Sr. Security Engineer, Vulnerability Management at Highmark Health | ND, United States | Rezi

Sr. Security Engineer, Vulnerability Management at Highmark Health

Sr. Security Engineer, Vulnerability Management

Highmark Health · ND, United States

Today

Sr. Security Engineer, Vulnerability Management

Highmark Health · ND, United States

10 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Highmark Health is seeking a highly experienced and technically adept Cybersecurity Engineer specializing in Vulnerability Management and Secure Configuration Management. This role is responsible for developing, implementing, and enhancing enterprise-wide security controls to defend against threats and meet regulatory obligations. The lead Security Engineer will design, develop, and implement ISRM Infrastructure solutions, champion security baselines, and research cutting-edge security technologies. Automation, orchestration, and advanced analytics are key to improving vulnerability management and threat visibility. Strong scripting skills and system integration experience are essential. This position requires a U.S. Citizen.

Responsibilities

  • Lead teams in defining requirements, deliverables, and timeframes.
  • Escalate issues and make recommendations to resolve them.
  • Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
  • Develop and/or deliver technical training in complex technical areas.
  • Mentor less senior staff in their duties.
  • Complete project tasks for on-time, within budget, and scope delivery of ISRM Infrastructure projects.
  • Implement, monitor, configure, and maintain security systems.
  • Assure compliance with required standards, procedures, guidelines, and processes.
  • Other duties as assigned or requested.

Requirements

  • U.S. Citizen (due to contractual/access requirements)
  • 10+ years of expertise in cybersecurity
  • Experience with cloud security and infrastructure security
  • Experience with system integrations
  • 7 years with Information Security and Systems Analysis
  • 7 years with Information Security and/or Information Risk Management and/or Information Technology
  • 7 years with Operating Systems and Software Administration
  • 7 years developing, communicating, and presenting Information Security and Risk Management concepts to varying audiences
  • 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
  • 10 years of experience in Information Security (Preferred)
  • 5+ years of experience in Vulnerability and Secure Configuration Management engineering, including design, architecture, complex deployments and configuration, API integrations, high availability concepts, vendor communication (Preferred)
  • 3+ years of experience in adjacent Security domains, such as Threat Intel, Application Security, Offensive Security (Penetration Testing, Red/Purple Teaming) (Preferred)
  • Outstanding technical acumen across a broad range of cloud and on-premise technologies, architectures, applications and APIs (Preferred)
  • Outstanding verbal, written, presentation, facilitation, and interaction skills, including ability to effectively communicate technical issues and engineering concepts to technical and non-technical people (Preferred)
  • Demonstrated ability to initiate and guide enterprise technical products and services business cases to successful outcomes at scale (Preferred)
  • Demonstrated ability to navigate technical details for enterprise security services, and guide through solution development (Preferred)
  • Compliance with ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
  • Compliance with HIPAA and data security guidelines.

Skills

  • Vulnerability Management
  • Secure Configuration Management
  • ISRM Infrastructure solutions
  • Cloud security
  • Infrastructure security
  • Security baselines
  • Configuration management practices
  • Threat detection
  • Attack surface management
  • Automation
  • Orchestration
  • Advanced analytics
  • Scripting
  • System integrations
  • HITRUST CSF
  • NIST 800-83 cyber security framework
  • PCI
  • HIPAA
  • HITECH
  • COBIT
  • ISO 27001/2
  • ITIL 3
  • Secure SDLC best practices
  • Microsoft Apps and Suites
  • Windows server
  • SharePoint
  • Teamwork
  • Inter-personal skills

Location

  • Office-Based

Work Type

  • Office-Based

Experience Level

  • 10+ years of expertise
  • 7 years with Information Security and Systems Analysis
  • 7 years with Information Security and/or Information Risk Management and/or Information Technology
  • 7 years with Operating Systems and Software Administration
  • 7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
  • 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
  • 10 years of experience in Information Security (Preferred)
  • 5+ years of experience in Vulnerability and Secure Configuration Management engineering (Preferred)
  • 3+ years of experience in adjacent Security domains (Preferred)

Education Level

  • Bachelor's Degree in Computer Science, Information Systems, or closely related field
  • Master's Degree in Computer Science, Information Security or related field (Preferred)

Salary/Compensations

  • $102,700.00
  • $164,600.00

About the Company

  • Highmark Health

Equal Opportunity

  • Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
  • We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
  • For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
  • California Consumer Privacy Act Employees, Contractors, and Applicants Notice