Jobs · Information Technology · Illinois

IT Security, Director I (Hybrid)

American Medical Association · Chicago, IL · 2 wk ago
HybridInformation Technology$146k–$198k/yrFull-time

About the role

The American Medical Association (AMA) is seeking an IT Security, Director I (Hybrid) to join our Information Technology team. This role is responsible for providing subject matter expertise on the strategy, research, design, implementation, and operation of technical and process security controls. The position requires 3 days a week in the office.

Responsibilities

  • System/Network/Application Security Strategy
    • Research, design, evaluate, and test the security and regulatory compliance of AMA applications, systems, and networks to ensure the operational effectiveness of technical controls implemented by the organization.
    • Manage the research, appropriate response, and remediation of malicious and inappropriate activity; ensure consistency of the risk assessment approach across the organization.
  • Data Security
    • Collaborate with the security operations team, and maintain the broad suite of information security infrastructure, and all associated contracting, policy, and regulatory compliance implications.
  • Risk Management
    • Maintain cybersecurity and related regulatory expertise to research, prepare, and maintain strategic roadmaps incorporated into the Information Security Program.
    • Lead or assist with security incidents and compliance investigations and produce timely and clear reporting to both technical and senior business leader audiences.
  • Service Delivery
    • Manage continuous process improvement to identify technical or process enhancements in the delivery of IT Security services to increase service quality.
    • Prioritize improvements on a cost/benefit basis, communicating opportunities to management.
  • Project Management
    • Serve as an escalation point in the fulfillment of IT Security service requests.
    • Manage IT Security-led projects following the AMA’s applicable project governance processes, including Software Development Life Cycle; ensure successful project outcomes, such as completing projects within time and budget tolerances.
  • Mentor security and infrastructure team members, including analysts, engineers, and managers, related to information security strategies and threat prevention techniques.

Requirements

  • Minimum 10+ years engineering/design experience with a mix of the following security platforms is required: network and application-layer firewalls and secure network design; infrastructure and application-layer vulnerability management, security information and event management (SIEM); Security, Orchestration, Automation and Response (SOAR), data loss prevention (DLP); enterprise encryption solutions for database, file systems and data in motion; Internet/Web Gateway; end point security controls (such as anti-virus, anti-malware XDR, host-based firewall, and full disk encryption solutions); and intrusion detection and prevention systems.
  • Knowledge of Attack and Penetration methodologies, tools, and techniques
  • Minimum 5 years conducting infrastructure and application project design reviews
  • Engineering/design experience with a mix of the following infrastructure technologies is required: Microsoft/Azure (Azure AD, ADFS, M365, Sharepoint 2019, Windows Server2019-2022, Windows 10-11); Red Hat Linux, VMware, AWS EC2, S3, IAM
  • Demonstrated industry leadership capabilities, and recognized as a subject expert in the information security field.
  • Knowledge of security scanning and analyzing tools; Commercial Application and Infrastructure/Operating System and Opensource Vulnerability scanning/management, and freeware/commercial Wireshark, NMAP, Burp Suite, Nikto, Qualys, Tenable, Snyk, Wiz
  • Polished verbal and written communication, interpersonal, analytical, and organizational skills, attention to detail, and a high level of integrity are required
  • Strong business acumen. Ability to understand the organization's various business functions and their objectives
  • Experience with project management and software development lifecycle methodologies preferred.
  • Professional IT Security and IT Audit certifications such as CISSP,CISM, CEH, CISA, and/or technical certifications preferred
  • Experience with IT Infrastructure Library (ITIL) – particularly incident, change, release, and/or problem management preferred
  • Experience with IT security standards, such as CIS Top 20, ISO 27001, NIST CSF, NIST 800-53, HITRUST, MITRE, OWASP,CWE/SANS Top 25 Programming Errors, and attestation reports such as SOC 1/2/3 and technology risk management methodologies, such as NIST 800-30 preferred
  • Experience with compliance standards such as PaymentCard Industry (PCI),Sarbanes Oxley (SOX) and Health Insurance Portability & Accountability Act (HIPAA) preferred
  • Bachelor’s Degree in Computer Science or related discipline strongly preferred. Master’s Degree in Computer Science or related discipline a plus
  • Additional Technical Background Experience with: Cloud-based security tools (CloudTrail, WAF, Security Center, etc.) Source code management tools (GitHub, BitBucket, etc.) Code scanning tools (Dynamic, Static and Opensource) Vulnerability Management solutions(Qualys, Tenable, Wiz) Knowledge of: User authentication such as Zero Trust concepts, SAML and OAuth-based SSO architectures and IDP integrations, MFA, Virtual Private Networks (VPNs), TLS, PAM, corporate wifi, device identity, 802.1x port-based authentication, server identification, authentication of web applications, S/MIME Email Signing, is desirable
  • Programming languages (.Net, Java, JavaScript, Angular, Drupal, Python, etc.) Web services, API, REST, RPC Infrastructure as Code (CloudFormation, Terraform) preferred Administration of Azure suite, including; Azure Active Directory, Conditional Access, Intune, Mobile Application Management, Microsoft Cloud App Security, and/or advanced Azure security services like Azure Security Center, Advanced DDoS Protection, Azure Firewall, and Azure WAF Administration of AWS security services and related best practices: GuardDuty, Cognito, Inspector, Detective and advocate AWS Identity & Access Management (IAM)
  • Operating systems: Windows, Mac, Linux, WVD, VDI, and Jump Boxes/Bastion Servers Network routing and communication frameworks, protocols, and technologies such as OSI, TCP/IP v4 & v6, RIP, OSPF, VPN, HTTPS, TLS, and SSH is required. Working knowledge of SQL, LDAP, and/or regex is a plus.

Pay

The salary range for this position is $146,384 - $197,728.

Schedule

This is an exempt position, requiring 3 days a week in the office.

Similar jobs

Director, IT Security

Ensemble Health PartnersUnited States· 1 wk ago
RemoteInformation Technology$141k–$223k/yrapply on ensemblehp.wd5.myworkdayjobs.com

Director, IT Security

Cozen O'ConnorPhiladelphia, PA· 2 mo ago
Information Technologyapply on hctq.fa.us2.oraclecloud.com

Director IT Security

MindrUnited States· 2 mo ago
RemoteInformation Technology$139k–$185k/yrapply on cstmyhr.rec.pro.ukg.net

IT Director (Hybrid)

Intact Insurance Specialty SolutionsFarmington, CT· 3 mo ago
Information Technology$225k–$263k/yrapply on recruiting.ultipro.com

Director, IT & Security

Equal Opportunity VenturesNew York, NY· 1 mo ago
Information Technology$200k–$250k/yrapply on jobs.eoventures.com