Do you want to join an organization that invests in you as a(an) Security Engineer? At HCA Healthcare, you come first. HCA Healthcare has committed up to $300 million in programs to support our incredible team members over the course of three years.
Job Summary and Qualifications
The IPS Field Security Engineer will support Division and Facility Network/System Engineers and Administrators by analyzing a wide range of applications, network configurations, and security architectures to ensure the security, integrity, and regulatory compliance of critical information transmitted or stored within the enterprise. Their role is to facilitate the discovery of information and IT-related risks, apply critical thinking to assumptions and develop the right security position/priorities that: first, attain compliance; second, address the material risks to the company while allowing the business to attain its objectives. This position blends cybersecurity engineering with system infrastructure expertise to support risk management, threat mitigation, infrastructure reliability, and compliance with IT and security standards.
The IPS Field Security Engineer will work across multiple domains of information security (i.e. Security and Risk Management, Asset Security, Security Architecture and Engineering, Network Security, Identity and Access Management, Security Assessment and Testing, and Security Operations), providing consultation, assessments, and security/technical guidance to business units and IT teams.
Risk Management and Security Consulting
Serves as an internal information security consultant to the enterprise while balancing the needs of the business.
Research and recommend solutions that meet security standards while ensuring functionality for business continuity.
Drive and manage execution of corrective actions to address deficiencies identified during risk assessments.
Drive targeted security risk reduction within IT
Augment IT resources by prioritizing, coordinating, and performing security Division and Facility hygiene activities.
Support implementation & configuration of security controls.
Translate security standards and regulatory requirements into actionable technical and business requirements.
Lead and support the IPS program by assessing new applications and technologies and ensuring they are implemented in accordance with company standards
Partner with appropriate stakeholders on vulnerability remediation
Engage in Architecture Review Committee discussions to identify and address Third Party solution variance from company standards
Support, coordinate, and manage incident response and investigation activities
Evaluate and recommend security solutions that balance risk mitigation with business functionality
Drive ongoing compliance with IPS policies, standards, and operational procedures
Serve as an internal security consultant across business units to provide technical security consultation on appropriate controls that balance business and security requirements.
Provide hands-on support for corporate-driven security efforts
Manage operational processes that monitor and respond to potential security threats
Security Engineering & Architecture
Evaluate new and proposed security technologies and assist in their integration
Identify appropriate security controls as part of the field intake process and ensure security controls are implemented and configured.
Assist in the design and implementation of secure network, application, and system architectures
Educate ITG colleagues on security policies and standards to help ensure compliance.
Partner with IT colleagues to assure ongoing maturity of IT operational security controls.
Participate in the development and testing of disaster recovery and contingency plans
Security Operations and Threat Management
Partner with corporate and local departments as required to facilitate rapid response to cybersecurity events and determine appropriate technical mitigations as necessary.
Maintain awareness of emerging threats, vulnerabilities, and mitigation techniques.
Coordinate Cyber Defense Center (CDC), MSSP, and Cyber Problem Effort and Resiliency (CPER) response efforts and report on progress
Augment IT response capabilities by providing hands-on technical support and remediation
Partner with IPS Facility Security Analyst and DISA to oversee processes for review and approval of security exception requests.
Vendor Systems Security
Partner with appropriate business and IT leadership to help ensure systems, services, and devices receive appropriate assessments and remediation as part of local on-boarding processes.
Partner with business and IT leadership to ensure proper controls are in place for existing vendor-maintained solutions.
Work with vendors to remediate security vulnerabilities in response to security events
Education & Experience:
Bachelor's degree and 3+ years of experience in a relevant field, REQUIRED
or
High School Graduate/Equivalent and 3+ years' experience in related field REQUIRED
Master's degree PREFERRED
3+ years of experience in security risk management, information security domains, and/or hospital operations. PREFERRED
Licenses, Certifications, & Training:
CISSP, CISA, CISM, CCNA, or other relevant certifications in network administration, information security or cyber risk management PREFERRED
Knowledge, Skills, Abilities, Behaviors:
Knowledge of supported operating systems (Windows server and VMware ESX), utilities, vendor products, applicable programming languages and scripting, diagnostic techniques, applicable communications protocols, applicable hardware configurations
Must have 1+ years of experience in deploying technically complex infrastructure computing solutions across platforms and components.
Knowledge of virtual technology, such as, Citrix, VMWare ESX, IBM LPARs, VIO servers, and micro partitions.
Knowledge of OS environment running one or more databases including SQL, Oracle, DB2.
Experience in one or more of the following: NetBackup, Data Domain, or CommVault
Applicable communication protocols and hardware configurations
Statistical and analytical tools for systems monitoring
Working knowledge of information security concepts, including risk management, engineering, networking, and cloud.
Understanding of cloud fundamentals and concepts, as well as experience with a popular cloud provider, like Microsoft, Google, or Amazon.
Excellent written and oral skills
Demonstrates a high degree of initiative, dependability, and the ability to work with minimal supervision.
Possesses a sense of responsibility and accountability - one who takes ownership and initiative.
Creative thinker, always looking for a "better way" to deliver value; not stopped or discouraged by adversity.
Maintains professional demeanor, appearance, and positive attitude.
Adaptable and flexible, with the ability to handle ambiguity and sometimes changing priorities.
The job may require up to 50% travel. (Mostly within the Division)
Benefits
HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
Wellbeing support, including free counseling and referral services
Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
Savings and retirement resources , including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts
Learn more about Employee Benefits (https://careers.hcahealthcare.com/pages/employee-benefits-and-rewards)
Note: Eligibility for benefits may vary by location.
"Good people beget good people."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
We are a family 270,000 dedicated professionals! Our Talent Acquisition team is reviewing applications for our Security Engineer opening. Qualified candidates will be contacted for interviews. Submit your resume today to join our community of caring!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.