Search jobs > New York, NY > It security engineer

IT Security Engineer

NYC Health + Hospitals
Manhattan
$117K a year
Full-time

About NYC Health + Hospitals

MetroPlus Health provides the highest quality healthcare services to residents of Bronx, Brooklyn, Manhattan, Queens and Staten Island through a comprehensive list of products, including, but not limited to, New York State Medicaid Managed Care, Medicare, Child Health Plus, Exchange, Partnership in Care, MetroPlus Gold, Essential Plan, etc.

As a wholly-owned subsidiary of NYC Health + Hospitals, the largest public health system in the United States, MetroPlus Health 's network includes over 27,000 primary care providers, specialists and participating clinics.

For more than 30 years, MetroPlus Health has been committed to building strong relationships with its members and providers to enable New Yorkers to live their healthiest life.

Position Overview

The security engineer is responsible for implementing, maintaining, monitoring and managing secure solutions. The engineer delivers these solutions in accordance with the organization’s architectural designs, best practices, and regulatory or compliance requirements.

As risks change, the security engineer is responsible for recommending modifications and enhancements to ensure the organization is evolving with the threat landscape.

The security engineer is expected to contribute to the corporate security strategy with security leadership and other senior security staffers and technologists.

Recipients of the engineer’s implementations and management include IT infrastructure, application development, security operations, security audit and end users.

With an emphasis on securing systems, applications, third-party connections, service providers and ancillary systems, the security engineer is responsible for securing business-to-business initiatives, third-party relationships, outsourced solutions and vendors.

Considered a highly knowledgeable individual, the security engineer is expected to implement, monitor and manage secure solutions that address modern day issues.

Job Description

  • Handle day-to-day implementation, monitoring and operational support of security hardware, software, customer applications, and managed solutions.
  • Actively participate security team meetings that facilitate secure design.
  • Engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects.

Additionally, deliver projects on time and within budget.

  • Assist with incident response and system stability issues as they occur. This may include involvement outside of regular work hours, and responsiveness is expected.
  • Implement solutions observing compliance Health Information Portability and Accountability Act (HIPAA), Payment Card Industry (PCI), New York State Department of Financial Services Cybersecurity Requirements (23 NYCRR 500).
  • Work in tandem with architects, the security operations center (SOC), incident responders (in cases of anomalous activity and host compromise), and technology infrastructure and development team members.
  • Respond to and handle service and escalation tickets within SLA expectations.
  • Develop security test plans from architectural design. Identify deficiencies and make enhancements to ensure production is not impacted.
  • Participate in change project and change management meetings as required.
  • Research, validate and deploy solutions meeting security and business needs.
  • Follow security engineering fundamentals and processes as outlined in NIST 800-160

Influence the planning and execution of incident response and postmortem exercises, with a focus on creating measurable benchmarks to show progress (or deficiencies requiring additional attention).

  • Focus on driving security efficiencies, enabling security team members to work on more advanced tasks.
  • Conduct performance testing to stress the limitations of security solutions while at the same time ensuring business innovation and day-to-day processes are not negatively impacted.
  • Perform other duties as assigned

Minimum Qualifications

  • Bachelor’s degree in computer science, information assurance, Cybersecurity or related field, or equivalent.
  • 10+ years of related experience required.

Licensure and / or Certification Required

CISSP (preferred); CISM and / or SANS certification or Cisco-related certifications a plus.

Professional Competencies

  • Experience with : Microsoft Azure or Amazon Web Services (AWS). Vulnerability tools such as Rapid7, Qualys, Nessus, NMAP, Kismet, AirsnortSIEM platforms and technologies Private and Public PKI InfrastructureNetwork security management, design, and deployment.
  • DevOps background with experience in compliance obligations.
  • Experience with one or more of the following standard frameworks : ISO 27001, NIST, PCI Data Security Standard (PCI DSS), HIPAA, Health Information Technology for Economic and Clinical Health (HITECH) Act, Center for Internet Security (CIS) standards or Service Organization Controls (SOC) 2.
  • Working knowledge of Windows and Linux.
  • Familiarity with state privacy laws.
  • Ability to think strategically and tactically, with effective decision-making skills.
  • Highly trustworthy; leads by example.
  • Experience supporting and utilizing SIEM platforms.
  • Working technical knowledge of Advance Threat Protection tools such as Crowdstrike, Trellix, etc.
  • Next Generation Firewalls (NGFW), Software-Defined Wide Area Networking (SD-WAN), Advanced Threat Protection and Sandboxing solutions.
  • Detection / Prevention Systems : Anomaly-based, signature-based, and host-based.
  • DLP and Data in rest encryption.

L-Hybrid

30+ days ago
Related jobs
Promoted
IT Accel, Inc
New York, New York

In-depth knowledge of networking and security engineering and technical approaches in designing, building, testing, and debugging problems as required in large-scale enterprise and public cloud networks, including but not limited to routing and switching, routing protocols such as BGP, IPv6, DNS, fi...

Promoted
MetroPlus Health Plan
New York, New York

The security engineer is expected to contribute to the corporate security strategy with security leadership and other senior security staffers and technologists. Recipients of the engineer's implementations and management include IT infrastructure, application development, security operations, secur...

Promoted
IT Accel, Inc
New York, New York

As a Security DevOps Engineer, you will work in collaboration with cloud engineering, network, security and risk management to deliver bank secured cloud solutions that meet security policies and standards. Integration of security reporting with SIEM and incorporation with Enterprise Monitoring proc...

Promoted
Tech Valley Talent
New York, New York

Tech Valley Talent (TVT) has an opening for an IT Security and Compliance Engineer with our client in Albany, NY. We are seeking a meticulous professional with a deep understanding of corporate cybersecurity, audit compliance, and a strong focus on documentation and system integrity. IT Security & C...

Lincoln IT
New York, New York

We are currently seeking for a Network Security Engineer with a minimum of 3-5 years of hands-on experience. If you are interested in working for a growth-oriented company with a culture that exudes collaboration, integrity and a passion for technology, submit your resume today! ...

MetroPlusHealth
New York, New York

The security engineer is expected to contribute to the corporate security strategy with security leadership and other senior security staffers and technologists. Recipients of the engineer’s implementations and management include IT infrastructure, application development, security operations, secur...

Client Server
New York, New York

As a Graduate IT Security Operations Engineer your role will be split between working with clients to onboard them to the platform services and providing troubleshooting and technical support during this process whilst also developing your knowledge and skills around Security Operations, Threat Hunt...

Datadog
New York, New York

Experience with IT security services and applications for endpoint security, threat and anomalous detection, EDR, XDR. Enterprise IT Security Engineer. The Enterprise IT Security team is internally focused with the mission of securing the endpoints, applications, infrastructure, services and network...

Lincoln IT
New York, New York

We are currently seeking for a Network Security Engineer with a minimum of 3-5 years of hands-on experience. If you are interested in working for a growth-oriented company with a culture that exudes collaboration, integrity and a passion for technology, submit your resume today!....

NYC Health + Hospitals
New York, New York

The security engineer is expected to contribute to the corporate security strategy with security leadership and other senior security staffers and technologists. Recipients of the engineer’s implementations and management include IT infrastructure, application development, security operations, secur...