Information Security Architect II
Valley Medical Center
Renton, United States of America
2 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Senior Compensation
$ 142KJob location
Renton, United States of America
Tech stack
Microsoft Windows
Amazon Web Services (AWS)
Macintosh Computers
Azure
Cloud Computing
Computer Security
Information Systems
Databases
Computer Forensics
Linux
Multi-Factor Authentication
Subnetting
OSI Models
Python
OpenSSL
Open Web Application Security
PCI Data Security Standards
Public Key Infrastructure
Powershell
Cloud Services
Zero Trust Network Access
TCP/IP
Software Vulnerability Management
Scripting (Bash/Python/Go/Ruby)
Virtual Environment
Information Technology
Patch Management
Job description
- Monitor all security solutions, investigate all alerts, and respond appropriately to all identified threats, incidents, and/or compromise.
- Monitor the ticket queue, attempt first tier support, and escalate as needed.
- Provide excellent customer service.
- Assist staff with access related issues.
- Provide certificate assistance to other teams as needed.
- Document all team related procedures and resources to include notes, training, templates, knowledge bases, databases, change control and SOPs.
- Perform performance maintenance and patch management on all security tools and databases.
- Provide IT policy guidance to assist staff with security compliance.
- Assist and take instruction from higher-level analysts with duties and responsibilities as assigned.
- Configure, manage, and operate all security tools to include firewalls, AV, SIEMs, SEG, PKI, etc.
- Conduct internal risk assessments.
- Research, recommend, and implement changes to procedures, systems, or infrastructure to enhance security and/or address non-compliance with information security standards.
- Review and recommend updates all team related procedures and resources to include notes, training, templates, knowledge bases, databases, change control and SOPs.
- Research and recommend patching for known threats and zero-day vulnerabilities.
- Research new technology requests and recommend appropriate security guidance.
- Provide security training and implement awareness campaigns to help educate staff.
- Assist and provide guidance to lower-level analysts with assigned duties and responsibilities.
- Assist and take instruction from senior-level analysts and supervisor with duties and responsibilities as assigned.
Requirements
- Education: Master's degree in computer science related field plus two (2) years industry related experience, OR Bachelor's degree in computer science related field plus three (3) years industry related experience, OR Associate's degree in computer science related field plus four (4) years industry related experience, OR five (5) years industry related experience.
- Certification: Intermediate-level information security certification from a cybersecurity industry standard such as (ISC)2, OffSec, EC-Council, GIAC, CompTIA, and other related certifications on approval. Current certification required.
- Applied Job Experience: Information Security Background: Industry experience preferred as a Cybersecurity Practitioner, Security Operations Center (SOC) Analyst, Risk Assessment Auditor, Penetration Tester, Incident Response Handler, or Computer Forensics Investigator. Experience as a Systems Administrator or Network Engineer to be considered up to three (3) years as time towards., * Working knowledge with scripting languages and automation such as Python, PowerShell, etc.
- Working knowledge with securing cloud computing and cloud services such as Azure and AWS.
- Working knowledge with securing operating system environments such as Windows, Mac, Linux, etc.
- Working knowledge with securing networking, wireless and virtual environments.
- Working knowledge with subnetting, segmentation, and zero-trust zones.
- Professional experience with PKI/certificate authority and OpenSSL.
- Professional experience with SEG, NGFW, AV and EDR.
- Professional experience with various SIEMs and SOC management.
- Professional experience with multi factor authentication implementation.
- Familiarity with security compliance standards such as HIPAA, PCI-DSS, GDPR, etc.
- Familiarity with security frameworks such as HITRUST, NIST, OWASP, ISO 27000, SANS CIS 20, STIGs, ITIL, etc.
- Familiarity with the full stack OSI model, as well as TCP/IP protocol suite.
- Familiarity with vulnerability management and patch cycles.
- Familiarity with risk assessments, pen-tests, table-top exercises, BCDR, and change management.
- Familiarity with writing and implementing IT policy, CSIRT plans, and training & awareness programs.
UNIQUE PHYSICAL and MENTAL DEMANDS, ENVIRONMENT, AND WORKING CONDITIONS:
- Requires ability to move items and equipment weighing up to 70 lbs.
- Requires ability to appropriately manage and handle highly confidential information.
- Requires ability to remain focused, self-motivated, and initiative-taking while working independently or on a team, regardless of working onsite or remotely with little to no instruction.
- Requires planning, organizing, and working on multiple tasks at one time with tight time constraints.
- Requires ability to identify the most important tasks and prioritize accordingly.
- Requires ability to implement a logical and structured approach to time management.
- Requires ability to demonstrate a high level of professionalism and show respect to all co-workers, patients, business partners, and members of the public.
- Requires ability to demonstrate a strong collaborative mindset, share knowledge, and function as a contributing member of the team.
- Requires ability to work effectively with all levels of the organization and broad technical understanding, while providing excellent customer service.
- Requires ability to demonstrate a high level of communication skills, both verbal (meeting organizer, training, etc.) and written (E-mail, IT policy, documentation, etc.) to C-level executives, auditors, end users, and engineers.
- Requires ability to quickly learn, conduct own research as necessary, and retain information.
- Requires ability to quickly understand information systems to identify and validate security requirements.
- Requires ability to stay up to date on all current cybersecurity events and zero-day exploitations.
- Requires ability to demonstrate strong critical-thinking and problem-solving skills.
- Requires ability to demonstrate acute attention to detail., * Do you have experience as a Cybersecurity Practitioner, Security Operations Center (SOC) Analyst, Risk Assessment Auditor, Penetration Tester, Incident Response Handler, or Computer Forensics Investigator?
- Do you have a certification from a cybersecurity industry such as (ISC)2, OffSec, EC-Council, GIAC, CompTIA?
Experience:
- industry related: 5 years (Preferred)
Benefits & conditions
Pulled from the full job description
- 401(k)
- Health insurance
- Employee discount
- Vision insurance
- Dental insurance
- Life insurance
- Flexible schedule, * 401(k)
- Dental insurance
- Employee discount
- Flexible schedule
- Health insurance
- Life insurance
- Vision insurance
About the company
At Valley, we serve a critical role in helping maintain and improve the health of our community. We share common core values such as compassion, respect, trust and teamwork. And we have an honest passion for helping others, patients and staff alike. If this excites and motivates you, consider joining our team!