Mayo Clinic

Senior Information Security Engineer - IS Mod

Mayo Clinic Rochester, Minnesota, United States · $134K–$195K/yr

Hospitals and Health Care · 10,001+ employees

15 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

This role serves as the dedicated security design and oversight lead for Enterprise Network Segmentation within the Information Protection team. The engineer will translate asset criticality and threat modeling into control requirements while validating policy implementation and providing executive reporting on risk-reduction outcomes.

What they look for

Network Segmentation Information Security Risk Management Threat Modeling Network Security Security Architecture Incident Response Vulnerability Management Security Automation CISSP CISM GSEC OSCP

Requirements

Candidates must possess a Bachelor's degree and at least five years of relevant experience in information security or a related field. A professional certification such as CISSP, CISM, GSEC, or OSCP is required at the time of hire.

Benefits

Health Insurance

Full description

Responsibilities

This Senior Information Security Engineer serves as the dedicated security design and oversight lead for Enterprise Network Segmentation within the Information Protection – Network Security (IP-NS) team, ensuring segmentation controls are architected to appropriately align with the risk profile of the assets they protect across a large, regulated healthcare environment. A strong background in network segmentation is required, including proven experience designing risk-based segmentation strategies and defining policy intent for high-risk assets. This role is a critical technical authority who partners with Product Owners, the Network Security Architect, network engineering teams, and enterprise risk stakeholders to translate asset criticality and threat modeling into control requirements. It will also validate implemented policy meets design intent; provide continued oversight of segmentation controls and drift; contribute to Tier 3 incident response; and support executive reporting on risk-reduction outcomes aligned to security control objectives. Familiarity with security monitoring, incident response, vulnerability management, and security automation is highly desirable. Ability to operate effectively in a hybrid work environment, including participation in on-site work-related events, team collaboration sessions, and key organizational activities as required.

This is a hybrid position and the incumbent must live within 100 miles of a Mayo Clinic campus.

Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM.

Qualifications

Bachelor’s degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field. Master’s degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field. One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.

Similar roles