IT Security Engineer

CONMED Corporation
Utica, NY, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$69,900.0 - $108,300.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Identity and Access Management Phishing Security Information and Event Management Data Logging Information Technology Microsoft Sentinel Vulnerability Analysis

Job description

The IT Security Engineer will support the organization’s cybersecurity program with a focus on IT security operations and Governance, Risk, and Compliance (GRC) within a highly regulated medical device environment.

This entry-level role provides hands-on experience in protecting sensitive data, manufacturing systems, and regulated products, while learning industry standards such as FDA cybersecurity guidance, ISO 13485, and NIST frameworks. The Analyst will gain exposure to both technical security controls and risk/compliance processes, contributing to the organization’s mission of ensuring patient safety and product integrity., IT Security Operations Support

  • Assist in monitoring security alerts and events using SIEM/XDR tools (e.g., Microsoft Sentinel, Defender)
  • Support incident response activities including triage, documentation, and escalation
  • Help maintain endpoint security, vulnerability scanning, and patch tracking
  • Participate in security investigations under guidance of senior analysts

Governance, Risk & Compliance (GRC)

  • Support development and maintenance of security policies, procedures, and standards
  • Assist in performing risk assessments for IT systems, applications, and medical devices
  • Help track and document risks, remediation plans, and control effectiveness
  • Contribute to audit preparation and evidence gathering for: FDA cybersecurity requirements, ISO 13485 / ISO 27001, NIST Cybersecurity Framework
  • Maintain compliance documentation and assist in control testing activities

Data Protection & Security Controls

  • Support implementation and monitoring of controls for: Sensitive data (PHI, PII, IP), Access control and identity management
  • Assist with user access reviews and least privilege enforcement
  • Help monitor data protection tools (DLP, encryption, logging)

Product & Regulatory Awareness

  • Learn fundamentals of medical device cybersecurity and secure product lifecycle practices
  • Assist in documenting security requirements for systems supporting product development and manufacturing
  • Support tracking of vulnerabilities and issues impacting device software or connected systems

Security Awareness & Training

  • Help coordinate cybersecurity awareness campaigns across the organization
  • Support phishing simulations and user training initiatives
  • Promote a culture of security and compliance awareness

Documentation & Reporting

  • Maintain records of incidents, risks, and compliance activities
  • Assist in developing dashboards and reports on Risk posture, Compliance status, and Security metrics

Requirements

  • Bachelor’s Degree in Cybersecurity, Information Technology, Information Systems or a related field
  • In Lieu of a Bachelors degree, candidates must have 3-5 years of experience Cybersecurity, Information Technology, Information Systems

Preferred Experience

  • Basic understanding of networking and operating systems, information security concepts (CIA triad, access control, vulnerabilities)
  • Strong interest in cybersecurity within regulated environments
  • Strong organizational, analytical, and communication skills

  • Familiarity with security frameworks (NIST CSF, ISO 27001) and Basic compliance concepts (audit, controls, risk)
  • Exposure (academic or hands-on) to: SIEM tools, vulnerability scanning tools, identity and access management
  • Interest in medical devices, healthcare technology, or manufacturing environments

Key Skills Developed

  • Security monitoring and incident response fundamentals
  • Risk assessment and compliance processes
  • Regulatory awareness (FDA, ISO, NIST)
  • Security documentation and audit preparation
  • Communication of technical risk in a business context

Key Performance Indicators (KPIs)

  • Accuracy and timeliness of risk and compliance documentation
  • Participation in incident response and alert triage
  • Completion of assigned audit and compliance support tasks
  • Quality of reports and documentation maintained
  • Progress in training and certification milestones

Benefits & conditions

Disclosure as required by applicable law, the annual salary range for this position is $69,900 - $108,300. The actual compensation may vary based on geographic location, work experience, education and skill level. The salary range is CONMED’s good faith belief at the time of this posting., CONMED offers a wide array of benefits to fit your unique needs. Visit our Benefits Page for more information.

  • Competitive compensation
  • Excellent healthcare including medical, dental, vision and prescription coverage Short & long term disability plus life insurance
    • cost paid fully by CONMED Retirement Savings Plan (401K)
    • CONMED matches your contributions dollar for dollar, with the potential for up to 7% per pay period Employee Stock Purchase Plan
    • allows stock purchases at discounted price
  • Tuition assistance for undergraduate and graduate level courses

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa Ā· LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 Ā· World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering Ā· World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

Videos

See all

Related articles

See all