Ensemble Health Partners

Cybersecurity Engineer II

Ensemble Health Partners$84K — $132K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Associate Degree in Cybersecurity, IT, Information Systems, Computer Science, or related field; or equivalent experience.
  • 3-5 years in cybersecurity, GRC, IT audit, or related areas.
  • Experience with cybersecurity risk management and compliance initiatives.
  • Familiarity with security frameworks and technical controls in enterprise settings.

Responsibilities

  • Own and manage the cybersecurity risk register, tracking and reporting risks.
  • Provide practical remediation guidance for business risks versus compliance gaps.
  • Support incident response from a GRC perspective, ensuring documentation and reporting.
  • Assist in investigating suspicious activities, recommending corrective actions.
  • Design and implement automated control monitoring processes to improve compliance efficiency.
  • Evaluate new technology initiatives against security frameworks before implementation.
  • Collaborate with engineering teams to address compliance gaps and improve security controls.

Benefits

  • Remote work flexibility with occasional travel for onsite requirements.
  • Professional development opportunities including relevant certifications and training.
  • Collaborative work environment with partnership across various departments.
  • Support for innovation, including the integration of AI to enhance processes.
Full Job Description

The Opportunity:

The Engineer II, Cybersecurity (GRC Engineer) supports Ensemble Health Partners' Governance, Risk, and Compliance (GRC) program by combining cybersecurity compliance expertise with hands-on technical execution. This role is responsible for the day-to-day management of the cybersecurity risk register, control automation initiatives, compliance monitoring, audit evidence collection, and administration of GRC platforms.

The GRC Engineer partners with security, engineering, and business stakeholders to maintain and strengthen the organization's compliance posture across multiple frameworks, support third-party risk management activities, and translate technical risk into actionable business recommendations. This position plays a critical role in reducing manual compliance activities through automation while ensuring audit readiness and continuous compliance across cloud, infrastructure, and enterprise technology environments.

Essential Job Functions:

  • Own and maintain the cybersecurity risk register, including identifying, assessing, tracking, quantifying, and reporting cybersecurity risks.
  • Differentiate meaningful business risks from theoretical compliance gaps and provide practical remediation recommendations.
  • Support incident response activities from a governance, risk, and compliance perspective, ensuring proper documentation, audit evidence collection, and reporting throughout the incident lifecycle.
  • Assist with investigations of suspected improper activity and recommend corrective and remediation actions.
  • Respond to GRC-related incidents and service requests within established service level agreements (SLAs).
  • Design, implement, and maintain automated control monitoring and evidence collection processes to reduce manual audit activities and support continuous compliance.
  • Participate in technology and IT initiatives to evaluate systems and processes against applicable regulatory and security frameworks before implementation.
  • Provide governance, risk, compliance, and control integration requirements for new projects and technologies.
  • Ensure infrastructure, cloud, and security control changes align with established security frameworks and CIS benchmarks.
  • Collaborate with engineering teams to identify and remediate control deficiencies and compliance gaps.
  • Identify opportunities to improve operational efficiencies through automation and process optimization.
  • Maintain compliance documentation, including risk assessments, control narratives, policies, procedures, and audit evidence repositories.
  • Partner with cybersecurity analysts, architects, engineers, and business stakeholders to ensure effective security controls are implemented across enterprise systems, cloud platforms, and IT environments.
  • Support regulatory, audit, and compliance initiatives while maintaining audit readiness across the organization.
  • Demonstrate customer obsession, innovation, and operational excellence in support of organizational goals and compliance objectives.

Employment Qualifications:

  • Associate Degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field; or equivalent combination of education and relevant experience.

Experience:

  • 3 to 5 years of experience in cybersecurity, information security, governance, risk management, compliance, IT audit, or related disciplines.
  • Experience supporting cybersecurity risk management programs, compliance initiatives, audits, and security control assessments.
  • Experience working with security frameworks, governance processes, and technical controls in enterprise environments.

Preferred Certifications:

One or more of the following certifications is preferred:

  • CompTIA Security+
  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • Other relevant cybersecurity, risk, audit, or compliance certifications may be considered.

Preferred Knowledge, Skill and Abilities:

  • Governance, Risk, and Compliance (GRC) program administration.
  • Cybersecurity risk assessment and risk register management.
  • Security control design, implementation, and monitoring.
  • Compliance framework management and audit support.
  • Control automation and continuous compliance monitoring.
  • Audit evidence collection and documentation management.
  • Third-party risk management and vendor assessments.
  • Security incident documentation and compliance reporting.
  • CIS Benchmarks and security configuration standards.
  • Collaboration across cybersecurity, engineering, infrastructure, cloud, and business teams.
  • Ability to communicate technical security risks to non-technical stakeholders.
  • Strong analytical, problem-solving, documentation, and process improvement skills.
  • Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
  • This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
  • This position pays between $84,000-132,300 based on experience

This posting addresses s state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the roles range.

#LI-LP1

#LI-Remote

Similar Jobs

More Jobs at Ensemble Health Partners

More Information Technology Jobs

Find similar Cybersecurity Engineer II jobs: