Information Security Engineer Senior

Hennepin Healthcare
Minneapolis, Minnesota, US
Full-time

Find out more about this role by reading the information below, then apply to be considered.

Hennepin Healthcare is an integrated system of care that includes HCMC, a nationally recognized Level I Adult Trauma Center and Level I Pediatric Trauma Center and acute care hospital, as well as a clinic system with primary care clinics located in Minneapolis and across Hennepin County.

The comprehensive healthcare system includes a 473-bed academic medical center, a large outpatient Clinic & Specialty Center, and a network of clinics in the North Loop, Whittier, and East Lake Street neighborhoods of Minneapolis, and in the suburban communities of Brooklyn Park, Golden Valley, Richfield, and St.

Anthony Village. Hennepin Healthcare has a large psychiatric program, home care, and operates a research institute, philanthropic foundation, and Hennepin EMS.

The system is operated by Hennepin Healthcare System, Inc., a subsidiary corporation of Hennepin County.

Equal Employment Opportunities : We believe equity is essential for optimal health outcomes and are committed to achieve optimal health for all by actively eliminating barriers due to racism, poverty, gender identity, and other determinants of health.

We are committed to equitable care and working in an environment that celebrates, promotes, and protects diversity, equity, inclusion, and belonging.

We are committed to bringing in individuals with new cultural perspectives to assist in creating a more equitable healthcare organization.

SUMMARY :

We are currently seeking an Information Security Engineer Senior to join our Information Security team. This full-time role will work days.

Primarily remote work but requires ability to report to campus last minute as needed.

Purpose of this position : The Information Security Engineer Senior is responsible for protecting the organization's digital information and computer network through the design, planning, implementation, and continued support of security measures to protect the organization's computer networks and systems.

In addition to supporting the secure and compliant operations of the organization, the Information Security Senior Engineer will be expected to help identify, design, and implement new security controls based on needs and industry trends.

A senior member of the Information Security team, this position requires a mindset aimed at safeguarding the organization's network assets, digital files, user accounts, PHI, and other sensitive information, as well as a continuous focus on improving the organization’s security posture.

RESPONSIBILITIES :

  • Designs and implements Information Security controls and audits recommendations
  • Leads the identification and remediation of risks, threats, and vulnerabilities
  • Designs and conducts security and compliance assessments, including managing documentation and presentation of findings
  • Identifies opportunities to operationalize and automate elements of IT security and security operations
  • Leads efforts in the identification and remediation of risks, threats, and vulnerabilities
  • Responsible for maturing the vulnerability management program
  • Works independently to identify new vulnerabilities
  • Leads and participates in security incident investigations, which may include assisting with malware containment and incident response
  • Provides subject-matter expertise needed for the development and revision of existing and new IS&T security policies
  • Partners with other IT teams and asset owners to mitigate vulnerabilities
  • Stays abreast of the latest Information Security trends, threats, and vulnerabilities
  • Provides direct end-user support for Tier 2 and 3 incidents
  • Mentors and supports the development of members of the team
  • Participates in external audits and assessments by collecting and providing requested evidence
  • Actively participates in ongoing Risk Management efforts
  • Represents Information Security at meetings, committees, and task forces
  • Thinks outside the box and assists in creating multiple risk and compliance remediation options
  • Responsible for the development, promotion, and maintenance of Information Security owned applications, such as a password vault, phishing simulator, authentication systems, 3rd-party risk management tools, etc.
  • Leads and participates in IT projects as they relate to Information Security
  • Maintains the Information Security Controls Catalog
  • Leads / Facilitates 3rd party risk management assessments and ongoing vendor monitoring
  • Participates in the Cyber Emergency Response Team
  • Provides regular and off-hour on-call support as scheduled
  • Other duties as assigned

QUALIFICATIONS :

Minimum Qualifications :

  • 3-5 years working in technology / information security
  • Bachelor’s Degree
  • An approved equivalent combination of education and experience

Preferred Qualifications :

  • Experience in HealthCare environments
  • Experience with Biomedical devices and healthcare applications
  • Red-Team / Penetration Testing experience
  • Proficient in using Microsoft Office 365 tools
  • Using APIs and developing information security tools
  • Experience performing Azure / AWS Security Assessments

Knowledge / Skills / Abilities :

