Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Engineer

Software Technology Inc

Info Security Engineer Onsite

3 Month Contract to Hire

Major Responsibilities

• The primary role of the Information Engineer, Information Security (IAM) is to support the daily operations of the IAM team by providing support for access management activities.

• This position will work with peers and technology owners to execute on continuous improvements with regards to IAM processes, with a primary focus on implementing Identity and Access control systems and support of core Identity and Access Management processes and system, while ensuring core assets are only accessible by authorized personnel and rights & privileges are appropriately managed.

• Key responsibilities include the support of core IAM systems, including Active Directory, Office365, Okta, CyberArk and other various applications, as well as managing requests and incidents through their ticketing system, and change control releases via the company’s change management tools.

• This role will also be responsible for designing and implementing all aspects of company identity and access management strategy – from single sign-on, self-service password request, dynamic multi-factor authentication, including expanding the scope of IAM to include 3rd parties, vendors, partners, and affiliates, as needed.

• The incumbent is also responsible for creating and implementing best practices and standards-based approaches as it relates to cloud security access controls in general and the integrations that are required for hybrid, cloud and service environments.

• Knowledge of security controls, frameworks, and standards such as PCI, HIPAA, etc. are required.

• Design, build, provide implementation guidance and support a diverse set of network infrastructure and security technologies focused on security services operation (e.g. firewall management, proxy services, security incident and event management, patching, etc.).

• Provide support to other members of the IAM team in managing technologies such as Okta (identity and access management), CyberArk (privileged management), two-factor authentication solutions, etc.

• Develop Role-Based Access Control (RBAC) models for system authentication and authorization.

• Responsible for IAM team’s Identity Governance, Administration and Automation initiatives.

• Implement RBAC controls and workflows within an Identity and Access Management (IAM) solution.

• Identify improvements and enhancements to current systems based upon business requirements.

• Integrate with multiple other applications and platforms using API’s or custom connectors

• Evaluate, propose, and leverage resources and solutions where appropriate that is scalable and cost-effective including in-house, on-premise, cloud, hybrid, hosted.

• Assist in various compliance efforts as needed, including HITRUST, HIPAA, and PCI.

• Research and leverage IT / IT security trends and emerging technologies to create business value consistent with the company's needs and growth expectations.

• Work collaboratively with information security team members and business stakeholders includes building solid, trust-based relationships with client stakeholders.

• Remain current on industry trends in cyber risk with industry standards and regulatory requirements (e.g., ISO27001/2, NIST Cyber-Security Framework, CIS 20, etc.)

• Ensure appropriate visibility of critical business assets, including customer data e.g. PHI, PII and ensure appropriate security controls to enhance patient, customer, and user experience as well as maintain high levels of customer satisfaction and data security.

• Ensure operational reliability and support of IT services delivered to our patients, customers, and users are according to defined SLA metrics for confidentiality, integrity, and availability from a design, architecture and integration perspective.

• Other duties as assigned by management.

Required:

• Bachelor’s Degree from an accredited college in IT/Information Security, Computer Science, IT, Engineering or related field. In lieu of degree 5+ years of experience is required or the equivalent combination of education and experience.

• Must have at least 3+ years of implementing identity and access management solutions, Role-Based Access Control (RBAC) in a medium-large sized organization (5,000+ users) with products such as Okta, Ping Identity, DUO, SecZetta, etc.

• 2+ years of experience with Okta, configuring application SSO using OIDC or OAuth token services, Okta Access Gateway for legacy SSO, or privileged access with Advanced Server Access

• 2+ years of experience with PowerShell scripting focused on user management tasks and routines.

• 1+ years of experience with utilizing APIs using API testing tools such as Postman. • Experience with access control on at-least one large scale ERP solution. Healthcare EMR such as Epic, Cerner, or Allscripts preferred.

Preferred:

• One or more security certifications such as CISSP, SSCP, Security +, CISM, CISA, or equivalent / Certified Okta Professional or Certified Okta Developer is considered a plus.

• Working knowledge of cloud provisioning strategies (i.e., SCIM, JIT, etc.)

• Good understanding of API, Web Services and Micros Services

• Experience in a multi-regional healthcare, retail, or dental company.

Knowledge/Skills/Abilities:

• Demonstrated experience in creating strategies, roadmaps and execution plans for successfully delivering the identity and access capabilities at other organizations.

• Must possess strong communication skills ensuring consistency from a technical to non-technical perspective and everything in between. • Knowledge of core Information Security frameworks, standards such as ISO 27001, NIST, SANS, HITRUST, HIPAA, PCI, etc. is essential, including experience using GRC tools for reporting, analysis, measurements, etc. Experience in protecting electronically protected health information (ePHI) and sensitive customer personally identifiable information is desirable.

• The ideal person will be a dynamic, ambitious, humble, technically competent, hands-on self-starter with strong communication, leadership and organizational development skills.

• Knowledge of business and management principles involved in strategic planning, resource allocation, human resources, leadership techniques, production methods, and coordination of people and resources. Notwithstanding any of the foregoing described job responsibilities, employee shall not engage in activities that constitute the practice of dentistry as prohibited under applicable law.

• Employee shall neither exercise control over nor interfere with the clinician-patient relationship.

• Clinicians shall have sole responsibility for all professional dental services provided to patients.

• Leadership capability with skills in team building and motivating people.

• Ability to plan, organize, schedule, prioritize and manage workload and resources to execute reliably in Strong Project Management skills – Ability to plan, organize based on priority. • Able to work with multiple project teams simultaneously and thrive in a fast-paced environment.

• Interpersonal and collaboration skills to partner effectively with internal business partners, vendors, consultant resources, including the ability to be both directive and collaborative as appropriate to the situation.

• Ability to multi-task effectively without compromising the quality of the work.

• Ability to respond to common inquiries from customers, staff, regulatory agencies, vendors, and other members of the business community.

• A self-motivated, reliable individual capable of working independently as well as part of a team.

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Engineer. Be the first to apply!