Cyber Security Engineer II
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security
Under limited supervision, the Cyber Security Engineer is primarily responsible for the enterprise IT security and threat mitigation framework, ensuring the safety of Information System assets. These responsibilities include: the engineering, implementation and monitoring of security measures for the protection of IT assets, networks and electronic protected data; the design, implementation and management of enterprise security architecture; the documentation of all relevant standard operating procedures and policies;
the proper operation of all proactive threat mitigation measures; the remediation of identified vulnerabilities or security events; security incident response and root cause analysis with forensic documentation; security education and training; maintains current knowledge of relevant technology and industry best practice; participates in special projects and other duties as assigned. As a level II engineer, the position requires the building and integration of solutions and leading of department projects and initiatives as determined by Cyber leadership
Bachelor's degree or current high-level IT security / cybersecurity certification. Associate's degree or mid-level IT security / cybersecurity certification plus 2 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position
Degree must be in Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Mathematics, Computer Forensics, Cyber Security, Information Technology, Healthcare IT, Information Assurance, Information Security, and Information Systems)
Relevant experience must be in computer or information systems design/development, programming, information/cyber/network security, vulnerability analysis, penetration testing, computer forensics, information assurance, and/or systems engineering
Experience2-5 years as a system security engineer or building and maintaining comprehensive IT security systems required
Knowledge,Skills And Abilities
- Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Demonstrated ability to work independently or under only general direction
- Demonstrate effective written and oral communication skills
- Experience with EPIC EMR
- Familiar with Vulnerability Management Process
- Familiar with Security Monitoring & Event Management
- Familiar with Infrastructure patching management process
- Experience using Tenable scanning tool, KnowBe4, Citrix Net Scaler
- Familiar with BIOMED device and patch management
- Familiar with Forcepoint web filtering
- Familiar with Mobile Device Management
- Proficiency with Active Directory and Microsoft Office Admin 36
- Requires familiarity with domain structures, user authentication, and digital signatures
- Requires understanding of FISMA policies and procedures, including FIPS 199, FIPS 200, NIST HIPAA,
-and other applicable policies - Knowledge of network tools (e.g., ping, trace route, nslookup)
- Knowledge of encryption methodologies
- Preference for certifications for EMR security, network security, cybersecurity or digital forensics from EC-Council, CompTIA, SANS
- Industry cyber tool certifications considered if relevant to GBMC
- Employee has knowledge and understanding of patient and workforce safety as it relates to job duties.
- Demonstrates competency in the delivery of care and applies the knowledge to meet age-specific needs if applicable.
- Building and applying infrastructure, policies, dashboards and alerting
- Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities
- Responsible for access control, passwords, and account creation and administration and auditing
- Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations
- Vulnerability…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).