Cyber Security Engineer

GE Healthcare
United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Agile Methodology Amazon Web Services Software System Penetration Testing Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Configuration Management Cyber Security Continuous Delivery
+34 more
Continuous Integration Data Security Web Development XacML Federated Identity Management Hardware Virtualization Infrastructure as a Service (IaaS) Identity and Access Management Systems Analysis Internet Security Information Systems Security Architecture Professional Network Security OAuth Open Web Application Security Platform as a Service (PAAS) Security Assertion Markup Language (SAML) Secure Coding Simple Object Access Protocol (SOAP) Virtualization Technology Software Vulnerability Management Web Application Frameworks Web Services Data Logging Git Information Technology Data Management Hardware Infrastructure U-Boot Restful APIs Operating System Security Multiplatform Cisco Jenkins Vulnerability Analysis

Job description

Design, review, and govern security architectures for cloud (AWS/Azure/GCP) and on-prem infrastructure. Ensure alignment with enterprise security standards, threat models, and regulatory requirements. Provide security design guidance for new platforms, applications, and services. Participate in architecture and design reviews to identify risks early and recommend mitigations.

Cloud & Infrastructure Security

Implement and manage cloud security controls including IAM, network security, data protection, logging, and monitoring. Secure on-prem environments including servers, networks, virtualization platforms, and hybrid integrations. Support secure configuration baselines and hardening standards for cloud and on-prem systems.

Vulnerability Management

Own and drive the vulnerability management lifecycle, including discovery, triage, risk scoring, remediation guidance, and verification. Analyze scan results and penetration test findings to determine true risk and business impact. Partner with engineering and infrastructure teams to prioritize remediation efforts.

Risk Analysis & Threat Modeling

Perform security risk assessments, threat modeling, and impact analysis for systems and services. Translate technical findings into clear risk statements and actionable recommendations. Support ongoing risk tracking and reporting for leadership and audit readiness.

Security Operations & Governance

Contribute to incident response investigations from a technical analysis perspective. Support compliance initiatives (e.g., ISO, SOC, HIPAA, IEC 62304, NIST) by providing technical evidence and assessments. Develop and maintain security standards, patterns, and reference architectures., * Design, review, and govern security architectures for cloud (AWS/Azure/GCP) and on-prem infrastructure.

  • Ensure alignment with enterprise security standards, threat models, and regulatory requirements.
  • Provide security design guidance for new platforms, applications, and services.
  • Participate in architecture and design reviews to identify risks early and recommend mitigations.

Cloud & Infrastructure Security

  • Implement and manage cloud security controls including IAM, network security, data protection, logging, and monitoring.
  • Secure on-prem environments including servers, networks, virtualization platforms, and hybrid integrations.
  • Support secure configuration baselines and hardening standards for cloud and on-prem systems.

Vulnerability Management

  • Own and drive the vulnerability management lifecycle, including discovery, triage, risk scoring, remediation guidance, and verification.
  • Analyze scan results and penetration test findings to determine true risk and business impact.
  • Partner with engineering and infrastructure teams to prioritize remediation efforts.

Risk Analysis & Threat Modeling

  • Perform security risk assessments, threat modeling, and impact analysis for systems and services.
  • Translate technical findings into clear risk statements and actionable recommendations.
  • Support ongoing risk tracking and reporting for leadership and audit readiness.

Security Operations & Governance

  • Contribute to incident response investigations from a technical analysis perspective.
  • Support compliance initiatives (e.g., ISO, SOC, HIPAA, IEC 62304, NIST) by providing technical evidence and assessments.
  • Develop and maintain security standards, patterns, and reference architectures.

Requirements

8-12 years of experience in cyber security engineering, with hands-on expertise in both cloud and on-prem environments. Strong experience with cloud platforms (AWS, Azure, or GCP) and associated security services. Proven background in security architecture, design reviews, and infrastructure security. Hands-on experience with vulnerability scanning tools, risk assessment methodologies, and remediation processes. Solid understanding of network security, operating system security, and identity and access management. Strong analytical and communication skills, with the ability to explain security risks to both technical and non-technical stakeholders., Experience working in regulated environments (healthcare, medical devices, finance, or similar). Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS, OWASP. Experience with container and Kubernetes security. Security certifications such as CISSP, CCSP, CISM, or equivalent. Experience supporting hybrid or large-scale enterprise environments., * 8-12 years of experience in cyber security engineering, with hands-on expertise in both cloud and on-prem environments.

