Cyber Security Engineer II

Greater Baltimore Medical Center (GBMC)

Towson (MD)

On-site

USD 80,000 - 143,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

GBMC HealthCare in Towson, MD seeks a Cyber Security Engineer II to design, implement, and monitor enterprise IT security measures protecting assets. This role leads department initiatives and supports threat mitigation, incident response, and forensic documentation.

Requirements include a Bachelor's degree in CS or related field and 2–5 years in security engineering, with experience in SIEM, vulnerability management, and security monitoring. On-site role with growth opportunities.

Qualifications

  • Bachelor's degree in Computer Science or related field as required.
  • 2–5 years as a system security engineer or similar experience.
  • Experience in computer/IT security, vulnerability analysis, and forensics.
  • Familiar with SIEM, vulnerability management and security monitoring.

Responsibilities

  • SIEM analysis and configuration including dashboards and alerts.
  • Lead incident response and root cause analysis with forensic documentation.
  • Manage access control, passwords, and accounts auditing.
  • Collect, preserve and present digital evidence for investigations.
  • Perform vulnerability assessment and remediation via security controls.
  • Assist policy administration and documentation of procedures.
  • Support patch management and SSL certificate tasks.
  • Deliver cybersecurity education and awareness briefings.
  • Stay current on cyber threats and industry best practices.

Skills

Cybersecurity principles
Incident response
Forensic analysis
Vulnerability management
SIEM monitoring
Network security
Windows Active Directory
Security policy enforcement

Education

Bachelor's degree in CS or related field
IT security/cybersecurity certification

Tools

Tenable
KnowBe4
Citrix NetScaler
BIOMED device patch mgmt
Forcepoint web filtering

Job description

Under limited supervision, the Cyber Security Engineer is primarily responsible for the enterprise IT security and threat mitigation framework, ensuring the safety of Information System assets. These responsibilities include: the engineering, implementation and monitoring of security measures for the protection of IT assets, networks and electronic protected data; the design, implementation and management of enterprise security architecture; the documentation of all relevant standard operating procedures and policies; the proper operation of all proactive threat mitigation measures; the remediation of identified vulnerabilities or security events; security incident response and root cause analysis with forensic documentation; security education and training; maintains current knowledge of relevant technology and industry best practice; participates in special projects and other duties as assigned. As a level II engineer, the position requires the building and integration of solutions and leading of department projects and initiatives as determined by Cyber leadership.

Education

Bachelor's degree or current high-level IT security / cybersecurity certification. Associate's degree or mid-level IT security / cybersecurity certification plus 2 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position.

Degree must be in Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Mathematics, Computer Forensics, Cyber Security, Information Technology, Healthcare IT, Information Assurance, Information Security, and Information Systems)

Relevant experience must be in computer or information systems design/development, programming, information/cyber/network security, vulnerability analysis, penetration testing, computer forensics, information assurance, and/or systems engineering.

Experience

2-5 years as a system security engineer or building and maintaining comprehensive IT security systems required.

Knowledge, Skills and Abilities
  • Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
  • Demonstrated ability to work independently or under only general direction
  • Demonstrate effective written and oral communication skills
  • Experience with EPIC EMR
  • Familiar with Vulnerability Management Process
  • Familiar with Security Monitoring & Event Management
  • Familiar with Infrastructure patching management process
  • Experience using Tenable scanning tool, KnowBe4, Citrix NetScaler
  • Familiar with BIOMED device and patch management
  • Familiar with Forcepoint web filtering
  • Familiar with Mobile Device Management
  • Proficiency with Active Directory and Microsoft Office Admin 36
  • Requires familiarity with domain structures, user authentication, and digital signatures
  • Requires understanding of FISMA policies and procedures, including FIPS 199, FIPS 200, NIST HIPAA, -and other applicable policies
  • Knowledge of network tools (e.g., ping, traceroute, nslookup)
  • Knowledge of encryption methodologies
Licensures, Certifications
  • Preference for certifications for EMR security, network security, cybersecurity or digital forensics from EC-Council, CompTIA, SANS
  • Industry cyber tool certifications considered if relevant to GBMC
Patient & Workplace Safety
  • Employee has knowledge and understanding of patient and workforce safety as it relates to job duties.
Patient Population
  • Demonstrates competency in the delivery of care and applies the knowledge to meet age-specific needs if applicable.
Principal Duties and Responsibilities

SIEM analysis and configuration

  • Building and applying infrastructure, policies, dashboards and alerting

Incident Response

  • Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities.

Systems Access

  • Responsible for access control, passwords, and account creation and administration and auditing

Digital Forensics

  • Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations

Vulnerability Assessment and Remediation

  • Vulnerability detection analysis and remediation through SIEM analysis
  • Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices
  • Evaluates vulnerabilities and assist with planning and implement remediation procedures

Policy Administration

  • Assist in the creation, auditing and maintenance of policies and procedures in relation to IT and cybersecurity

Patch Management

  • Assist in the detection, analysis and remediation of security vulnerabilities in system

Cybersecurity Education

  • Ability to prepare and deliver education and awareness briefings to ensure that systems, network, and data users are aware of and adhere to systems security policies and procedures

Knowledge of Cyber Threats/Global Trends

  • Remain current in knowledge of cyber threats and global trends - Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise
  • Develop content for cyber defense tools
  • Performs Computer Security Incident Response according to industry best practice and assist with RCA and forensic documentation
  • Assist with design, development and implementation of the Cybersecurity Framework policies and procedures
  • Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices
  • Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level
  • Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation
  • EMR Security Support
  • Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance
  • Assist with SSL certificate management
  • Assist with implementing periodic BCA and HA validation
  • Lead and/or participate in special projects as required
All roles must demonstrate GBMC Values:

Respect

I will treat everyone with courtesy. I will foster a healing environment.

  • Treats others with fairness, kindness, and respect for personal dignity and privacy
  • Listens and responds appropriately to others' needs, feelings, and capabilities

Excellence

I will strive for superior performance in every aspect of my work. I will recognize and celebrate the accomplishments of others.

  • Meets and/or exceeds customer expectations
  • Actively pursues learning and self-development
  • Pays attention to detail; follows through

Accountability

I will be professional in the way I act, look and speak. I will take ownership to solve problems.

  • Sets a positive, professional example for others
  • Takes ownership of problems and does what is needed to solve them
  • Appropriately plans and utilizes required resources for various job duties
  • Reports to work regularly and on time

Teamwork

I will be engaged and collaborative. I will keep people informed.

  • Works cooperatively and collaboratively with others for the success of the team
  • Addresses and resolves conflict in a positive way
  • Seeks out the ideas of others to reach the best solutions
  • Acknowledges and celebrates the contribution of others

Ethical Behavior

I will always act with honesty and integrity. I will protect the patient.

  • Demonstrates honesty, integrity and good judgment
  • Respects the cultural, psychosocial, and spiritual needs of patients/families/coworkers

Results

I will set goals and measure outcomes that support organizational goals. I will give and accept help to achieve goals.

  • Embraces change and improvement in the work environment
  • Continuously seeks to improve the quality of products/services
  • Displays flexibility in dealing with new situations or obstacles
  • Achieves results on time by focusing on priorities and manages time efficiently
Pay Range

$79,517.04 - $143,130.67

Final salary offer will be based on the candidate's qualifications, education, experience and alignment with our organizational needs.

Equal Employment Opportunity

GBMC HealthCare and its affiliates are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, mental or physical disability, genetic information, veteran status, or any other status protected by federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer II
Cyber Security Engineer II

Boston Medical Center • Towson (MD), Northern (KY)

Hybrid
USD 110,000 - 140,000
Cyber Security Engineer II
Cyber Security Engineer II

Boston Medical Center • United States

On-site
USD 95,000 - 130,000
Cyber Security Engineer II
Cyber Security Engineer II

Boston Medical Center • Baltimore (MD)

On-site
USD 95,000 - 130,000
Cyber Security Engineer II
Cyber Security Engineer II

gbmc • United States

On-site
USD 90,000 - 130,000
Patient Services Assistant - Perinatal Associates
Patient Services Assistant - Perinatal Associates

Greater Baltimore Medical Center (GBMC) • Towson (MD)

On-site
Manager Charge Description Master & Revenue
Manager Charge Description Master & Revenue

Greater Baltimore Medical Center (GBMC) • Baltimore (MD)

On-site
USD 89,000 - 162,000
Sr. Ambulatory Practice Manager
Sr. Ambulatory Practice Manager

GBMC HealthCare • Towson (MD)

On-site
USD 75,000 - 127,000
Senior Network Engineer
Senior Network Engineer

GBMC HealthCare • Baltimore (MD)

On-site
USD 79,000 - 144,000
Patient Services Assistant - Internal Medicine - Towson
Patient Services Assistant - Internal Medicine - Towson

Greater Baltimore Medical Center (GBMC) • Baltimore (MD)

On-site
Patient Services Assistant - Full-time - Pulmonology
Patient Services Assistant - Full-time - Pulmonology

GBMC HealthCare • Baltimore (MD)

On-site
USD 23,000 - 34,000