Cybersecurity Engineer II

Ensemble Health Partners
United States
17 days ago
Apply on ensemblehp.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$84,000.0 - $132,300.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cloud Computing CompTIA Security+ Cyber Security Information Systems Information Technology Audit Information Technology RSA Archer Platform CIS Benchmarks

Job description

The Engineer II, Cybersecurity (GRC Engineer) supports Ensemble Health Partners’ Governance, Risk, and Compliance (GRC) program by combining cybersecurity compliance expertise with hands-on technical execution. This role is responsible for the day-to-day management of the cybersecurity risk register, control automation initiatives, compliance monitoring, audit evidence collection, and administration of GRC platforms.

The GRC Engineer partners with security, engineering, and business stakeholders to maintain and strengthen the organization’s compliance posture across multiple frameworks, support third-party risk management activities, and translate technical risk into actionable business recommendations. This position plays a critical role in reducing manual compliance activities through automation while ensuring audit readiness and continuous compliance across cloud, infrastructure, and enterprise technology environments.

Essential Job Functions:

  • Own and maintain the cybersecurity risk register, including identifying, assessing, tracking, quantifying, and reporting cybersecurity risks.
  • Differentiate meaningful business risks from theoretical compliance gaps and provide practical remediation recommendations.
  • Support incident response activities from a governance, risk, and compliance perspective, ensuring proper documentation, audit evidence collection, and reporting throughout the incident lifecycle.
  • Assist with investigations of suspected improper activity and recommend corrective and remediation actions.
  • Respond to GRC-related incidents and service requests within established service level agreements (SLAs).
  • Design, implement, and maintain automated control monitoring and evidence collection processes to reduce manual audit activities and support continuous compliance.
  • Participate in technology and IT initiatives to evaluate systems and processes against applicable regulatory and security frameworks before implementation.
  • Provide governance, risk, compliance, and control integration requirements for new projects and technologies.
  • Ensure infrastructure, cloud, and security control changes align with established security frameworks and CIS benchmarks.
  • Collaborate with engineering teams to identify and remediate control deficiencies and compliance gaps.
  • Identify opportunities to improve operational efficiencies through automation and process optimization.
  • Maintain compliance documentation, including risk assessments, control narratives, policies, procedures, and audit evidence repositories.
  • Partner with cybersecurity analysts, architects, engineers, and business stakeholders to ensure effective security controls are implemented across enterprise systems, cloud platforms, and IT environments.
  • Support regulatory, audit, and compliance initiatives while maintaining audit readiness across the organization.
  • Demonstrate customer obsession, innovation, and operational excellence in support of organizational goals and compliance objectives.

Requirements

  • Associate Degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field; or equivalent combination of education and relevant experience., * 3 to 5 years of experience in cybersecurity, information security, governance, risk management, compliance, IT audit, or related disciplines.
  • Experience supporting cybersecurity risk management programs, compliance initiatives, audits, and security control assessments.
  • Experience working with security frameworks, governance processes, and technical controls in enterprise environments.

Preferred Certifications:

One or more of the following certifications is preferred:

  • CompTIA Security+
  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • Other relevant cybersecurity, risk, audit, or compliance certifications may be considered.

Preferred Knowledge, Skill and Abilities:

  • Governance, Risk, and Compliance (GRC) program administration.
  • Cybersecurity risk assessment and risk register management.
  • Security control design, implementation, and monitoring.
  • Compliance framework management and audit support.
  • Control automation and continuous compliance monitoring.
  • Audit evidence collection and documentation management.
  • Third-party risk management and vendor assessments.
  • Security incident documentation and compliance reporting.
  • CIS Benchmarks and security configuration standards.
  • Collaboration across cybersecurity, engineering, infrastructure, cloud, and business teams.
  • Ability to communicate technical security risks to non-technical stakeholders.
  • Strong analytical, problem-solving, documentation, and process improvement skills.
  • Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
  • This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
  • This position pays between $84,000-132,300 based on experience

This posting addresses s state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role’s range., This posting addresses state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role’s range.

Benefits & conditions

22 Healthcare Financial Management Association (HFMA) MAP Awards for High Performance in Revenue Cycle 2019-2024

Leader in Everest Group’s RCM Operations PEAK Matrix Assessment 2024

Clarivate Healthcare Business Insights (HBI) Revenue Cycle Awards for strong performance 2020, 2022-2023

Energage Top Workplaces USA 2022-2024

Fortune Media Best Workplaces in Healthcare 2024

Monster Top Workplace for Remote Work 2024

Great Place to Work certified 2023-2024

  • Innovation
  • Work-Life Flexibility
  • Leadership
  • Purpose + Values

Bottom line, we believe in empowering people and giving them the tools and resources needed to thrive. A few of those include:

  • Associate Benefits - We offer a comprehensive benefits package designed to support the physical, emotional, and financial health of you and your family, including healthcare, time off, retirement, and well-being programs.
  • Our Culture - Ensemble is a place where associates can do their best work and be their best selves. We put people first, last and always. Our culture is rooted in collaboration, growth, and innovation.
  • Growth - We invest in your professional development. Each associate will earn a professional certification relevant to their field and can obtain tuition reimbursement.
  • Recognition - We offer quarterly and annual incentive programs for all employees who go beyond and keep raising the bar for themselves and the company.

About the company

Ensemble is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.

Ensemble keeps communities healthy by keeping hospitals healthy. We recognize that healthcare requires a human touch, and we believe that every touch should be meaningful. This is why our people are the most important part of who we are. By empowering them to challenge the status quo, we know they will be the difference!

O.N.E Purpose:

  • Customer Obsession: Consistently provide exceptional experiences for our clients, patients, and colleagues by understanding their needs and exceeding their expectations.
  • Embracing New Ideas: Continuously innovate by embracing emerging technology and fostering a culture of creativity and experimentation.
  • Striving for Excellence: Execute at a high level by demonstrating our “Best in KLAS” Ensemble Difference Principles and consistently delivering outstanding results.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on ensemblehp.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all