Amerisource Bergen

Engineer - Information Security

Amerisource Bergen$70K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science or related field.
  • 0-2 years of experience in information security.
  • Familiarity with IT risk management standards (SOX, ISO 27001/27002, etc.).
  • Knowledge of cybersecurity and cloud security principles.
  • Proficiency in programming languages like Python, JavaScript, and SQL.

Responsibilities

  • Support the company's information security infrastructure and compliance initiatives.
  • Assist with incident response and forensic investigations.
  • Conduct security assessments and contribute to identity management projects.
  • Develop security policies and procedures related to user access and incident response.
  • Resolve issues identified by security monitoring tools.
  • Gather metrics to evaluate the effectiveness of security controls.
  • Document findings and recommendations from security testing.

Benefits

  • Comprehensive medical, dental, and vision care.
  • Support for working families, including backup care and adoption assistance.
  • Flexible personal development resources and training programs.
  • Opportunities for mentorship and community engagement activities.
  • Inclusive culture that emphasizes holistic wellness and support.
Full Job Description
Job Details

Summary:

The Engineer - Information Security is responsible for supporting the planning, execution, and managing of multi-faceted projects related to risk management, mitigation and response, compliance, control assurance, and user awareness for all IT systems. This key role will support, monitor, and maintain information security infrastructure to protect the company's computer systems and networks from cyber-attacks, and help execute the information security program in compliance with policy and applicable regulations. They conduct security testing on simple to intermediate assets and support design, development, implementation and troubleshooting of various information system and cybersecurity software. They gather reports, metrics, and key performance indicators to measure and validate the effectiveness of existing security controls for team review. They analyze and report known and emerging threats to determine risks against asset creation, maintenance, and governance.

Primary Responsibilities:
  • Supports information security infrastructure to protect the company's computer systems and networks from cyber-attack and ensures information security compliances to all infrastructure
  • Provides support to security incidents and assists in forensics investigations
  • Assists in security assessments and attestations and works on security initiatives/issues for like identity management, access control, security clearance etc.
  • Provides assistance to ensure the company's infrastructure and information assets are protected and helps in developing security policies and procedures such as user log-on and authentication rules, security breach escalation procedures, security assessment procedures, and use of firewalls and encryption routines
  • Assist teams in resolving issues that are uncovered by security monitoring tools
  • Assists in the implementation of enterprise-wide security policies, procedures and standards to meet compliance responsibilities
  • Supports in creating technical/functional design documents, in building, maintaining, and implementing cybersecurity, data security, and cloud security solutions
  • Participates in gathering reports, metrics, and key performance indicators to measure and validate the effectiveness of existing security controls for team review
  • Conducts security testing on simple to intermediate assets as scoped by security assessment engagement
  • Assists in conducting risk assessments, creating security assessment reports with evidence of findings and discoveries, and escalating data security compromises
  • Assists in performing dynamic application security testing using both manual and automated testing tools
  • Gathers metrics, and KPIs of penetration testing program for management review
  • Documents targets, test plans, scenarios tested, findings, test evidences and recommendations in penetration test report
  • Conducts security testing validation for incidents as directed by management
  • Assists in research of vulnerabilities and provides status updates of issues to Lead Engineers
  • Assists project team in gathering cyber, data, mobile and cloud security business requirements, and aids in documenting project scope
  • Assists in the evaluation and recommendation for tools and solutions that provides cyber, data, mobile and cloud security functions
  • Supports in managing the computer security program and applying IT security principles, methods, and security products to protect and maintain the availability, integrity, confidentiality, and accountability of information system resources and information processed
  • Handles the complex and detailed technical work necessary to establish security systems such as firewalls, monitoring software, encryption technology, cloud security and threat hunting
  • Assists in planning, implementing, and managing the overall system security strategy, secure network, cloud, platform, and application solutions


Education, Experience & Skillset Requirements:

Education:
  • Bachelor's Degree in Computer Science, Information Technology or any other related discipline or equivalent related experience.


Preferred Certifications:
  • Azure Security Engineer Certification
  • Certified Cloud Security Professional (CCSP)
  • Certification in Information Security Strategy Management (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Security + Certification
  • Systems Security Certified Practitioner (SSCP)


Work Experience & Skillsets:
  • 0-2 years of directly-related or relevant experience, preferably in information security.
  • Problem Solving
  • Creativity & Innovation
  • Critical Thinking
  • Impact and Influencing
  • Multitasking
  • Prioritization and Organization


Technical Skills:
  • Network Solutions and Systems
  • Cybersecurity
  • Data Security
  • Cloud Security
  • Programming and Development
  • Information Security Strategy Standards (SOX, ISO 27001/27002, COBIT, ITIL, NIST, PCI)
  • IT Risk Management


Tools Knowledge:
  • Microsoft Office Suite
  • Programming and Development Languages - JavaScript, HTML/CSS, Python, SQL
  • Security Tools - SIEM, EDR, Email Security Gateway, SOAR, Firewall, Anti-virus, Firewalls, VPN IDS/IPS, AV, proxies, etc.


What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora

Full time

About Amerisource Bergen

AmerisourceBergen Corporation is a pharmaceutical distribution company headquartered in Chesterbrook, Pennsylvania. It was founded in 2001 through the merger of AmeriSource Health Corporation and Bergen Brunswig Corporation. The company distributes a wide range of pharmaceutical products, including brand-name and generic drugs, specialty drugs, and over-the-counter medications. AmerisourceBergen serves healthcare providers, including hospitals, pharmacies, and physician practices, as well as pharmaceutical manufacturers. The company is committed to sustainability and has implemented several initiatives to reduce its environmental impact.
Learn more about Amerisource Bergen
Size
21,000 employees
Industry

Similar Jobs

More Jobs at Amerisource Bergen

More Information Technology Jobs

Find similar Engineer - Information Security jobs: