Jobs and Careers
CV

Senior Cyber Threat Intelligence Engineer

CVS Health
Work At Home-New Jersey, United States, United Statesfull_timeVerifiedPosted 6 Jan 2025
💰 $222,480/yr($111,240/yr$222,480/yr)

About the role

Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
 
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.

Position Summary

CVS Health’s Cyber Threat Intelligence (CTI) team is responsible for all phases of cyber security intelligence (collection, analysis, production and dissemination) and tasked with identifying increasingly sophisticated cyber-attacks; monitoring the tactics, techniques and procedures of threat actors and establishing motives that could impact company resources.  This intelligence is then leveraged to actively hunt for adversary activity targeting CVS Health’s computing environment.  

As a senior member of the CTI team, you will collect, monitor and analyze various threat data and intelligence feeds to provide actionable threat indicators as well as recommending suitable defensive solutions.  In addition, you will also engineer various Threat Intelligence solutions that will allow the threat intelligence team to continue to automate and improve their collection and analysis capabilities. You will also help develop alerts, enhance workflows and create automation leveraging the actionable threat indicators. CTI also continually fosters strong collaborative relationships with the Intelligence community, law enforcement agencies, and the financial, retail, and healthcare industries. 

Responsibilities: 

  • Identify, evaluate and communicate new and ongoing cyber security threats through regular and ad-hoc reporting; produce intelligence briefings, attribution reports and position papers  
  • Produce concise tactical warning bulletins and other analytic reports that detail daily findings, events, and activities.  
  • Effectively perform all phases of the intelligence cycle (collection, analysis, production and dissemination)   
  • Maintain, develop and continually analyze threat data/intelligence sources, both technical and non-technical  
  • Contribute to overall engineering efforts, including supporting design and development for capturing, storing, processing, and analyzing and disseminating threat intelligence for awareness and action. 
  • Advocates threat intelligence engineering priorities. Evaluate tools and best practices for tracking intelligence, TTPs and Intelligence tools.  
  • Implement in-depth research on threat actors, TTPs and vulnerabilities and generate reports to relevant stake holders. 
  • Analyze and help prioritize security incidents for further enrichment of detection and alerting capabilities using various security technologies (SIEM, SOAR, EDR) 
  • Continuously improve processes for use across detection sets for more efficient operations. 

Required Qualifications:

  • 7+ years of experience in a technical cybersecurity function with emphasis around Threat Intelligence.
  • 3+ years’ experience with advanced threat intelligence collection and analysis methodologies, threat actors and MITRE techniques 
  • 3+ years’ experience with various SIEM and SOAR tools, open source and or commercial tools.
  • 3+ years’ experience in engineering and analyzing diverse datasets such as product telemetry, commercial threat feeds and information from OSINT sources.
  • 3+ years’ experience writing threat briefs and prioritizing threats from alerts as well as security log analysis.
  • 2+ years’ experience demonstrated proficiency in scripting and querying languages.
  • 1+ years’ experience presenting various threat intelligence reports to various stakeholders.

Preferred Qualifications: 

  • Experience automating and developing solutions and prototypes in the security particularity the threat intelligence space.
  • Proven experience in a Security Engineering environment with the ability to script and engineer solutions.
    <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CVS Health

View company profile →