Turn this role into an interview — a resume and cover letter built around what this employer wants.
Mayo Clinic is seeking a Senior Information Security Engineer to lead complex security engineering initiatives with autonomy and authority. The role focuses on privileged access management design and implementation, including CyberArk and related tools, across a large healthcare environment.
Collaboration with infrastructure, apps, and clinical teams is essential to reduce risk while preserving patient care.
The Senior Information Security Engineer is a senior-level technical position responsible for leading complex security engineering initiatives and providing advanced expertise across multiple information security domains. The position operates with significant autonomy, serves as a technical authority, and is accountable for designing, implementing, and optimizing security solutions that address enterprise risk, regulatory requirements, and business objectives.
The ideal candidate serves as a technical architect for privileged access management, leading the design and implementation of PAM solutions across the enterprise and setting the technical direction others build against. This includes demonstrated experience administering and supporting CyberArk/Idira solutions in a large, complex environment, including Privilege Cloud, secrets management (Conjur, Secrets Hub, and Central Credential Provider), and Endpoint Privilege Manager, as well as hands-on work onboarding privileged accounts, designing safe and platform structures, and implementing credential rotation, session isolation, and session recording through CPM and PSM. Familiarity with the Microsoft administrative tier model and why Tier 0 and Tier 1 access warrants the strongest protections is expected. Experience integrating privileged access controls with identity governance, MFA, and SIEM platforms is strongly preferred, as is proficiency with scripting and automation (PowerShell, Python, and REST APIs) to streamline onboarding, reporting, and day-to-day operations.
Equally important is the ability to partner effectively with infrastructure, application, and clinical technology teams to reduce privileged access risk without disrupting patient care operations. Candidates should be able to explain privileged access requirements and associated risk clearly to both technical staff and leadership, and should bring experience supporting audit and regulatory requirements in healthcare or another highly regulated industry.
This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.