Mayo Clinic

SR Information Security Engineer - IS-Mod

Mayo Clinic • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, computer science, information systems, engineering, or a related field plus 5 years of relevant experience.
  • Master's degree in applicable field plus 4 years of relevant experience preferred.
  • Experience with CyberArk/Idira solutions in large environments, including Privilege Cloud and secrets management.
  • Familiarity with Microsoft administrative tier model, especially Tier 0 and Tier 1 access.
  • Proficiency in scripting and automation (PowerShell, Python, REST APIs) for operational efficiency.
  • One or more relevant certifications required: CISSP, CISM, GSEC, OSCP.

Responsibilities

  • Lead complex security engineering initiatives with significant autonomy.
  • Design, implement, and optimize security solutions to mitigate enterprise risk.
  • Serve as a technical authority for privileged access management (PAM) solutions.
  • Onboard privileged accounts and implement credential rotation and session isolation.
  • Collaborate with infrastructure, application, and clinical technology teams to manage privileged access risk.
  • Communicate privileged access requirements and risks to technical staff and leadership.
  • Support audit and regulatory compliance in healthcare or regulated industries.

Benefits

  • Opportunity to work in a senior-level technical position with significant autonomy.
  • Engagement in complex security engineering initiatives that impact enterprise risk.
  • Collaboration with diverse teams across the organization.
  • Exposure to advanced security technologies and practices in a healthcare setting.
Full Job Description
Job Description

The Senior Information Security Engineer is a senior-level technical position responsible for leading complex security engineering initiatives and providing advanced expertise across multiple information security domains. The position operates with significant autonomy, serves as a technical authority, and is accountable for designing, implementing, and optimizing security solutions that address enterprise risk, regulatory requirements, and business objectives.

The ideal candidate serves as a technical architect for privileged access management, leading the design and implementation of PAM solutions across the enterprise and setting the technical direction others build against. This includes demonstrated experience administering and supporting CyberArk/Idira solutions in a large, complex environment, including Privilege Cloud, secrets management (Conjur, Secrets Hub, and Central Credential Provider), and Endpoint Privilege Manager, as well as hands-on work onboarding privileged accounts, designing safe and platform structures, and implementing credential rotation, session isolation, and session recording through CPM and PSM. Familiarity with the Microsoft administrative tier model and why Tier 0 and Tier 1 access warrants the strongest protections is expected. Experience integrating privileged access controls with identity governance, MFA, and SIEM platforms is strongly preferred, as is proficiency with scripting and automation (PowerShell, Python, and REST APIs) to streamline onboarding, reporting, and day-to-day operations.

Equally important is the ability to partner effectively with infrastructure, application, and clinical technology teams to reduce privileged access risk without disrupting patient care operations. Candidates should be able to explain privileged access requirements and associated risk clearly to both technical staff and leadership, and should bring experience supporting audit and regulatory requirements in healthcare or another highly regulated industry.

This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.

Qualifications

Bachelor's degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

Master's degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.

About Mayo Clinic

Mayo Clinic is a nonprofit academic medical center based in Rochester, Minnesota, focused on integrated clinical practice, education, and research. It employs more than 4,500 physicians and scientists and 58,400 administrative and allied health staff. The practice specializes in treating difficult cases through tertiary care and destination medicine. It is home to the Mayo Clinic College of Medicine and Science, which includes a medical school and research programs. Mayo Clinic has a large presence in three U.S. metropolitan areas: Rochester, Minnesota; Jacksonville, Florida; and Phoenix, Arizona. It also has several affiliated hospitals and clinics elsewhere in the United States and around the world.
Learn more about Mayo Clinic
Size
74,000 employees
Industry
Founded
1919

Similar Jobs

More Jobs at Mayo Clinic

More Information Technology Jobs

Find similar SR Information Security Engineer - IS-Mod jobs: