Cyber Security Engineer II
GBMC HealthCare Adelaide, South Australia, Australia · $80K–$143K/yr
Hospitals and Health Care · 1,001-5,000 employees
About the role
The Cyber Security Engineer is responsible for enterprise IT security, threat mitigation, and the protection of information system assets. Key duties include designing security architecture, managing incident response, performing vulnerability assessments, and ensuring compliance with organizational policies.
What they look for
Requirements
Candidates must possess a bachelor's degree in a relevant field or an associate's degree with significant experience, along with 2-5 years of experience in system security. Proficiency in security tools, vulnerability management, and knowledge of regulatory frameworks like NIST and HIPAA is required.
Full description
Under limited supervision, the Cyber Security Engineer is primarily responsible for the enterprise IT security and threat mitigation framework, ensuring the safety of Information System assets. These responsibilities include: the engineering, implementation and monitoring of security measures for the protection of IT assets, networks and electronic protected data; the design, implementation and management of enterprise security architecture; the documentation of all relevant standard operating procedures and policies; the proper operation of all proactive threat mitigation measures; the remediation of identified vulnerabilities or security events; security incident response and root cause analysis with forensic documentation; security education and training; maintains current knowledge of relevant technology and industry best practice; participates in special projects and other duties as assigned. As a level II engineer, the position requires the building and integration of solutions and leading of department projects and initiatives as determined by Cyber leadership
Education
Bachelor's degree or current high-level IT security / cybersecurity certification. Associate's degree or mid-level IT security / cybersecurity certification plus 2 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position
Degree must be in Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Mathematics, Computer Forensics, Cyber Security, Information Technology, Healthcare IT, Information Assurance, Information Security, and Information Systems)
Relevant experience must be in computer or information systems design/development, programming, information/cyber/network security, vulnerability analysis, penetration testing, computer forensics, information assurance, and/or systems engineering
Experience
2-5 years as a system security engineer or building and maintaining comprehensive IT security systems required
Knowledge, Skills and Abilities
- Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Demonstrated ability to work independently or under only general direction
- Demonstrate effective written and oral communication skills
- Experience with EPIC EMR
- Familiar with Vulnerability Management Process
- Familiar with Security Monitoring & Event Management
- Familiar with Infrastructure patching management process
- Experience using Tenable scanning tool, KnowBe4, Citrix NetScaler
- Familiar with BIOMED device and patch management
- Familiar with Forcepoint web filtering
- Familiar with Mobile Device Management
- Proficiency with Active Directory and Microsoft Office Admin 36
- Requires familiarity with domain structures, user authentication, and digital signatures
- Requires understanding of FISMA policies and procedures, including FIPS 199, FIPS 200, NIST HIPAA, -and other applicable policies
- Knowledge of network tools (e.g., ping, traceroute, nslookup)
- Knowledge of encryption methodologies
Licensures, Certifications
- Preference for certifications for EMR security, network security, cybersecurity or digital forensics from EC-Council, CompTIA, SANS
- Industry cyber tool certifications considered if relevant to GBMC
Patient & Workplace Safety:
- Employee has knowledge and understanding of patient and workforce safety as it relates to job duties.
Patient Population:
- Demonstrates competency in the delivery of care and applies the knowledge to meet age-specific needs if applicable.
Principal Duties and Responsibilities
SIEM analysis and configuration
- Building and applying infrastructure, policies, dashboards and alerting
Incident Response
- Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities
Systems Access
- Responsible for access control, passwords, and account creation and administration and auditing
Digital Forensics
- Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations
Vulnerability Assessment and Remediation
- Vulnerability detection analysis and remediation through SIEM analysis
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices
- Evaluates vulnerabilities and assist with planning and implement remediation procedures
Policy Administration
- Assist in the creation, auditing and maintenance of policies and procedures in relation to IT and cybersecurity
Patch Management
- Assist in the detection, analysis and remediation of security vulnerabilities in system
Cybersecurity Education
- Ability to prepare and deliver education and awareness briefings to ensure that systems, network, and data users are aware of and adhere to systems security policies and procedures
Knowledge of Cyber Threats/Global Trends
- Remain current in knowledge of cyber threats and global trends - Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise
- Develop content for cyber defense tools
- Performs Computer Security Incident Response according to industry best practice and assist with RCA and forensic documentation
- Assist with design, development and implementation of the Cybersecurity Framework policies and procedures
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices
- Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level
- Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation
- EMR Security Support
- Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance
- Assist with SSL certificate management
- Assist with implementing periodic BCA and HA validation
- Lead and/or participate in special projects as required
All roles must demonstrate GBMC Values:
Respect
I will treat everyone with courtesy. I will foster a healing environment.
- Treats others with fairness, kindness, and respect for personal dignity and privacy
- Listens and responds appropriately to others’ needs, feelings, and capabilities
Excellence
I will strive for superior performance in every aspect of my work. I will recognize and celebrate the accomplishments of others.
- Meets and/or exceeds customer expectations
- Actively pursues learning and self-development
- Pays attention to detail; follows through
Accountability
I will be professional in the way I act, look and speak. I will take ownership to solve problems.
- Sets a positive, professional example for others
- Takes ownership of problems and does what is needed to solve them
- Appropriately plans and utilizes required resources for various job duties
- Reports to work regularly and on time
Teamwork
I will be engaged and collaborative. I will keep people informed.
- Works cooperatively and collaboratively with others for the success of the team
- Addresses and resolves conflict in a positive way
- Seeks out the ideas of others to reach the best solutions
- Acknowledges and celebrates the contribution of others
Ethical Behavior
I will always act with honesty and integrity. I will protect the patient.
- Demonstrates honesty, integrity and good judgment
- Respects the cultural, psychosocial, and spiritual needs of patients/families/coworkers
Results
I will set goals and measure outcomes that support organizational goals. I will give and accept help to achieve goals.
- Embraces change and improvement in the work environment
- Continuously seeks to improve the quality of products/services
- Displays flexibility in dealing with new situations or obstacles
- Achieves results on time by focusing on priorities and manages time efficiently
Pay Range
$79,517.04 - $143,130.67Final salary offer will be based on the candidate's qualifications, education, experience and alignment with our organizational needs.
Equal Employment Opportunity
GBMC HealthCare and its affiliates are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, mental or physical disability, genetic information, veteran status, or any other status protected by federal, state, or local law.
Similar roles
-
Information System Security Engineer III
TRISTAR INC Bloomington, Indiana, United States
-
Information System Security Engineer II
TRISTAR INC Bloomington, Indiana, United States
-
Network & Cybersecurity Engineer | C-sUAS
Sherpa 6 Alexandria, Virginia, United States · $165K–$200K/yr
-
Senior Cybersecurity Engineer
WSI (Warehouse Specialists, LLC) Town of Grand Chute, Wisconsin, United States
-
Associate Security Engineer
JPMorgan Chase & Co. Dublin, Leinster, Ireland
-
Cloud Security Engineer
Security Risk Advisors Philadelphia, Pennsylvania, United States · $90K–$130K/yr