USNLX Ability Jobs

USNLX Ability Careers

Job Information

Banner Health Cybersecurity Engineer III - Firewall in Arizona, Arizona

Primary City/State:

Arizona, Arizona

Department Name:

IT Network Services

Work Shift:

Day

Job Category:

Information Technology

Good health care is key to a good life. At Banner Health, we understand that, and that’s why we work hard every day to make a difference in people’s lives. Do you like the idea of making a positive change in people’s lives – and your own? If so, this could be the perfect opportunity for you.

Our team is Firewall Services within the Infrastructure department and our team supports all perimeter Palo Alto firewalls that protect all hospitals, clinics, MOBs, etc. from security breaches such as patient PHI and PII data.

As Banner continues to leverage technology to deliver the highest quality of possible care, Cybersecurity is a top priority. Firewalls Services is responsible for planning, implementing, managing, monitoring, and upgrading security measures for the protection of the organization's data, systems, and networks as well as troubleshooting security and network platforms. This position ensures that the organization's data and infrastructure are protected from insider and outsider threats by enabling the appropriate security controls while responding to all system and/or network security breaches.

As a Cybersecurity Engineer III , you will be on the front lines and help investigate and remediate cybersecurity incidents, escalate cybersecurity incident as defined by procedure, and help liaise closely other teams to ensure the correct response and remediation of cybersecurity incidents. Also in the CSE III role, you will be an innovator and SME within design and architecture as well as helping see major Cyber Security projects through to completion within the Banner team. The location for this role can be local to Arizona or remote and will include on call duties. The typical schedule for this role is Monday-Friday 8AM-5PM AZ time. Banner Health IT was awarded Inside Pro and Computerworld's 100 Best Places to work in IT for 2020, 2021, 2022 and 2023!

Your pay and benefits (Total Rewards) are important components of your Journey at Banner Health. Banner Health offers a variety of benefit plans to help you and your family. We provide health and financial security options, so you can focus on being the best at what you do and enjoying your life.

Within Banner Health Corporate, you will have the opportunity to apply your unique experience and expertise in support of a nationally-recognized healthcare leader. We offer stimulating and rewarding careers in a wide array of disciplines. Whether your background is in Human Resources, Finance, Information Technology, Legal, Managed Care Programs or Public Relations, you'll find many options for contributing to our award-winning patient care.

POSITION SUMMARY

This position leads the designs, develops, configures, implements, tunes, maintains solutions, resolve technical and business issues related to cybersecurity threat & vulnerability management, identity management, security operations center, forensics, and data protection. Cybersecurity Engineers work with Cybersecurity Architects to execute strategic cyber initiatives, evaluate security components of the network, applications and end-user devices, and provides guidance to ensure new systems meet regulatory and technical standards. Cybersecurity Engineers leads root-cause analysis on Cyber systems to determine improvement opportunities when failures occur. Cybersecurity Engineers work closely with other IT organizations to ensure cyber products are working and integrating with non-cyber environments (apps, networks, End User devices, Servers, etc).

CORE FUNCTIONS

  1. Proactively initiates the design and implementation of cybersecurity solutions, upgrades, enhancements, while looking forward three to five years.

  2. Leads in providing technical expertise and support for cybersecurity solutions, including operational aspects of the software.

  3. Serves as subject matter expert in the design, implementation, and compliance of secure baseline configurations for applications and infrastructure components.

  4. Proactively initiates technical assessments of systems and applications to ensure compliance with policy, standards and regulations. 

  5. Authors new cybersecurity standards and procedures. Leads the revision of existing cybersecurity policies, standards, and procedures, as needed. 

  6. Serves as technical leader for cybersecurity projects, including the development of project scope requirements, budgeting, work breakdown and operational handoff.

  7. Identify threats and develop suitable defense measures, evaluate system changes for security implications, and recommend enhancements, research, and draft cybersecurity white papers, and provide first-class support to the cybersecurity operations staff for resolving difficult cybersecurity issues.

  8. Under limited direction, self starter, this position is responsible for cybersecurity across multiple departments system-wide and requires interaction at all levels of staff and management. Work closely on cross functional IT Teams. Leads work through indirect leadership across other cyber resources. Articulate complex Security functions into simple business ease.

MINIMUM QUALIFICATIONS

Must possess strong knowledge of business, information security and/or computer science as normally obtained through the completion of a bachelor's degree.  Bachelor’s Degree in Computer Science, Information Security, Information Systems, or related field, or equivalent.

Experience normally obtained through seven plus years of experience of enterprise-scale information security engineering, preferably in healthcare. Must also possess three plus years’ experience in a healthcare environment or an equivalent combination of relevant education, technical, business and healthcare experience. 

Experience with IT operations, automation of security processes, coding and scripting languages, ability to document security processes as well as use case development. Experience with the assessing cyber products, including vendor selection, define requirements, contractual documentation development. Experienced assessing and reaching out to vendors for needed features via enhancement requests. Expert understanding of regulatory and compliance mandates, including but not limited to HIPAA, HITECH, PCI, Sarbanes-Oxley. Experienced in planning, designing and implementing cybersecurity solutions, operating, maintaining and managing the lifecycle of cybersecurity solutions. Advanced knowledge of Security Engineering Principles, including risk management, resilience, vulnerability management, Information Security, NIST, MITRE ATT@CK, etc. Advanced expertise in Cyber products supporting Data Loss Prevention, EDR, AntiVirus, Perimeter services, threat systems, cyber platform analytics, SIEM, CASB, CLOUD Security, ETC. Proven Cloud Security experience. Requires independent judgment, critical decision making, excellent analytical skills, with excellent verbal and written communications. Ability to think quickly under difficult or complex conditions and clearly communicate to appropriate staff; ability to balance project workloads with customer support and on-call demands. Must demonstrate deep knowledge of information technology and information security principles and practices. Requires communication and presentation skills to engage technical and non-technical audiences. Requires ability to communicate and interact across facilities and at various levels. Incumbent will have skills to mentor less experienced team members. As is typical in this industry, variable shifts and hours and responding to after-hours notifications may be required. 

PREFERRED QUALIFICATIONS

Certification in two or more of the following areas Systems Security Certified Practitioner (SSCP), HealthCare Information Security & Privacy Practitioner, (HCISPP), CompTIA Security+, Certified Information Systems Security Professional (CISSP) – Engineering (ISSEP), Certified Ethical Hacker (CEH), SANS GIAC, or Certified Information Systems Auditor (CISA).  Four plus years as a System Administrator or in IT Operations. Or four plus years in risk management or GRC experience in the healthcare/medical environment. Five plus years’ experience in a healthcare environment or an equivalent combination of relevant education, technical, business and healthcare experience. 

Additional related education and/or experience preferred.

EOE/Female/Minority/Disability/Veterans (https://www.bannerhealth.com/careers/eeo)

Our organization supports a drug-free work environment.

Privacy Policy (https://www.bannerhealth.com/about/legal-notices/privacy)

EOE/Female/Minority/Disability/Veterans

Banner Health supports a drug-free work environment.

Banner Health complies with applicable federal and state laws and does not discriminate based on race, color, national origin, religion, sex, sexual orientation, gender identity or expression, age, or disability

DirectEmployers