Jobs · Information Technology · Minnesota

Network/Firewall Security Engineer - Information Tech (Onsite) (Days)

Tanner Health · Carrolton, MN · 1 wk ago
On-siteInformation TechnologyFull-time

About the role

The IT Security Engineer develops and maintains enterprise-wide security architecture and strategies for all aspects of the security domain in alignment with the business strategy and goals. They provide technical and security expertise to IT and business teams to understand technical constraints, identify security technology solutions, and develop security reference architectures and strategies to achieve business results.

The IT Security Engineer identifies and drives remediation for vulnerabilities discovered across Tanner Medical Center's systems and applications. They build platforms to automate processes for triage, prioritize security deviations for closure, and provide insight into the state of security at Tanner Medical Center. In this role, the IT Security Engineer also acts as a consultant to other analysts and development teams for planning and implementation of IT initiatives across the Tanner Business Units.

Responsibilities

  • Develop and maintain enterprise-wide security architecture and strategies.
  • Provide technical and security expertise to IT and business teams.
  • Identify and drive remediation for vulnerabilities in systems and applications.
  • Automate processes for triage and prioritization of security deviations.
  • Act as a consultant for planning and implementation of IT initiatives.
  • Create technical procedural documentation.

Requirements

  • Bachelor's degree in computer science or IT Technology.
  • Six years of related experience.
  • Prior experience performing in the role of an IT Security Engineer.
  • Prior experience working in IT within the healthcare industry.

Skills

  • Understanding of Information Security frameworks and good practices (e.g., ISO, NIST, MITRE ATT&CK).
  • Understanding of computer, application, and network exploits and vulnerabilities.
  • Knowledge of authentication, authorization, and access control methods.
  • Knowledge of Identity Management Protocols and Software (e.g., ADFS, SAML, OKTA).
  • Knowledge of cryptography and cryptographic key management concepts.
  • Working knowledge of system component installation, integration, and optimization.
  • Working knowledge of cybersecurity principles and organizational requirements (confidentiality, integrity, availability, authentication, non-repudiation).
  • Demonstrated experience in applying cybersecurity methods (firewalls, demilitarized zones, encryption).
  • Working knowledge of network access, identity, and access controls.
  • Working knowledge of network protocols (TCP/IP, DHCP, DNS, directory services).
  • Knowledge of network design processes, including security objectives and tradeoffs.
  • Working knowledge of security management concepts (Release Management, Patch Management).
  • Working knowledge of configuration management techniques.
  • Working knowledge of device and client firewall policies for Windows, iOS, Android, MacOS, and ChromeOS.
  • Experience with Security Information Event Management (SIEM) and event log management.
  • Experience with Privileged Access Management Systems (PAM).
  • Experience with Vulnerability Management, Managed Detection and Response, and Intrusion Detection/Prevention Systems.
  • Experience in incident response processes and forensic investigations.
  • Strategic thinking and strong tactical execution.
  • Strong written and verbal communication skills.
  • Strong customer service skills during interactions with clinical staff, end-users, contractors, and vendors.

Preferred Qualifications

  • Certifications: CISSP, GIAC.

Similar jobs