IT Security Engineer

Stanford Health Care

$116K — $153K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Engineering, Computer Science, or a related field
  • 3+ years of hands-on experience in security engineering
  • Proficient in TCP/IP, DHCP, DNS, and directory services
  • Experienced with IDS/IPS, Endpoint protection, and other network security technologies
  • Knowledgeable in multiple operating systems including Unix, Linux, Apple, and Windows
  • Strong understanding of network security architecture and Defense-in-Depth principles
  • Possession of CISSP or equivalent security certification (CISM, GIAC)

Responsibilities

  • Conduct research and analysis to identify threats to SHC networks and systems
  • Analyze network traffic for anomalous activity and potential security threats
  • Establish alerting thresholds and analyze alerts from enterprise sources
  • Validate IDS alerts against network traffic to eliminate false positives
  • Perform regular vulnerability scans and malware assessments
  • Assist in incident triage to evaluate security incidents' scope and impact
  • Provide forensic analysis on vulnerabilities and recommend remediation strategies

Benefits

  • Comprehensive health coverage options
  • 401(k) retirement savings plan with employer matching
  • Generous paid time off and holiday scheduling
  • Professional development and continuing education opportunities
  • Collaborative work environment with innovative technology
Full Job Description
A Brief Overview
The IT Security Engineer is responsible for analyzing and correlating information collected from a variety of sources to identify, investigate, and report vulnerabilities in the SHC environment. IT Security Engineers will additionally be responsible for assisting with resolution of identified security incidents, and coordinating with infrastructure and applications teams as required to achieve incident resolution.

Locations
Stanford Health Care

What you will do
  • Conduct research, analysis, and correlation across a wide variety of source data to identify and prevent compromise of SHC networks, host systems, and data, including:
  • Analyze network traffic and host data to identify anomalous activity and potential threats to SHC resources;
  • Establish alerting thresholds/triggers, analyze alerts from various sources within the enterprise, and determine possible causes and effects on SHC systems and data;
  • Validate intrusion detection system (IDS) alerts against network traffic and host data sources using to root out false positives;
  • Perform regular and ad-hoc vulnerability and malware scans to identify unauthorized access to SHC data systems and malicious code activity such as trojans, root kits, backdoors, bots, or malware.
  • Provide engineering support for security incidents and threats in the SHC environment, including:
  • Perform initial incident triage, determining scope, urgency, and potential impact of security incidents;
  • Respond to and resolve identified security incidents, maintaining contact with end users and the SHC service desk through resolution;
  • Perform forensic analysis on known security vulnerabilities and recommend risk mitigation procedures.
  • Perform trend analysis and reporting on security incidents, identify technical and procedural findings, and recommend remediation strategies or technical solutions.
  • Participate in IT security audits as required.


Education Qualifications
  • Bachelor's degree in Engineering, Computers Science, or related field from an accredited college or university


Experience Qualifications
  • Three (3) years of progressively responsible and directly related work experience


Required Knowledge, Skills and Abilities
  • Strong knowledge and experience with tools, platforms, and protocols such as:
  • TCP/IP, Dynamic Host Configuration Protocol (DHCP), Domain Name System (DNS), and directory services
  • Network security defense technologies such as IDS, IPS, Endpoint protection, DLP, NAC, Proxy, and WAF
  • Unix, Linux, Apple, and Windows operating systems
  • SCCM/SCOM
  • Mobile platforms
  • Strong knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of Defense-in-Depth)
  • Ability to identify systemic security issues based on analysis of vulnerability and configuration data


Licenses and Certifications
  • CISSP - Cert Information Systems Security Prof
  • CISM, OR GIAC


Base Pay Scale: Generally starting at $55.85 - $74.00 per hour

The salary of the finalist selected for this role will be set based on a variety of factors, including but not limited to, internal equity, experience, education, specialty and training. This pay scale is not a promise of a particular wage.

Similar Jobs

More Jobs at Stanford Health Care

More Healthcare Jobs

Find similar IT Security Engineer jobs: