← All jobs
Director - Cyber Security Operations
Des Moines, IA, US · On-site · Full-time · Technology
Apply well, not just fast
Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.
About the role
CybersecurityPenetration TestingAuditingProcurementRisk ManagementHIPAA
Why Wellmark: We are a mutual insurance company owned by our policy holders across Iowa and South Dakota, and we’ve built our reputation on over 80 years’ worth of trust. We are not motivated by profits. We are motivated by the well-being of our friends, family, and neighbors–our members. If you’re passionate about joining an organization working hard to put its members first, to provide best-in-class service, and one that is committed to sustainability and innovation, consider applying today! 
Why Wellmark Technology? Wellmark is building innovative, modern solutions using cutting edge technology. We are driving organizational transformation and business strategy by empowering our technology team to innovate new and elegant solutions to enhance the customer experience. Together, we are leaning into the future, owning the outcome, and driving organizational change to transform how we work. 
Provide operational leadership of Wellmark’s Cyber Security Operations department and related disciplines. Collaborate across the organization toward the strategic development and implementation of cyber security policies, standards, and processes aligned to leading industry practices as well as HIPAA, NIST, BCBSA, and all applicable regulatory requirements. Lead domain-specific change efforts resulting from cyber security strategy and policy updates and recommend/implement control changes in response to emerging risks. Partner with departmental leadership and staff to ensure the effective operation of security services that foster enterprise-wide understanding and support of the Corporate Information Security Program.
Required:
- Bachelor’s degree or equivalent experience (4 years).
- One or more certifications: CISSP, CISM, CRISC, CCSP, CISA, CISSP-ISSMP.
- Minimum 7 years’ experience designing and delivering security solutions, including 5+ years security management, 4+ years implementing security controls, experience in risk identification, analysis, and mitigation, and 3+ years shaping security structure and direction at an organizational or discipline level.
- Deep technical cyber security expertise that includes extensive cloud (PaaS) security experience.
- Demonstrated ability to lead high-performing teams that deliver results.
- Strong communication, influence, and relationship-building skills.
- Proven ability to set strategy and drive tactical execution.
- Experience leading through change and resolving complex problems.
- Strong decision-making and critical-thinking skills.
- Knowledge of existing and emerging technologies.Preferred:
- Master’s degree.
a. Provide strategic direction to a team of individual contributors and leaders to support enterprise goals; communicate strategy and priorities across the team. Oversee daily management of financial and human resources, including coaching, performance development, and departmental budgeting.
b. Lead and continuously improve the Cyber Incident Management process using NIST and other cyber-industry best practices. Coordinate response to cyber-security incidents; advise leaders on risk remediation and process improvement plans. Oversee cyber-forensics staff and their use of operational practices that ensure legal defensibility and proper chain-of-custody standards. Establish risk-based incident metrics and reporting.
c. Develop and maintain the insider threat management program, including user activity monitoring and anomalous behavior detection. Set operational rules enabling rapid detection without impacting member service.
d. Lead a best-in-class security awareness program from onboarding through annual training and ad-hoc education. Lead and participate in the development of clear, practical cyber security policies and collaborate with stakeholders to promote compliance.
e. Build and lead a high-performing Security Operations Center (SOC) delivering 24x7x365 threat response, ensuring the appropriate use of tools, processes, and performance metrics. Oversee a cyber security threat intelligence capability that delivers actionable, relevant insights and tangible early-warning value.
f. Partner with departmental leadership in the administration of the Information Security Program, including the development and enforcement of policy and standards frameworks. Lead Third Party Risk Management's oversight of processes governing third-party security reviews, and collaborate with Procurement, Legal, and adjacent teams on vendor risk assessment.
g. Oversee a comprehensive vulnerability management and penetration testing program for applications, systems, cloud environments, and databases. Establish risk-based remediation expectations and provide operational and executive reporting.
h. Support the regular maintenance of the strategic cyber security roadmap across managed disciplines. Work with internal partners and external assessors to identify gaps, evaluate tools, and assess emerging threats.
i. Provide day-to-day leadership to multiple cyber security teams; develop leaders and staff in alignment with organizational strategy. Manage budgets, staffing plans, and business cases for technology investments and cyber security enhancements.
j. Collaborate with Privacy, Legal, and Internal Audit as required for compliance and event investigation purposes. Act on behalf of the CISO when needed, including participation in executive meetings, industry forums, and major incident leadership.
k. Other duties as assigned.
All your information will be kept confidential according to EEO guidelines.
This job requires a non-compete agreement.
An Equal Opportunity Employer
The policy of Wellmark Blue Cross Blue Shield is to recruit, hire, train and promote individuals in all job classifications without regard to race, color, religion, sex, national origin, age, veteran status, disability, sexual orientation, gender identity or any other characteristic protected by law.
Applicants requiring a reasonable accommodation due to a disability at any stage of the employment application process should contact us at [email protected]
Please inform us if you meet the definition of a "Covered DoD official".
At this time, Wellmark is not considering applicants for this position that require any type of immigration sponsorship (additional work authorization or permanent work authorization) now or in the future to work in the United States. This includes, but IS NOT LIMITED TO: F1-OPT, F1-CPT, H-1B, TN, L-1, J-1, etc. For additional information around work authorization needs please refer to the following resources:Nonimmigrant Workers and Green Card for Employment-Based Immigrants 
Wellmark supports and expects the responsible use of AI for our workforce! We welcome the responsible use of these tools by job seekers as well and are interested in learning from you; you will have an opportunity in the application process to share which tools you used and how you applied them.