Cybersecurity Specialist

Cahaba Medical Care Foundation
Centreville, AL, United States
8 days ago
Apply on workforcenow.adp.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Chrome OS CompTIA Security+ Cyber Security Identity and Access Management Information Security Management Phishing Security Information and Event Management Network Access Control Information Technology Gsuite
+1 more
Vulnerability Analysis

Job description

Position Summary: The Cybersecurity Specialist will be the dedicated champion for the security posture of our Federally Qualified Health Center (FQHC). Reporting directly to the IT Director/Director of Infrastructure, this role will transition our security from a shared team responsibility to a focused, proactive program. You will be responsible for safeguarding patient data (PHI), ensuring HIPAA compliance, managing security vendor relationships, implementing further endpoint controls, and leading our internal vulnerability assessments.

Responsibilities and Duties:

  • Vulnerability & Threat Management: Lead annual security risk assessments and ongoing internal penetration testing. Analyze results, prioritize remediation, and work with the IT team to patch vulnerabilities.
  • MDR/SIEM Oversight: Serve as the primary point of contact and administrator for our 24/7 security monitoring partner. Monitor alerts, investigate incidents, and lead response efforts.
  • Endpoint & Identity Security: Take ownership of securing our mixed-OS environment. Maintain Google Workspace Enterprise policies for Chromebooks, and spearhead the selection, implementation, and management of a Mobile Device Management and directory solution for our Windows and Mac endpoints.
  • Network & Access Control: Maintain and optimize our RADIUS-based network authentication and access controls to ensure secure connectivity across all clinic sites.
  • Compliance & Governance: Ensure all IT systems and workflows align with HIPAA, HITECH, and other healthcare regulatory frameworks. Maintain documentation for audits.
  • Security Awareness: Develop and run ongoing security awareness training and phishing simulations for FQHC staff.

Requirements

  • Experience: 3-5 years of dedicated experience in cybersecurity or information security, preferably within a healthcare (FQHC/hospital) or highly regulated environment.
  • Technical Stack Familiarity:
  • Strong knowledge of Google Workspace Enterprise administration and ChromeOS security.
  • Proven experience implementing MDM solutions from scratch.
  • Familiarity with Network Access Control (NAC) and RADIUS protocols.
  • Experience working with co-managed SIEM/MDR providers.
  • Certifications (Preferred but not required): CompTIA Security+, CEH (Certified Ethical Hacker), GSEC, or HCISPP (Healthcare Information Security and Privacy Practitioner).
  • Soft Skills: A collaborative mindset. You will be embedding security into the workflows of a busy IT team and medical staff, so empathy and clear communication are key.

Benefits & conditions

Background: Cahaba Medical Care Foundation is a community health center providing medical, pharmacy, dental, and behavioral health services to diverse underserved communities in Alabama. We are a Level 3 Patient-Centered Medical Home and Joint Commission accredited organization, committed to increasing integration and coordination of behavioral health and primary care. This is an exciting, fast paced practice with a strong mission and commitment to providing high quality care.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on workforcenow.adp.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:04 min

Designing an automated phishing attack pipeline

Wolfgang Ettlinger +1 · World Congress 2023

Videos

See all

Related articles

See all