coordination, and transition between normal security operations and formal incident response activities.
  • Support regulatory, audit, and compliance activities by providing evidence of security monitoring and incident response controls and ensuring alignment with applicable frameworks and requirements, including HIPAA, HITRUST, PCI DSS, NIST Cybersecurity Framework, SOX, SEC cybersecurity requirements, and applicable breach notification obligations.
  • Develop business-level presentations, operational reporting, incident briefings, and strategic recommendations that enable senior leadership to understand cybersecurity risk, operational performance, capability gaps, and investment priorities.
  • Hires, trains, coaches, counsels, and evaluate performance of direct reports.

Benefits

  • merit increases
  • paid holidays
  • Paid Time Off
  • incentive bonus programs
  • medical
  • dental
  • vision
  • short and long term disability benefits
  • 401(k) +match
  • stock purchase plan
  • life insurance
  • wellness programs
  • financial education resources
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service