The Sr Security Engineer is an integral part of the Cybersecurity program. This position will be responsible for maturing the Risk Management and Incident response areas. This will be accomplished by conducting risk assessment of third parties systems & equipment being placed on the network and cloud systems. Incident Response duties include organizing table top exercise and working with other staff on remediation of gaps identified. Day to day this position will interface with staff at all levels of the organization.
Responsibilities:
Assists with the implementation execution and continuous improvement of the Information Security Program including but not limited to: Policy and Document Maintenance Risk Assessment Security Controls and Technical Oversight.
Maintains information security policies procedures and standards.
Conducts periodic risk analysis and risk management assessments.
Develops and coordinates application security reviews and is responsible for vulnerability and incident management.
Responsible for evaluation selection and implementation of information security tools.
Ability to problem solve/remediate in a highly complex and matrixed environment.
Ability to successfully work in a fast-paced environment with a variety of personalities and work styles.
Ability to successfully work well under pressure with tight deadlines and with a sense of urgency.
Possess excellent written oral and active listening skills.
Other duties as required.
Requirements
Other information:
Technical Expertise
Experience in HIPAA HITECH PCI NIST and other frameworks is required.
Experience in securing information system technologies is required.
Experience with both Technical Security Engineer and Governance Risk and Compliance (GRC) is strongly preferred.
Experience working with all levels within an organization is required.
Experience in healthcare is preferred.
Proficiency in MS Office Outlook Excel Word or similar software is required.
In-depth knowledge of security concepts such as cyber-attacks and techniques threat vectors risk management incident management etc.
Experience with an organizations privacy and security due diligence efforts when entering into third party relationships or M&A activities a plus.
Knowledge of various operating system flavors including but not limited to Windows Linux Unix
Knowledge of applications databases middleware to address security threats against the same.
Proficient in preparation of reports dashboards and documentation
Excellent communication and leadership skills
Ability to handle high pressure situations with key stakeholders
Good Analytical skills Problem solving and Interpersonal skills
Ability to adapt and thrive in a dynamic work environment. Exceptional organization skills ability to work independently as well as part of a team and demonstrated experience in taking initiative and following up on tasks.
Proficiency in MS Office Outlook Excel Word Visio and SharePoint or similar software is required.
Education and Experience
Education: Bachelor degree in related field is required.
Security Certification Required: CEH CISSP GCIH GSEC or similar level security certification
2-3 years leadership/ supervisory experience preferred
Bachelors degree in Information Technology Information Systems or equivalent experience. 35 years of experience in IT service management service desk operations or IT operations. Hands-on experience with Service Desk Plus Enterprise or similar ITSM platforms. Working knowledge of ITIL processes including Incident Request Change and Problem Management. Strong analytical documentation and communication skills.
Required Education:
Any Graduate
Summary:The Sr Security Engineer is an integral part of the Cybersecurity program. This position will be responsible for maturing the Risk Management and Incident response areas. This will be accomplished by conducting risk assessment of third parties systems & equipment being placed on the network ...
Summary:
The Sr Security Engineer is an integral part of the Cybersecurity program. This position will be responsible for maturing the Risk Management and Incident response areas. This will be accomplished by conducting risk assessment of third parties systems & equipment being placed on the network and cloud systems. Incident Response duties include organizing table top exercise and working with other staff on remediation of gaps identified. Day to day this position will interface with staff at all levels of the organization.
Responsibilities:
Assists with the implementation execution and continuous improvement of the Information Security Program including but not limited to: Policy and Document Maintenance Risk Assessment Security Controls and Technical Oversight.
Maintains information security policies procedures and standards.
Conducts periodic risk analysis and risk management assessments.
Develops and coordinates application security reviews and is responsible for vulnerability and incident management.
Responsible for evaluation selection and implementation of information security tools.
Ability to problem solve/remediate in a highly complex and matrixed environment.
Ability to successfully work in a fast-paced environment with a variety of personalities and work styles.
Ability to successfully work well under pressure with tight deadlines and with a sense of urgency.
Possess excellent written oral and active listening skills.
Other duties as required.
Requirements
Other information:
Technical Expertise
Experience in HIPAA HITECH PCI NIST and other frameworks is required.
Experience in securing information system technologies is required.
Experience with both Technical Security Engineer and Governance Risk and Compliance (GRC) is strongly preferred.
Experience working with all levels within an organization is required.
Experience in healthcare is preferred.
Proficiency in MS Office Outlook Excel Word or similar software is required.
In-depth knowledge of security concepts such as cyber-attacks and techniques threat vectors risk management incident management etc.
Experience with an organizations privacy and security due diligence efforts when entering into third party relationships or M&A activities a plus.
Knowledge of various operating system flavors including but not limited to Windows Linux Unix
Knowledge of applications databases middleware to address security threats against the same.
Proficient in preparation of reports dashboards and documentation
Excellent communication and leadership skills
Ability to handle high pressure situations with key stakeholders
Good Analytical skills Problem solving and Interpersonal skills
Ability to adapt and thrive in a dynamic work environment. Exceptional organization skills ability to work independently as well as part of a team and demonstrated experience in taking initiative and following up on tasks.
Proficiency in MS Office Outlook Excel Word Visio and SharePoint or similar software is required.
Education and Experience
Education: Bachelor degree in related field is required.
Security Certification Required: CEH CISSP GCIH GSEC or similar level security certification
2-3 years leadership/ supervisory experience preferred
Bachelors degree in Information Technology Information Systems or equivalent experience. 35 years of experience in IT service management service desk operations or IT operations. Hands-on experience with Service Desk Plus Enterprise or similar ITSM platforms. Working knowledge of ITIL processes including Incident Request Change and Problem Management. Strong analytical documentation and communication skills.