Cyber Security Engineer (Philadelphia) Job at Integrated Resources, Inc ( IRI ), Philadelphia, PA

SXo4elpMdXhvdmJkTkREc05QWjVRTVdvbHc9PQ==
  • Integrated Resources, Inc ( IRI )
  • Philadelphia, PA

Job Description

Duties:

Hybrid - 80% remote, 20% onsite. Position is temp to perm. Please only submit candidates with CISSP certification at this time. The manager is also prioritizing candidates with could security certifications.

The Cloud Security Engineer will play a pivotal role in the cloud security service delivery model. The role combines deep technical expertise, collaboration across internal and external teams to design, implement, and optimize cloud security controls and service lines. The candidate will support both project-based and continuous security initiatives, focusing on securing Clients cloud migration, supporting cloud security tool optimization, cloud security processes for the Information Security team, cloud/hybrid controls, automation, and risk-driven security outcomes.

Proven experience in securing a multi-cloud environment.

Proven experience with Identity and access management in the cloud

Proven experience with all security service lines in a cloud environment and the supporting security tools and processes to be successful.

Demonstrate collaboration with internal stakeholders, vendors, and supporting teams to design, implement, and maintain security technologies across network, endpoint, identity, and cloud infrastructure.

Drive continuous improvement and coverage of cloud security controls by validating alerts, triaging escalations, and working with the MSP to fine-tune detection and prevention capabilities.

Lead or support the development of incident response plans, engineering runbooks, tabletop exercises, and system hardening guides.

Ensure alignment of security architectures with Clients policies, standards, and external frameworks such as NIST SP 800-53, HIPAA, PCI-DSS, CISA ZTMM, CIS Benchmarks, and Microsoft CAF Secure Methodology, AWS CAF, AWS Well Architected framework, Google CAF

Participate in design and governance forums to provide security input into infrastructure, DevSecOps, and cloud-native application strategies.

Assist with audits, compliance assessments, risk remediation plans, and evidence collection with internal compliance and external third-party stakeholders.

Mentor and support junior InfoSec engineers through documentation, training, and peer reviews.

Hands-on experience in security engineering, systems integration, and cloud architecture (Azure preferred).

Proficiency in tools and domains such as: EDR (Microsoft Defender), SIEM (Sentinel or Splunk), CSPM (e.g., Wiz), IAM (Entra ID), VPNs/NGFWs, NAC, and encryption protocols.

Demonstrated understanding of secure configuration management, automation pipelines (e.g., Terraform, PowerShell), and vulnerability management platforms.

What you will do

A Principal Information Security Specialist has similar responsibilities to Information Security Specialist III personnel. However, a Principal Information Security Specialist is deemed to be the subject matter expert and in-house advisor on complex problems and issues. A Principal Information Security Specialist also:

Works independently to initiate assignments and draws upon extensive professional knowledge and experience to make independent judgments regarding analysis, evaluation, development, and implementation of enterprise long-term solutions and operating initiatives to ensure that enterprise architectural objectives are aligned with organizational needs and strategic goals.

Education:

Required: Bachelor's Degree

Preferred: Bachelors degree in computer science, Information Systems, or related field.

Required Experience:

At least twelve (12) years industry related experience, including experience in one to two IT disciplines (such as technical architecture, network management, application development, middleware, information analysis, database management or operations) in a multitier environment.

At least six (6) years experience with information security, regulatory compliance and risk management concepts.

At least three (3) years experience with Identity and Access Management, user provisioning, Role Based Access Control, or control self-assessment methodologies and security awareness training.

Experience with Cloud and/or Virtualization technologies.

Preferred Experience:

At least three (3) years in working with matrixed high-performance teams.

level 2a

Languages:

English( Speak, Read, Write )

Skills:

Duties (cont'd):

Optimizes information management approaches through an understanding of evolving business needs and technology capabilities and ensures that projects do not duplicate functionality or diverge from each other and business and DTS strategies.

Shapes, designs, and plans specific service lines in product area and manages the risks associated with information and DTS assets through appropriate standards and security policies.

Functions as the Subject Matter Expert (SME) to maintain an understanding of Client DTS business and clinical applications and the relationship to InfoSec and compliance solutions; assist Hospital stakeholders in understanding information protection needs that support the Hospital's business.

Works with other architects to provide a consensus-based enterprise solution that is scalable, adaptable and in synchronization with ever changing business needs and takes ownership of a particular solution offering.

Works with highly matrixed team of DTS personnel to support enterprise architecture and information security operations including, but not limited to, architecture and InfoSec principles around identity & access management models, cloud identify management providers, security information and event monitoring, and data loss prevention, perimeter (e.g. firewalls, IPS, web filtering), cloud and virtualization environments and network security (host-based firewalls, anti-virus, disk encryption).

Support and/or lead activities around InfoSec standards for business continuity and change management activities (e.g., table tops and change review board) and educates DTS Hospital management on security issues (e.g., Identity and Access Management (IAM), Role Based Access Control (RBAC) models.

Skills:

Demonstrates comprehensive knowledge and understanding of Information security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.

Exhibits knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, ISO 27000 series).

Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.

Good knowledge of basic database query techniques & data mining to analyze data or other related database functionality.

Knowledge of Microsoft Active Directory, UNIX, and Clinical Applications a plus.

Experience implementing application-level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience a plus.

General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.

Microsoft, UNIX, Lawson, and Clinical Applications,

Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, Project).

Experience with risk management frameworks.

Information Security Requirements

Understand and comply with all enterprise and IS departmental information security policies, procedures and standards.

Support the integration of information security in the development, design, and implementation of Hospital Technology Resources that process, transmit, or store Client information.

Support all compliance activities related to state, federal regulatory requirements, healthcare accreditation standards, and all other applicable regulations that govern the use and disclosure of patient, financial, or other confidential information.

Job Tags

Permanent employment, Temporary work, Part time, Remote work,

Similar Jobs

ZOE International

Fundraising Development Intern Job at ZOE International

 ...Fundraising Development Spring/Summer Intern Location : Santa Clarita, California Time Commitment : Monday-Friday; 15-30 hours per week...  ...and building relationships to advance our mission. This internship is an excellent opportunity for individuals interested in... 

CEL - Critical Power

EHS Officer Job at CEL - Critical Power

 ...multicultural, hard-working team. About The Role: Reporting to our QEHS Manager, we are seeking a highly experienced EHS Officer to ensure compliance and continuous improvement with our environmental, health and safety systems, ensuring compliance with all US... 

Apex Systems

Hybrid CSR II: Billing & Enrollment (Contract-to-Hire) Job at Apex Systems

A staffing firm is seeking a Customer Service Representative II for a hybrid role in New York. The candidate will assist Medicaid Providers with inquiries, process transactions, and maintain database records. Applicants should have a High School Diploma or GED and 2+ years...

Tockwotton on the Waterfront

Activity Assistant Job at Tockwotton on the Waterfront

 ...Activity Assistant -- Part time The Activity Assistant is responsible for facilitating activities that enhance the psycho-social well being of the resident. They will be conducting various activities that will help promote brain stimulation, exercise, and friendships... 

Solomon Page

Travel Progressive Care Unit Registered Nurse - $2,289 per week Job at Solomon Page

 ...Solomon Page is seeking a travel nurse RN PCU - Progressive Care Unit for a travel nursing job in Derry, New Hampshire. Job Description & Requirements...  ...concierge, membership-based access to virtual primary care, urgent care, mental health therapy, a vision program, and...