CommonSpirit Health

IT Cybersecurity Engineer - WebAppSec PCI

CommonSpirit Health$90K — $120K *
US-AnywhereRemote
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree or equivalent 4 years of experience
  • 2-3 years in application security testing or related activities
  • Experience with multiple target types for security assessments
  • Knowledge of PCI compliance standards and practices
  • Familiarity with web application security frameworks and methodologies

Responsibilities

  • Designs and implements discovery and assessment solutions for existing architectures
  • Supports engagements across various IT operations and business function owners
  • Acts as a security advocate for adherence to security policies and best practices
  • Manages workload efficiently and documents task completion
  • Pursues continuing education to stay updated on security best practices
  • Participates in knowledge management and collaboration efforts for the IT Security team
  • Communicates technical and security information effectively across the organization
  • Assists management in identifying knowledge and technology gaps
  • Supports web application security for PCI compliance and engages in remediation efforts
  • Partners with development teams to analyze web application security concerns
  • Performs system and application vulnerability reviews and supports risk management processes
  • Proactively identifies and escalates configuration issues, leading remediation efforts
  • Serves as a subject matter expert for web application security platforms.

Benefits

  • Opportunities for continuing education and professional growth
  • Collaborative environment within the IT Security team
  • Support for compliance with PCI standards and practices
  • Engagement in a variety of projects within the cybersecurity domain
  • Access to knowledge management and collaboration systems for skills enhancement
Full Job Description
Job Summary and Responsibilities Job Summary

The Cybersecurity EngineerWebAppSec position supports the Attack Surface Management (ASM) program for CommonSpirit Health.  This program provides web application security services, performs technical security assessment services, maintains WebAppSec security systems and workflows, and provides engagement and reporting services on specific and systemic security vulnerability and configuration issues for the enterprise.

The Cybersecurity Engineer will report to the Manager, WebAppSec, as part of the overall Cyber Vigilance and Defence group, focused on identifying, protecting, responding and containing threats and vulnerabilities to the overall CommonSpirit organization.

The Cybersecurity Engineer performs web application security services related to PCI compliance such as payment scripts monitoring, web application security scans, activities to identify CommonSpirit systems, applications, services, and repositories available on the Internet, assesses system and application weaknesses, misconfigurations, or other flaws in operating systems, network devices, web applications, or other technologies that could lead to security compromises, as well as gaps in current control states.  Monitors the threat and vulnerability landscape and changing business requirements to identify functional, technological and/or control solutions.  Develops, integrates, and maintains WebAppSec tools and platforms.  Integrates all cybersecurity solutions in an optimal manner to best discover and protect the organization from cyber threats and exposures.    

May drive one or more projects, acts as a subject matter expert (SME) for one or more discovery or scanning methods, tools, and target environments.  Develops and maintains operational security processes, and assists in the remediation of the identified issues.  May act as team-lead for other security personnel.  

 

Job Responsibilities
  • Designs, develops, and implements new discovery and assessment solutions to integrate into and test within existing or newly defined architectures.
  • Provide support on team related engagements with Security Engineering, Identity Management Engineering, Security Architecture, SOC, Network Engineering, Clinical Engineering, Systems Engineering, Application Development, and/or other IT Operations and business function owners.
  • Act as a security advocate for IT Operations team’s adherence to CommonSpirit Health policies, security standards and requirements, and industry best practices.
  • Manage workload, prioritizing tasks and documenting time, and other duties as directed by management.
  • Pursue continuing education to grow and maintain knowledge of best practices, compliance requirements, attack surface discovery methodologies, vulnerabilities, threats and trends in information security, translating into operational action items, policies, procedures, standards and guidelines as part of the IT Security team.
  • Participate in the collection and documentation of departmental knowledge artifacts, participant in the development and population of knowledge management and collaboration systems for the IT Security team.
  • Communicates security and technical information to team members and across the IT Organization.
  • Assists Management in identifying knowledge, process, and technology gaps.
  • Provide service line support for web application security for PCI compliance.  Create and manage crawling / scanning assessments and workflows, implement and manage script monitoring technologies and services, including alerting and remediation engagement (PCI DSS v4 6.4.3 and 11.6.1), in order to safeguard payment processing applications against fraud and breaches.
  • Partner with web application development groups to analyze and remediate security concerns within payment pages.
  • Provide service line support for dynamic application security testing services and remediation engagement. 
  • Perform reviews and analysis of system and applications vulnerabilities and configurations, and support Security technical Risk Management processes.
  • Proactively identify, engage on, and escalate vulnerability and configuration issues, either system/application specific or systemic.  Lead specific engagement and remediation efforts.
  • Designs, develops, configures, and implements solutions to resolve intermediate technical and business issues related to information security.
  • Reviews and consults on security of technology solutions to resolve intermediate to high technical and business issues.
  • Provides support and works on multiple functions of intermediate to high complexity. 
  • Serves as SME for one or more web application security platforms and services.
Job Requirements