  • Strong experience with cloud platforms (AWS, Azure, or GCP) and associated security services.
  • Proven background in security architecture, design reviews, and infrastructure security.
  • Hands-on experience with vulnerability scanning tools, risk assessment methodologies, and remediation processes.
  • Solid understanding of network security, operating system security, and identity and access management.
  • Strong analytical and communication skills, with the ability to explain security risks to both technical and non-technical stakeholders., * Experience working in regulated environments (healthcare, medical devices, finance, or similar).
  • Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS, OWASP.
  • Experience with container and Kubernetes security.
  • Security certifications such as CISSP, CCSP, CISM, or equivalent.
  • Experience supporting hybrid or large-scale enterprise environments.

Education Qualification

For roles outside USA:

Bachelor’s Degree in Computer Science or ā€œSTEMā€ Majors (Science, Technology, Engineering and Math) with advanced experience.

For roles in USA:Bachelor’s Degree in Computer Science or ā€œSTEMā€ Majors (Science, Technology, Engineering and Math) with minimum years of experience4years

Desired CharacteristicsTechnical Expertise:

  • Experience with cyber security framework (NIST 800-53, ISO 27001, IEC 62443, etc.) implementation and governance
  • Program and Project Management experience; expertise with Agile development teams
  • Experience with secure coding principles; code signing; secure boot
  • Experience with penetration testing and ethical hacking
  • Knowledge of CI/CD and automation tools (Chef, Git, Jenkins)
  • Knowledge of Identity management and identity federation (SAML, Oauth, SCIM, XACML)
  • Experienced in developing web services (SOAP/REST)
  • Must be available for on call for potential security response
  • Knowledge of application risk identification and evaluation techniques
  • Knowledge of Cyber Security and full knowledge of multiple related engineering functions
  • Experience securing applications within cloud platforms such as AWS, Azure and alike.
  • Experience with broad set of information security technologies and processes within a SaaS, IaaS, PaaS, or cloud environment, Agile Programming Methodologies, Amazon Web Services (AWS), Analysis Skills, Architectural Design, Automation, CCSP - Cisco Certified Security Professional, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Candidate Screening, Career Development, Chef (Configuration Management), Cloud Architecture, Cloud Computing, Communication Skills, Computer Hacking, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Enterprise Protection, Environmental Health, Establish Priorities, Finance, GCP (Good Clinical Practices), Git, HIPAA (Health Insurance Portability and Accountability Act), Hardware Virtualization, Healthcare, ISO (International Organization for Standardization), Identity Data Management, Identity Federation, Incident Response, Information/Data Security (InfoSec), International Electro-Technical Commission (IEC), Internet Security, Jenkins, Leadership, Mathematics, Medical Equipment, Microsoft Windows Azure, Multiplatform/Cross-Platform, Network Security, OAuth, On Call, Penetration Testing, Product Lifecycle, Project/Program Management, Protective Services, REST (Representational State Transfer), Regulatory Requirements, Risk, Risk Analysis, SOAP (Simple Object Access Protocol), Secure Coding, Security Analysis, Security Architecture, Security Assertion Markup Language (SAML), Security Design, Security Monitoring, Systems Analysis, Technical Analysis, Threat Modeling, Threat and risk analysis (TRA), U.S. National Institute of Standards and Technology (NIST), Vaccination, Vulnerability Scanners, Web Application Framework, Web Programming, Web Services

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

2:30 min

Understanding XACML components for access control evaluation

Anderson Dadario +1 Ā· LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz Ā· WWC Europe 2026

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer Ā· Coffee With Developers

50 sec

Evaluating common authentication and custom authorization challenges

Anderson Dadario +1 Ā· LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz Ā· WWC Europe 2026

Videos

See all

Related articles

See all