Sr. Cybersecurity Engineer ( remote )
Orlando, Florida, United States - Remote
AssistRx
See how AssistRx offers intelligent therapy initiation and patient support solution that improve patient uptake, visibility and outcomes.The Cyber security Engineer utilizes business knowledge and solid technical experience of security to provide a secure environment for the business. Cyber security engineers identify threats and vulnerabilities in systems and software, then apply their skills to developing and implementing high-tech solutions to defend against hacking, malware and ransomware, insider threats and all types of cybercrime.
The successful candidate must demonstrate a strong ability to manage and improve operational security functions, implement risk-based solutions, develop and maintain security metrics, promote security best practices and training across the organization and partner with stakeholders from various IT and business teams. Focus areas will include managing security requests, investigating and responding to alerts and incident tickets, conducting user access reviews, developing and maintaining security documentation, network and endpoint security management, vulnerability management, identity and access management, incident response, SIEM and log management, cloud security operations, overall security monitoring, and reporting. Additionally, the candidate will be responsible for contributing to internal control testing related to client and regulatory audits (e.g. HIPAA, SOC1/2) by gathering and submitting proper technical evidence based on control testing needs and ensuring controls tests are completed comprehensively and on time.
Requirements
- Monitor and manage the Information Security request queue, including analysis and resolution of outstanding issues and process improvement.
- Manage endpoint and network security environments including overall health, policy modifications, troubleshooting/resolving issues and producing monthly health metrics for workstations, servers, and identities.
- Work directly with the Security Operations Center (SOC) to analyze and resolve security events/alerts. Including:
- monitoring and management of the SIEM platform
- managing the logging health of various log sources (e.g. Windows and Linux systems, cloud infrastructure and services, and network and security infrastructure).
- Works directly with Information Security Engineering and Governance, Risk and Compliance (GRC) resources as needed to investigate and resolve issues.
- Supports and manages the vulnerability management platforms for infrastructure and application scanning. Including:
- development and maintenance of scanning policies
- onboarding assets
- reporting
- validation and false positive research
- remediation tracking
- process improvement.
- Conduct internal security control testing. Includes gathering, uploading, and reviewing evidence within the GRC (Governance, Risk and Compliance) tool.
- Supporting PCI, SOC1/2, HIPAA, and client security assessments.
- Manage and maintain Information Security training and awareness campaigns (e.g. training, phishing).
- Developing/monitoring campaigns, ensuring required training is complete, producing reports/metrics and recommending improvements to the current process.
Requirements:
- A Bachelor's degree or higher in Computer Science, Electrical Engineering, Information Assurance, Network Security Computer Engineering or a related field, or equivalent experience
- 5+ years of Information Security / Cybersecurity experience
- Strong knowledge of Information Security / Cybersecurity related technologies, processes, and tools.
- Working knowledge of Office 365 security concepts, policies, settings, alerting, audit logging, security and compliance center, cloud app security and investigations is required.
- Experience identifying assets (e.g. servers, network devices, applications), identifying network layouts and determining security risk and potential solutions.
- Security focused degree and/or certifications a plus (e.g. BS/MS in Cybersecurity or related discipline, CEH, OCSP, CISSP, CISA, CompTIA Security+, etc.)
- Familiar with network security concepts and products (e.g. firewall (Palo Alto, Cisco), network (e.g. Cisco, Meraki), email (O365). Cisco Umbrella a major plus).
- Familiar with endpoint security products and concepts (e.g. malware protection, network protection, forensics, DLP, compliance. Bitdefender a plus).
- Familiar with security monitoring (SIEM), analysis and resolution of security events/alarms (AlienVault a plus).
- Familiar with identity and access management concepts (e.g. Azure Active Directory, SSO, user access reviews).
- HIPAA and healthcare experience a plus
- Understanding of SDLC process is a plus
- Excellent oral and written communication skills.
Benefits
- Supportive, progressive, fast-paced environment
- Competitive pay structure
- Matching 401(k) with immediate vesting
- Medical, dental, vision, life, & short-term disability insurance
- AssistRx, Inc. is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration without regard to race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors, or any other protected categories protected by federal, state, or local laws.
- All offers of employment with AssistRx are conditional based on the successful completion of a pre-employment background check.
- In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. Sponsorship and/or work authorization is not available for this position.
- AssistRx does not accept unsolicited resumes from search firms or any other vendor services. Any unsolicited resumes will be considered property of AssistRx and no fee will be paid in the event of a hire
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Active Directory AlienVault Audits Azure CEH CISA CISSP Cloud Compliance CompTIA Computer Science Cyber crime Endpoint security Firewalls Forensics Governance HIPAA IAM Incident response Linux Malware Monitoring Network security SDLC Security assessment SIEM SOC SOC 1 SSO Vulnerabilities Vulnerability management Windows
Perks/benefits: Competitive pay Health care Insurance
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.