Required

  • Bachelor's Degree or 4 years of equivalent experience may be considered in lieu of Bachelor's degree.
  • 2-3 years job related experience required, specifically conducting application security testing or related activity on a multiple set of target types.

Preferred

  • Bachelors Other In a related field and 3-4 year’s experience, upon hire

About CommonSpirit Health

CommonSpirit is a nonprofit health care center. They offer community health programs, research programs, virtual care services, and home health programs that address the root causes of poor health, such as access to care, affordable housing, neighborhoods, and a healthy environment.

CommonSpirit Health Careers

Join the dedicated team at CommonSpirit Health, a leader in healthcare innovation and community wellness. CommonSpirit Health offers a range of job opportunities that empower professionals to grow their careers in a supportive and diverse environment.

Explore Career Opportunities

CommonSpirit Health is actively hiring and offers a variety of positions that cater to different skills and career aspirations. From clinical roles to administrative positions, the company provides a platform for growth and professional development.

Experience a Culture of Care and Innovation

At CommonSpirit Health, the culture is grounded in diversity, leadership, and innovation. The team is committed to fostering an inclusive environment where every member’s contribution is valued. CommonSpirit Health leads with a spirit of compassion and a commitment to excellence in healthcare.

Join a Team That Values Diversity and Leadership

CommonSpirit Health believes in the power of diversity and leadership to drive innovation. The company invests in diversity training and leadership development programs, ensuring that all team members are equipped to lead with integrity and empathy.

Internship and Employment Opportunities

For those starting their career, CommonSpirit Health offers internship programs that provide hands-on experience in the healthcare industry. These internships are designed to develop essential skills and offer insights into various aspects of healthcare operations.

Benefits and Growth

Employees at CommonSpirit Health enjoy a comprehensive benefits package that supports both their professional and personal lives. The company is committed to the career growth of its employees, offering numerous opportunities for advancement and professional development.

Networking and Professional Development

CommonSpirit Health encourages networking and continuous learning. Employees have access to a wide range of professional development courses and are encouraged to connect with peers and leaders within the industry to enhance their career prospects.

Applying for a Position

To apply for a position at CommonSpirit Health, candidates should prepare their resume to highlight relevant experience and skills. The hiring process may include an interview to assess compatibility with the company’s values and culture. Interested candidates can explore job listings and submit applications through the CommonSpirit Health Careers portal.

Stay Connected with CommonSpirit Health Jobs

Keep up to date with new job opportunities and company news by subscribing to job alert emails from CommonSpirit Health. Tailor the subscription to receive updates that match specific career interests and preferences.

Explore CommonSpirit Health Careers

Discover the rewarding career opportunities at CommonSpirit Health. With a commitment to community health, innovation, and compassionate care, CommonSpirit Health is an ideal place to advance a career in healthcare. Search open positions that match skills and interests and join a team that’s making a difference.

SEARCH COMMONSPIRIT HEALTH JOBS

Read Careers Blog

Stay informed with career tips, insider perspectives, and industry-leading insights from CommonSpirit Health. Use this valuable information to enhance career growth and stay ahead in the healthcare industry.

READ CAREERS BLOG

Job Alert Emails

Personalize the subscription to receive job alerts, latest news, and insider tips tailored to preferences. Explore the exciting and rewarding opportunities that await at CommonSpirit Health.
Learn more about CommonSpirit Health
Size
10,001 employees
Industry

Similar Jobs

More Jobs at CommonSpirit Health

More Information Technology Jobs

Find similar IT Cybersecurity Engineer - WebAppSec PCI jobs: