Compensation
Pay Range: $126,470 - $205,515/year
Benefits
- 100% tuition assistance
- Wellness initiatives
- Generous paid time off
- Paid parental leave
- Public Service Loan Forgiveness Program eligible employer
- Additional benefits and resources to support employees personally and professionally
Job Duties
To independently employ a broad knowledge of principles, practices, and procedures in a particular field of specialization to plan, design, develop and support systems and projects. To conduct research and analysis and present findings for review. To carry out complex assignments requiring the development of new or improved techniques and procedures. This position commits to fostering an environment of heightened security following Information Technology Security Policies and participating in security training, such as Health Insurance Portability & Accountability Act (HIPAA) and Family Education Rights and Privacy Act (FERPA), on an annual basis.
Qualifications
- Bachelor's degree in Information Systems or a related field and six (6) years of related experience required. Work experience may substitute for the education requirement.
- Certified Information Systems Security Professional (CISSP) certification preferred.
Preferred Certifications
- CISSP
- CCNA
- CEH, OSCP, GPEN
Preferred Healthcare Experience
- Network Security
- Knowledge of TCP/IP, HTTP, SSL, SSH and other networking protocols
- Managing network security tools such as IPS, Firewalls, SASE
- Reviewing firewall requests to determine risk
- Managing network configuration tools
- Cloud Security
- Data protection policies
- CASB Administration
- Baseline Configuration (Conditional Access policies, NIST, CIS Benchmarks, vendor best practices)
- Support the development and execution of enterprise-wide Cloud security program
- Application Security
- Managing application security scanners (DAST, SAST)
- Familiarity with software security frameworks (OWASP, NIST, BSIMM, OpenSAMM)
- Performing application security assessments, threat modeling and security testing
- Security Architecture and technical risk assessments
- Providing security configuration recommendations to network and infrastructure architects
- Developing security policies for cloud infrastructure
- Assisting with implementation of a cybersecurity framework (NIST Cyber Security Framework, CIS top 20)
- IoT risk management and maintaining passive scanners to discover IoT and biomedical devices
- Reference MDS2 documents from vendors to determine risk
- Providing remediation plans for biomedical device vulnerabilities
- Providing architecture guidance for implementation of medical devices
- Contribution to maintaining medical device asset inventory and security information collection