Security Engineer / Information Technology

Children's Nebraska
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Software System Penetration Testing Audit Trail Bash Shell Cyber Security Information Systems Information Leak Prevention Data Security Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management
+21 more
Information Technology Operations Intrusion Detection Systems Virtual Private Networks (VPN) Mobile Application Software Python (Programming Language) Network Security Network Segmentation Windows PowerShell Azure Active Directory Phishing Microsoft SharePoint Security Information and Event Management TCP/IP Virtual Local Area Networks Software Vulnerability Management Scripting Network Access Control Firewalls (Computer Science) Microsoft InTune Information Technology Vulnerability Analysis

Job description

The Security Engineer at Children’s Nebraska plays a critical role in safeguarding the confidentiality, integrity, and availability of patient data, clinical systems, and hospital infrastructure. This position is responsible for designing, implementing, and maintaining security controls across a complex healthcare environment while ensuring compliance with HIPAA, HITECH, and other applicable regulatory frameworks., * System Security Engineering:

  • Design, deploy, and maintain security infrastructure including firewalls, IDS/IPS, SIEM, endpoint protection, and identity management systems
  • Architect and implement zero-trust network segmentation
  • Evaluate, recommend, and integrate new security technologies that align with healthcare operational requirements
  • Collaborate with IT and clinical teams to embed security into the design of new systems, applications, and medical device integrations.
  • Configure and manage Microsoft Purview compliance solutions including Data Loss Prevention (DLP), Information Protection sensitivity labels, and Insider Risk Management policies to safeguard PHI and PII
  • Administer Entra ID (Azure AD) security controls including Conditional Access policies, Privileged Identity Management (PIM), Identity Protection risk policies, and Multi-Factor Authentication (MFA) enforcement
  • Monitor and harden Exchange Online, SharePoint Online, OneDrive, and Teams environments against phishing, data exfiltration, and unauthorized sharing threats
  • Review and approved endpoint compliance policies, mobile device management (MDM), and mobile application management (MAM) across hospital-issued and BYOD devices
  • Conduct regular review of M365 audit logs, sign-in logs, and unified audit log (UAL) for anomalous activity and policy violations
  • Vulnerability Management, Threat Detection & Incident Response
  • Monitor security events and alerts using SIEM and other security tools; investigate and triage potential security incidents
  • Lead and participate in incident response activities including containment, eradication, recovery, and post-incident review
  • Conduct threat hunting exercises to proactively identify indicators of compromise within the environment
  • Develop and refine detection rules, use cases, and playbooks tailored to healthcare threat landscapes
  • Perform regular vulnerability assessments and coordinate and lead penetration testing across network, application, and medical device environments
  • Prioritize and track remediation of identified vulnerabilities in partnership with asset owners and IT operations
  • Maintain awareness of emerging threats, CVEs, and healthcare-specific security advisories (e.g., HHS HC3, FBI alerts)
  • System Security Administration:
  • Researches and writes security “effective practices” as “living documents” which are updated as the environment changes. This role includes Policy Implementation
  • Collaborates with Information Security Team to create policies, procedures and best practices
  • Champion a culture of security consciousness across all hospital departments and service lines
  • Serve as a trusted advisor to clinical and operational leaders on security best practices and risk trade-offs
  • Regular attendance at work is an essential function of the job.
  • Perform physical requirements as described in the Physical Requirements section

Requirements

Do you have experience in Windows support?, Do you have a Bachelor’s degree?, * Bachelor’s Degree from an accredited college or university in Cyber-Security, Networking, Computer Science, Information Systems, Engineering or related field Preferred and

  • equivalent work experience may be substituted for education Required, * Minimum 3-5 years of hands-on experience in information security engineering or a related security role experience strongly preferred Required and
  • Minimum 3 years of progressively responsible experience performing Windows system administration duties in a critical production environment, preferably healthcare Required
  • Experience operating within regulated industries; healthcare or financial services experience strongly preferred Preferred
  • Proven track record in incident response, including leading or participating in security incident investigations Preferred

Skills and Abilities

  • Proficiency in network security concepts: TCP/IP, VLANs, VPNs, DNS, firewalls, and network access control (High proficiency)
  • Hands-on experience with the Microsoft 365 security stack including Entra ID, Purview, PIM, and Intune (High proficiency)
  • Working knowledge of directory services and identity management (Active Directory, Azure AD, MFA, PAM) (High proficiency)
  • Scripting or automation skills (Python, PowerShell, or Bash) for security tooling and workflow automation (High proficiency)
  • Ability to communicate effectively both verbally and in writing (High proficiency)
  • Strong interpersonal and team building skills (High proficiency)
  • Effective planning, organizational, time management and prioritizing skills (High proficiency)
  • Expert knowledge of application and implementation of HIPAA control implementation (High proficiency)

Licenses and Certifications

  • Certified Ethical Hacker (CEH) Preferred andGAC Certified Forensic Analyst (GCFA) Preferred

About the company

At Children’s, the region’s only full-service pediatric healthcare center, our people make us the very best for kids. Come cultivate your passion, purpose and professional development in an environment of excellence and inclusion, where team members are supported and deeply valued. Opportunities for career growth abound as we grow our services and spaces, including the cutting-edge Hubbard Center for Children. Join our highly engaged, caring team-and join us in providing brighter, healthier tomorrows for the children we serve., Children’s is the very best for kids and the very best for your career! At Children’s, we put YOU first so together, we can improve the life of every child!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders ¡ LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa ¡ LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner ¡ LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper ¡ Europe 2026 Virtual

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering ¡ WWC Europe 2026

Videos

See all

Related articles

See all