  • Critical thinking and problem-solving skills
  • Interpersonal skills and the ability to communicate with management, peers, and customers via reports, email, or verbal updates
  • Experience evaluating information security risks
  • Experience doing technical analysis of system vulnerabilities
  • Excellent customer focus, including escalation handling and resolution
  • Demonstrated ability to manage multiple priorities and deadlines
  • Adaptable to changing priorities, tasks, and work schedules to meet customer service standards
  • Effective written and verbal communication skills
  • Experience leading projects
  • Must be a self-starter, able to work under pressure, and be flexible in setting priorities
  • Demonstrated ability to learn new technologies and systems quickly and provide instruction on complex processes
  • Python and or PowerShell Scripting experience
  • Mobile Device Security / MDM Solutions Management

License / Certifications :

  • Certified CISSP or related security certification
  • Required to become certified with CISSP, or another security certification within 18 months of hire

You've made the right choice in considering Hennepin Healthcare for your employment. We offer a wealth of opportunities for individuals who want to make an impact in our patients' lives.

We are dedicated to providing Equal Employment Opportunities to both current and prospective employees. We are driven to connect talented individuals with life-changing career opportunities, enabling you to provide exceptional care without exception.

Thank you for considering Hennepin Healthcare as a future employer.

Please Note : Offers of employment from Hennepin Healthcare are conditional and contingent upon successful clearance of all background checks and pre-employment requirements.

Department : Information Security

Primary Location : MN-Minneapolis-Downtown Campus

Standard Hours / FTE Status : FTE 1.00 (80 hours per pay period)

Shift Detail : Day

Job Level : Staff

Employee Status : Regular

Eligible for Benefits : Yes

Union / Non Union : Non-Union

Job Posting : Apr-09-2024

J-18808-Ljbffr

3 days ago
Related jobs
Promoted
Wells Fargo
Minneapolis, Minnesota

Wells Fargo is seeking a Senior Information Security Engineer who will be responsible for designing, creating, and maintaining the security systems related to Certificate Authority and Validation Services technologies. Advanced Information Security technical skills and solid knowledge and understand...

Promoted
Wells Fargo
Minneapolis, Minnesota

Wells Fargo is seeking a motivated Lead Information Security Engineer to join an exciting, fast paced team working on cutting edge encryption, tokenization and key management technologies that are leveraged to protect information companywide. Work with partner engineering teams on identification and...

Promoted
SmartThings, Inc.
Minneapolis, Minnesota

Senior Information Security Engineer (Minneapolis, MN). As a Senior Information Security Engineer your role will support our ecosystem, its expansion, and growing list of new features to ensure the assets of SmartThings and our users are protected at all times. As a Senior Information Security Engin...

Promoted
Rvohealth
Minneapolis, Minnesota

The Early Careers Rotational Program is an 18–month program for graduating seniors and is divided up into two 9–month rotations within one of RVO Health's core functions,. We meet people where they are in their personal health journeys and connect them with both the information and the care they nee...

Promoted
zoom
Saint Paul, Minnesota

SIEM Architect, Security Data Engineer, Security Engineer, Technical Program Manager) or a combination of software engineering and cybersecurity. As a Senior Security Data Engineer, you will be leading an effort to enhance Zoom’s security telemetry, logging, and data platform. Collaborate with engin...

WELLS FARGO BANK
Minneapolis, Minnesota

Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards. Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security ...

Olympus Corporation of the Americas
Brooklyn Park, Minnesota

The Senior Product Security Operations Engineer within the Digital Unit will assist with monitoring, detecting, and resolving security issues across our product portfolio, infrastructure, cloud environment, and others. Minimum of 5 years’ experience working as a Software Security Engineer or Securit...

WELLS FARGO BANK
Minneapolis, Minnesota

Wells Fargo is seeking a Senior Information Security Engineer who will be responsible for designing, creating, and maintaining the security systems related to Certificate Authority and Validation Services technologies. Advanced Information Security technical skills and solid knowledge and understand...

Deluxe
Minneapolis, Minnesota

The Senior Information Security Risk Analyst leads enterprise information security training and awareness activities, including secure development training, compliance & ethics training, and phishing simulations. Launch your cybersecurity career as an Information Security Risk Analyst at Deluxe. Inf...

WELLS FARGO BANK
Minneapolis, Minnesota

Wells Fargo is seeking a Lead Information Security Engineer in Technology as a part of Chief Technology Office. Provide security consulting on large projects for internal clients to ensure conformity with corporate information, security policy, and standards. Utilize subject matter knowledge in indu...