HTM Information Security Engineer
Listed on 2026-06-15
-
IT/Tech
Cybersecurity, Information Security
Benefits Highlights
- Medical:
Multiple plan options. - Dental:
Delta Dental or reimbursement account for flexible coverage. - Vision:
Affordable plan with national network. - Pre‑Tax Savings: HSA and FSAs for eligible expenses.
- Retirement:
Competitive retirement package to secure your future.
This is a hybrid position and must be located within 100 miles of a Mayo Clinic campus for occasional on‑site expectations based on business needs.
The HTM Cyber team is seeking a technically strong Information Security Engineer to support the team’s medical/facility device cybersecurity operations across medical, research, laboratory, and facilities environments. Unlike a traditional IT security function, this role is focused on identifying, assessing, and mitigating cybersecurity risks and vulnerabilities directly on connected medical and operational technology equipment.
This position will work closely with the Senior Engineer and provide practical technical support across core operational areas, including Associate Engineer support, Security Lifecycle Profiles, secure baseline remediation, vulnerability management, remote access review, vulnerability scanning, metrics, and process improvement.
The ideal candidate brings hands‑on biomedical equipment or clinical engineering experience, a solid understanding of IT networking, and a working knowledge of cybersecurity principles. This individual should be able to bridge HTM field operations, vendor support, IT, and Information Security by helping troubleshoot connected device issues, translating security requirements into practical device‑level actions, documenting repeatable remediation processes, and supporting risk‑based decisions that protect patient care while reducing risk across complex healthcare technology environments.
The Information Security Engineer position requires an information security professional who is results oriented, multi‑disciplined, and comfortable in implementing system security solutions in multi‑vendor environments. The incumbent also assists system users with information systems security matters, undertakes complex projects requiring additional specialized technical knowledge, and acts as an information security liaison to various business units.
QualificationsBachelor's degree in Computer Science, Information Systems, Engineering or related major and a minimum one (1) year experience in the information security field required, OR associate's degree and two (2) years' experience in the information security field, OR in lieu of a degree, five (5) years' experience in the information security field required.
Ability to develop specific proactive procedures for detection of security breaches, identifying security risks in the software development process and code promotion procedures. Basic knowledge of TCP/IP networking. Possesses human relation skills to interact effectively with a variety of personnel. Ability to multi‑task and prioritize issues appropriately. Demonstrated ability to work effectively in a team environment as a participant, capacity to work independently and willingness to seek advice/assistance.
Certified as CISSP, GIAC, CISM, or security equivalent; or will obtain certification within 2 years of hire.
- Biomedical / Clinical Engineering
Experience:
Hands‑on experience working with medical, laboratory, or operational devices in clinical environments. - Healthcare Device Networking Fundamentals: IP addressing, ports/protocols, VLANs, connectivity, and troubleshooting of networked medical devices.
- Medical Device Cybersecurity & Vulnerability Management:
Identification, assessment, prioritization, and remediation of vulnerabilities on connected devices. - Device‑Level Security Implementation (Hardening & Remediation):
Applying secure configurations, coordinating patching, and implementing compensating controls in vendor‑constrained environments. - Cross‑Functional Technical
Collaboration:
Working across HTM, IT, Information Security, and vendors to resolve issues without impacting patient care. - Risk‑Based Decision Making in Clinical Environments:
Balancing cybersecurity risk with patient safety, device…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).