Information Security Engineer - IS Mod

Mayo Clinic
Rochester, NY, United States
10 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Computer Networks Data Security Network Security Network Segmentation Software Vulnerability Management Information Technology 3-tier Architectures Security Orchestration, Automation & Response

Job description

This Senior Information Security Engineer serves as the dedicated security design and oversight lead for Enterprise Network Segmentation within the Information Protection - Network Security (IP-NS) team, ensuring segmentation controls are architected to appropriately align with the risk profile of the assets they protect across a large, regulated healthcare environment. A strong background in network segmentation is required, including proven experience designing risk-based segmentation strategies and defining policy intent for high-risk assets. This role is a critical technical authority who partners with Product Owners, the Network Security Architect, network engineering teams, and enterprise risk stakeholders to translate asset criticality and threat modeling into control requirements. It will also validate implemented policy meets design intent; provide continued oversight of segmentation controls and drift; contribute to Tier 3 incident response; and support executive reporting on

Requirements

risk-reduction outcomes aligned to security control objectives. Familiarity with security monitoring, incident response, vulnerability management, and security automation is highly desirable. Ability to operate effectively in a hybrid work environment, including participation in on-site work-related events, team collaboration sessions, and key organizational activities as required., Bachelor’s degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

Master’s degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all