IT Security Administrator
About the role
Under supervision of the Chief Information Officer, this person will audit current systems and develop and support the information security architecture that provides continuous protection of the company’s confidential information. This includes evaluating processes and systems to ensure integrity, confidentiality, and availability of resources.
Responsibilities include researching, planning, designing, and implementing security requirements; responding to security events with on-call support and incident management; training personnel on security requirements and configurations; using monitoring tools; and conducting routine security awareness training.
Responsibilities
- Write and develop security policies, procedures, and guidelines based on established industry best practices.
- Administer organizational IT security training and education programs to mitigate risks associated with social engineering (phishing) and other associate-based security threats.
- Conduct risk assessments for internal/external projects, systems, and vendors.
- Create and maintain documentation related to network and surrounding architecture.
- Plan and implement changes to combat vulnerabilities identified by assessments, security advisories, and intrusion detections.
- Conduct security assessments (penetration testing, vulnerability scanning, auditing).
- Perform setup and staging of relevant equipment as needed.
- Assist with configuration, maintenance, and upgrade rollouts to continuously improve the organization’s operating environment.
- Assist with operation and maintenance of the onsite data center and relevant colocations.
- Perform network administration tasks, including performance tuning and troubleshooting.
- Ensure basic information technology security principles are adhered to across the organization.
- Assist with development and maintenance of network and server systems, applications, security, and related configurations.
- Participate in creating and maintaining the company’s disaster recovery plans.
- Recommend upgrades, patches, new applications, and equipment.
- Architect and maintain system backups and recovery, monitor system configuration, and ensure data integrity.
- Assist with management of complex, virtualized VMware systems environments.
- Participate in maintenance of Microsoft Group Policy from an enterprise approach.
- Perform operational tasks supporting intrusion detection, security incident response, security event log keeping and analysis, management reporting, and virus prevention and patch management.
- Create and lead projects to develop, implement, and manage security technology functions and applications.
- Architect a ransomware security response to safeguard data and provide rapid recovery and restoration of impacted clinical systems.
- Administer Multi-Factor Authentication (MFA) security measures using MS Azure and other industry-leading technologies such as Imprivata.
- Ensure EPCS authentication compliance.
- Secure systems access leveraging MS Azure SSO and related security mechanisms with encryption in transit and at-rest.
- Install, configure, maintain, and troubleshoot security software and hardware, including specialized email firewalls, VPNs, content monitoring, intrusion detection/prevention systems, antivirus, and other security-related software or hardware.
- Maintain ongoing reliability, performance, and support of infrastructure with emphasis on hardware/software supporting clinical systems.
- Lead installation of new server-level software releases, system upgrades, evaluate and install patches, and resolve software-related problems.
- Assist with support and maintenance of complex Clinical Information Systems and related workflows.
- Evaluate and test Clinical Information Systems upgrades and patches prior to deployment.
- Ensure IT infrastructure meets evolving requirements of Clinical Information Systems.
- Ensure storage, archive, backup, and recovery procedures function correctly.
- Assist with prevention and remediation of security network incidents, unauthorized activities, malware infestations, and potential security vulnerabilities.
- Monitor and maintain LAN and WAN network devices, firewalls, domain controllers, and virtualization devices.
- Monitor performance of clinical systems and related infrastructure to ensure optimum delivery of patient care.
- Serve as an escalation path on the help desk for higher-tier issues.
- Provide off-hour on-call support as required.
Qualifications
- Minimum of three years of professional experience in an information system role of similar responsibility.
- Certified Information System Security Professional (CISSP).
- Cisco Certified Network Administrator and/or Engineer (CCNA or CCNE).
- Training and experience in Microsoft Active Directory/Windows Server Operating Systems 2008-2019 configuration and administration.
- Office 365 experience.
- Training and experience with Cisco network equipment configuration and administration.
- Training and experience with industry-leading security antivirus and encryption suite configuration and administration.
- VMware administration experience; VMware certification recommended.
- Experience architecting, maintaining, and supporting complex VMware environments.
- Strong knowledge of network appliances and TCP/UDP routing theory, including Cisco Catalyst series professional switches, Cisco ASA, and related security appliances.
- Experience with HIPAA and HITECH governing rules and regulations.
Skills
- Demonstrated knowledge in networks, servers, and storage systems.
- Self-motivated and directed, with the ability to effectively prioritize and execute tasks.
- Works well with others or independently depending on required activities.
- Demonstrated knowledge of system fundamentals, system administration, network management, computer hardware, and software support, and their application to related medical equipment.
- High level of proficiency and demonstrated effectiveness in problem-solving and implementing new procedures related to increased departmental/organizational operating efficiency.
- Strong working knowledge of Certificate Authorities and maintenance of security certificates.
- Ability to work 24x7, 365 days per year availability.
- Wide degree of creativity and latitude is expected.
Preferred: Bachelor’s Degree in Cyber Security/Information Systems and/or a level of knowledge equivalent to that ordinarily acquired through completion of a Bachelor’s degree in a related technical field.