Job Type
Full-time
Description
Information Security Engineers are responsible for the day-to-day access to and security of system resources. This includes identifying, implementing, and maintaining appropriate controls to provide confidentiality, integrity, and availability (C-I-A) to the system resources facilitating the routine functions of the business. This role coordinates closely with other groups on a wide range of security projects. As a member of our Cloud Services team, your job would involve:
- Ensuring corporate data privacy and security
- Evaluating output from various security monitoring tools
- Coordinating with monitoring group to prioritize action
- Planning and implementing remediation and/or mitigating controls
- Carrying out security based risk assessments and advising on any potential risk acceptance
- Planning and implementing remediation and/or mitigating controls
- Implementing controls and working with other teams to ensure appropriate access to corporate assets
- Maintaining knowledge of security/regulatory concepts such as least privilege
- Providing security feedback and expertise
- Implementing any controls needed to end the current incident and protect against future occurrences
- Designing, implementing, and maintaining secure system configurations
- Assisting in the security evaluation of system design and implementation
- Communicating and coordinating with other security and IT groups.
Requirements
- Bachelor's or associate degree preferred, and/or 2-3 years applicable work or military experience
- Security specific certifications preferred, but not required:
- Certified Information Systems Security Professional, (ISC)² - CISSP
- Certified Information Systems Auditor, ISACA - CISA
- Global Information Assurance Certifications, GIAC - GISF, GCED, GNFA, etc.
- Certified Cloud Security Professional, (ISC)² - CCSP
- Certificate of Cloud Security Knowledge, CSA - CCSK
- Certified Cloud Security Specialist, GSTF - CCSS
- Knowledge and awareness of applicable information security standards, guidelines, regulations, and industry standard best practices:
- Information Security Management (ISO 27001/27002/27017)
- Security Operations Center (SOC I & II)
- Quality Management (ISO 9001)
- National Institute of Standards & Technology (NIST)
- Scripting experience (especially in IT operations)
- Multiple years of experience or education dealing with information security tools and techniques
- Ability to identify and work with application and system experts to help identify and remediate vulnerabilities
- Ability to work with various monitoring resources to understand current security threats and engineer solutions
- Advanced knowledge of information security principles and practices, including any of the following: security risk assessment standards, risk assessment methodologies, and vulnerability assessment
- Strong analytical, reasoning, and problem solving skills and technical aptitude
- Exceptional written and verbal communication skills
- Ability to work well with stakeholders and interested parties of varying position and tenure
- Ability to use discretion when handling confidential information
- Ability to learn new tools and technologies quickly.
Hiring salary range: $66,000- $105,000 per year.
Actual salary will be determined based on an individual's skills, experience, education, and other job-related factors permitted by law.
MEDITECH offers competitive employee
benefits including but not limited to health, dental, & vision insurance; profit sharing trust and 401(k); tuition reimbursement, generous paid time off, sick days, personal time, and paid holidays.
This is a
hybrid role which includes a blend of in-office and remote work as designated by the management team.