Mayo Clinic

Senior Information Security Engineer - IS Mod

Mayo Clinic Rochester, Minnesota, United States · $134K–$195K/yr

Hospitals and Health Care · 10,001+ employees

4 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

This role serves as the security design and oversight lead for Enterprise Network Segmentation, ensuring controls align with asset risk profiles. The engineer will partner with stakeholders to translate threat modeling into requirements and provide ongoing oversight of segmentation controls.

What they look for

Network Segmentation Information Security Risk Management Threat Modeling Security Architecture Incident Response Vulnerability Management Security Automation Network Engineering Policy Definition Compliance Security Monitoring

Requirements

Candidates must possess a bachelor's degree with at least five years of relevant experience or a master's degree with four years of experience. A professional certification such as CISSP, CISM, GSEC, or OSCP is required at the time of hire.

Benefits

Benefits Eligible

Full description

This Senior Information Security Engineer serves as the dedicated security design and oversight lead for Enterprise Network Segmentation within the Information Protection – Network Security (IP-NS) team, ensuring segmentation controls are architected to appropriately align with the risk profile of the assets they protect across a large, regulated healthcare environment. A strong background in network segmentation is required, including proven experience designing risk-based segmentation strategies and defining policy intent for high-risk assets. This role is a critical technical authority who partners with Product Owners, the Network Security Architect, network engineering teams, and enterprise risk stakeholders to translate asset criticality and threat modeling into control requirements. It will also validate implemented policy meets design intent; provide continued oversight of segmentation controls and drift; contribute to Tier 3 incident response; and support executive reporting on risk-reduction outcomes aligned to security control objectives. Familiarity with security monitoring, incident response, vulnerability management, and security automation is highly desirable. Ability to operate effectively in a hybrid work environment, including participation in on-site work-related events, team collaboration sessions, and key organizational activities as required.

This is a hybrid position and the incumbent must live within 100 miles of a Mayo Clinic campus.

Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM.

Qualifications

Bachelor’s degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

Master’s degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.

Similar roles