Job Description
The Senior Information Security Engineer is a senior-level technical position responsible for leading complex security engineering initiatives and providing advanced expertise across multiple information security domains. The position operates with significant autonomy, serves as a technical authority, and is accountable for designing, implementing, and optimizing security solutions that address enterprise risk, regulatory requirements, and business objectives.
This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.
Qualifications
Bachelor's degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.
Master's degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.
One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.
Experience securing web applications, APIs, and internet-facing technologies.
Experience with Akamai solutions such as WAAP, Property Manager, Edge DNS, CDN, or similar web security platforms.
Strong understanding of web application security, API security, DNS, TLS/SSL, and threat mitigation techniques.
Experience with scripting, automation, or Infrastructure-as-Code technologies.
Strong analytical, communication, and problem-solving skills.
One or more of the following certifications (or equivalent) are required at the time of hire: CISSP, CISM, GSEC, OSCP.
Preferred Qualifications
Experience with Akamai Bot Manager, API Security, Account Protector, or SiteShield.
Experience with Azure, AWS, or Google Cloud security services.
Knowledge of OWASP Top 10, DDoS protection, and modern application security practices.