Associate Information Security Engineer

highmarkhealth

Pennsylvania

Hybrid

USD 85,000 - 125,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

enGen is seeking an Information Security/Infrastructure professional to assist in planning, researching, evaluating, and designing ISRM infrastructure aligned with organizational strategy. You will support OS and software tooling development, monitor performance, and help establish engineering policies and procedures.

The role focuses on assisting with requirements, root cause analysis, and delivering secure infrastructure components.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems or related field.
  • Substitutions: 6 years of related and progressive experience in lieu of Bachelor's degree.
  • 1 year in Information security and systems analysis.
  • 1 year in Information security, Information Risk management and/or information technology.
  • 1 year with operating systems and software administration.
  • 1 year of developing, communicating and presenting information security and risk management concepts to varying audiences.
  • 1 year with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms.

Responsibilities

  • Assists teams in defining requirements, deliverables and timeframes; escalate issues and make recommendations.
  • Assists in root cause analysis to identify and resolve complex problems.
  • Assists in developing and/or delivering technical training in less complex technical areas.
  • Assists in completing project tasks to enable on-time, within-budget, and within-scope delivery of ISRM Infrastructure projects.
  • Assists to implement, monitor, configure, and maintain security systems.
  • Assure compliance to required standards, procedures, guidelines and processes.
  • Other duties as assigned or requested.

Skills

HITRUST CSF
NIST 800-83
PCI DSS
HIPAA / HITECH
ISO 27001
ITIL v3
Secure SDLC
Windows Server / Microsoft Apps

Education

Bachelor's degree in Computer Science or Information Systems
6 years related experience in lieu of Bachelor's degree

Tools

SharePoint
Windows Server
IPS
SEIM
DLP

Job description

Company : enGen Job Description :

JOB SUMMARY

This job assists others to plan, research, evaluate, design and develop Information Security and Risk Management (ISRM) Infrastructure systems by applying engineering, hardware and software design theories and principles to develop a compatible system infrastructure in line with organizational strategies. Assists with the design, development, and implementation of less complex ISRM Infrastructure components such as operating systems, software tools, and utilities. Assists in conducting less complex studies of ISRM Infrastructure performance and traffic analysis. Assists in determining systems design requirements and ensures that system improvements are successfully implemented and monitored to increase efficiency. Assists with the development of ISRM Infrastructure engineering policies, standards and procedures.

ESSENTIAL RESPONSIBILITIES
  • Assists teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.
  • Assists in conducting root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
  • Assists in developing and/or delivering technical training in less complex technical areas.
  • Assists in completing project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.
  • Assists to implement, monitor, configure, and maintain security systems.
  • Assure compliance to required standards, procedures, guidelines and processes.
  • Other duties as assigned or requested.
EDUCATION
  • Required: Bachelor's degree in Computer Science, Information Systems or related field
  • Substitutions: 6 years of related and progressive experience in lieu of Bachelor's degree
  • Preferred: None
EXPERIENCE
  • Required: 1 year in Information security and systems analysis
  • Required: 1 year in Information security, Information Risk management and/or information technology
  • Required: 1 year with operating systems and software administration
  • Required: 1 year of developing, communicating and presenting information security and risk management concepts to varying audiences
  • Required: 1 year with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
  • Preferred: Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
  • Preferred: IT/information security risk advisory experience
  • Preferred: In-depth understanding of network security architecture, network and networking protocols
  • Preferred: Database management, system administration and software development lifecycle
  • Preferred: Experience with IoT (Internet of things) Security, including IoMT (Internet of Medical things) and (OT) Operational Technology, or MDM (Mobile Device Management)
  • Preferred: Experience with Linux or Mac Management
  • Preferred: Experience with modern Windows Endpoint Management tooling
LICENSES or CERTIFICATIONS
  • Required: None
  • Preferred: Certified Information Systems Security Professional (CISSP), Security +
  • Preferred: CISA (Certified Information Systems Auditor) or CISM (Certified Information Security Manager)
  • Preferred: GSEC (GIAC Security Essentials Certification)
SKILLS
  • Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
  • Familiarity with secure SDLC best practices
  • Knowledge of Microsoft Apps and Suites, Windows Server, SharePoint, etc.
  • Strong teamwork and inter-personal skills
Language (Other than English):

None

Travel Requirement:

0% - 25%

PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
  • Position Type Office-based
  • Teaches / trains others regularly Occasionally
  • Travel regularly from the office to various work sites or from site-to-site Rarely
  • Works primarily out-of-the office selling products/services (sales employees) Never
  • Physical work site required Yes
  • Lifting: up to 10 pounds Constantly
  • Lifting: 10 to 25 pounds Occasionally
  • Lifting: 25 to 50 pounds Rarely
Disclaimer:

The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement :

This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.

As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as al

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Business Systems Analyst
Associate Business Systems Analyst

highmarkhealth • Pennsylvania

Hybrid
USD 37,000 - 58,000
IT Security Engineer, Level III
IT Security Engineer, Level III

SherlockTalent • Fort Lauderdale (FL)

Hybrid
USD 90,000 - 120,000
Manager Information Security & Risk Management - Cloud Security Manager
Manager Information Security & Risk Management - Cloud Security Manager

enGen • United States

On-site
USD 129,000 - 215,000
Manager Information Security and Risk Management – Enterprise Data Security
Manager Information Security and Risk Management – Enterprise Data Security

Highmark Health • Hartford (CT)

On-site
USD 129,000 - 215,000
Senior Security Engineer – Secure SDLC
Senior Security Engineer – Secure SDLC

Highmark Health • Jackson (MS)

On-site
USD 103,000 - 165,000
Senior Security Engineer – Secure SDLC
Senior Security Engineer – Secure SDLC

Highmark Health • Nashville (TN)

On-site
USD 103,000 - 165,000
Information Security Engineer
Information Security Engineer

Clinical Reference Laboratory • Lenexa (KS)

On-site
USD 95,000 - 180,000
Medical, Dental, Vision
Life/AD&D
Section 125 FSA Plan
+4
Information Security Engineer
Information Security Engineer

International Executive Service Corps • Lenexa (KS), Northern (KY)

Hybrid
USD 95,000 - 180,000
Medical, Dental, Vision
Life/AD&D
Supplemental Life/AD&D
+6
Information Security Engineer
Information Security Engineer

SECURA Insurance Company • Neenah (WI), Northern (KY)

On-site
USD 110,000 - 150,000
Information Security Architect – Data Engineering & Security
Information Security Architect – Data Engineering & Security

Socket.dev • Pennsylvania

Hybrid
USD 103,000 - 165,000