Director I Cybersecurity - Threat Intelligence & Engineering

Elevance HealthIndianapolis, Mason, Indiana, Virginia, OhioHybridFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Anticipated End Date:
2026-10-12

Position Title:
Director I Cybersecurity - Threat Intelligence & Engineering

Job Description:

Director I Cybersecurity - Threat Intelligence & Engineering

Location: This role requires associates to be in-office 3 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.

Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.

The Director I Cybersecurity - Threat Intelligence & Engineering is responsible for leading the threat intelligence, detection engineering, threat hunting, and phishing resiliency functions. This leader will translate the external threat landscape and internal telemetry into measurable risk reduction — improving detection coverage, accelerating response, and continuously validating controls.

How you will make an impact:

People & Executive Leadership:
•    Build, mentor, and retain a multi-disciplinary team of intel analysts, hunters, detection engineers, red/purple operators, and automation engineers.
•    Serve as a trusted advisor to executives on threat landscape, detection posture, and risk-based prioritization.
•    Partner with x-functional organizations across privacy, legal, law enforcement, intelligence community, and other intel sharing organizations

Cyber Threat Intelligence (CTI):
•    Enhance and direct the enterprise Cyber Threat Intelligence, program, establishing the strategy, requirements, and operating model for threat intelligence and threat hunting.
•    Establish and oversee analysis and reporting on adversary tactics, techniques, and procedures, threat actor profiles, and emerging threats.
•    Set the strategy and operating model for Threat Intelligence, Threat Hunting, Detection Engineering with AI & Automation.
•    Drive zero trust cyber defense – visualization, correlation, and analytics anchored on cyber threat intelligence.
•    Manage vendor relationships and external intelligence sharing partnerships

Detection engineering & operations:
•    Own and enhance an efficient detection engineering lifecycle and its efficacy from hypothesis, intelligence, deployment, tuning and deprecation.
•    Map detection to the industry frameworks like MITRE ATT&CK and real world threat feeds for robust coverage of today’s threats and anticipatory of tomorrow’s threats based on emerging intelligence.
•    Drive purple and red team exercises partnering with the Attack Surface management & red teams.
•    Integrate automation and AI capabilities with the AI SOC
Collaboration & Communications:
•    Establish team OKRs and outcomes aligned to business risk, security priorities, and industry frameworks (e.g., ATT&CK coverage, MTTD/MTTR improvements, control validation).
•    Evaluate and govern adoption of agentic security solutions (AI-driven investigation/response), ensuring safety, auditability, human-in-the-loop controls, and measurable value.
•    Communicate complex threats and trends clearly to executive leadership and business stakeholders verbally and through written threat intel briefs.

Minimum Requirements:

Requires an BA/BS degree in Information Technology, Computer Science or related field of study and a minimum of 7 years of IT management experience; or any combination of education and experience, which would provide an equivalent background.

Preferred Skills, Capabilities and Experiences:

•    Experience evaluating and operationalizing agentic (AI-driven) security solutions is strongly preferred.
•    Seven years in cybersecurity, with at least 5 years leading CTI, detection engineering, or security operations team is preferred.
•    Deep familiarity with SOC technologies, threat intelligence, and adversary emulation technologies and practices is strongly preferred.
•    Extensive and deep knowledge in industry frameworks like the MITRE ATT&CK framework, NIST, & CIS is preferred.
•    Proven track record of managing high performing technical teams, scaling security programs, and driving x-functional cyber debt and risk reduction is strongly preferred. 
•    Ability to manage across geographically diverse associates and vendor partners strongly preferred.

Job Level:
Director

Workshift:

Job Family:
IFT > IT Tech Strategy

Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.

Who We Are

Elevance Health is a health company dedicated to improving lives and communities – and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.

How We Work

At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.

We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.

Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process should submit the following form: Accessibility Accommodation Request Form and a member of the team will be in contact. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.

Prospective employees required to be screened under Florida law should review the education and awareness resources at HB531 | Florida Agency for Health Care Administration .

NOTE: Workday keeps job postings active through 11:59:59 PM on the day before the listed end date. Example: If the end date is 3/13, the posting will automatically come down on 3/12 at 11:59:59 PM. In other words — the job is posted until 3/13, not through 3/13.