Ensemble Health Partners

Cybersecurity Engineer II

Ensemble Health Partners$84K — $132K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Associate Degree in Cybersecurity, Information Technology, or related field; equivalent experience may be accepted.
  • 3 to 5 years in cybersecurity or related disciplines.
  • Experience supporting cybersecurity risk management and compliance initiatives.
  • Familiarity with security frameworks and technical controls in enterprise settings.
  • Preferred certifications include CompTIA Security+, CRISC, or CISA.

Responsibilities

  • Maintain the cybersecurity risk register and report on risks.
  • Provide actionable remediation recommendations for compliance gaps.
  • Support incident response activities, ensuring proper documentation and reporting.
  • Assist in investigating suspected improper activities and suggest corrective actions.
  • Design and implement automated control monitoring processes to enhance compliance.
  • Evaluate systems against regulatory and security frameworks pre-implementation.
  • Collaborate with engineering teams to remediate compliance gaps and control deficiencies.

Benefits

  • Remote working flexibility with occasional travel requirements.
  • Engagement in innovative processes, including AI, for operational improvements.
  • Opportunities for professional development through relevant certifications.
Full Job Description

The Opportunity:

The Engineer II, Cybersecurity (GRC Engineer) supports Ensemble Health Partners' Governance, Risk, and Compliance (GRC) program by combining cybersecurity compliance expertise with hands-on technical execution. This role is responsible for the day-to-day management of the cybersecurity risk register, control automation initiatives, compliance monitoring, audit evidence collection, and administration of GRC platforms.

The GRC Engineer partners with security, engineering, and business stakeholders to maintain and strengthen the organization's compliance posture across multiple frameworks, support third-party risk management activities, and translate technical risk into actionable business recommendations. This position plays a critical role in reducing manual compliance activities through automation while ensuring audit readiness and continuous compliance across cloud, infrastructure, and enterprise technology environments.

Essential Job Functions:

  • Own and maintain the cybersecurity risk register, including identifying, assessing, tracking, quantifying, and reporting cybersecurity risks.
  • Differentiate meaningful business risks from theoretical compliance gaps and provide practical remediation recommendations.
  • Support incident response activities from a governance, risk, and compliance perspective, ensuring proper documentation, audit evidence collection, and reporting throughout the incident lifecycle.
  • Assist with investigations of suspected improper activity and recommend corrective and remediation actions.
  • Respond to GRC-related incidents and service requests within established service level agreements (SLAs).
  • Design, implement, and maintain automated control monitoring and evidence collection processes to reduce manual audit activities and support continuous compliance.
  • Participate in technology and IT initiatives to evaluate systems and processes against applicable regulatory and security frameworks before implementation.
  • Provide governance, risk, compliance, and control integration requirements for new projects and technologies.
  • Ensure infrastructure, cloud, and security control changes align with established security frameworks and CIS benchmarks.
  • Collaborate with engineering teams to identify and remediate control deficiencies and compliance gaps.
  • Identify opportunities to improve operational efficiencies through automation and process optimization.
  • Maintain compliance documentation, including risk assessments, control narratives, policies, procedures, and audit evidence repositories.
  • Partner with cybersecurity analysts, architects, engineers, and business stakeholders to ensure effective security controls are implemented across enterprise systems, cloud platforms, and IT environments.
  • Support regulatory, audit, and compliance initiatives while maintaining audit readiness across the organization.
  • Demonstrate customer obsession, innovation, and operational excellence in support of organizational goals and compliance objectives.

Employment Qualifications:

  • Associate Degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field; or equivalent combination of education and relevant experience.

Experience:

  • 3 to 5 years of experience in cybersecurity, information security, governance, risk management, compliance, IT audit, or related disciplines.
  • Experience supporting cybersecurity risk management programs, compliance initiatives, audits, and security control assessments.
  • Experience working with security frameworks, governance processes, and technical controls in enterprise environments.

Preferred Certifications:

One or more of the following certifications is preferred:

  • CompTIA Security+
  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • Other relevant cybersecurity, risk, audit, or compliance certifications may be considered.

Preferred Knowledge, Skill and Abilities:

  • Governance, Risk, and Compliance (GRC) program administration.
  • Cybersecurity risk assessment and risk register management.
  • Security control design, implementation, and monitoring.
  • Compliance framework management and audit support.
  • Control automation and continuous compliance monitoring.
  • Audit evidence collection and documentation management.
  • Third-party risk management and vendor assessments.
  • Security incident documentation and compliance reporting.
  • CIS Benchmarks and security configuration standards.
  • Collaboration across cybersecurity, engineering, infrastructure, cloud, and business teams.
  • Ability to communicate technical security risks to non-technical stakeholders.
  • Strong analytical, problem-solving, documentation, and process improvement skills.
  • Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
  • This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
  • This position pays between $84,000-132,300 based on experience

This posting addresses s state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role9s range.

#LI-LP1

#LI-Remote

Similar Jobs

More Jobs at Ensemble Health Partners

More Information Technology Jobs

Find similar Cybersecurity Engineer II jobs: