Mayo Clinic→
Information Security Engineer - IS Mod at Mayo Clinic in Rochester, MN
Entry LevelHybridFull-timeRochester, MN$100k–$140k/yr
Skills
endpoint security infrastructureinformation security toolsserver configurations and controlssecurity infrastructure hardware and softwarenetwork vulnerability mitigationcomputer evidence analysiscisspgseccismhcispposcpcapacity to work independentlywillingness to seek advice/assistance
Job Description
Summary: Mayo Clinic is a renowned healthcare organization seeking an Information Security Engineer to join their Email-Endpoint-PKI Security Team. This role involves collaborating with security engineers to modernize and support the endpoint security infrastructure, ensuring a safe and compliant environment while assisting various business units with security design and technology implementation.
Responsibilities:
- Collaborate with a team of security engineers to modernize and support Mayo Clinic's endpoint security infrastructure and practices
- Work collaboratively across the IT and Risk departments to ensure a safe, compliant, and resilient endpoint environment in support of the Information Security Modernization Program for Endpoint Protection
- Act as an information security liaison to various business units and the information technology department to assist with the security design, consultation, and technology implementation for various Mayo Clinic projects and initiatives
- Assist system users relative to information systems security matters and undertake moderately complex projects requiring additional specialized technical knowledge
- Work with business partners within the department to achieve organizational and OIS goals
- Develop required competencies by mastering fundamental tasks
- Analyze technology security posture and appropriate use of security defenses
- Match technical solutions with business requirements and then participate in their design and implementation
- Engage in software development, testing, support/problem solving, and overall technology administration
- Understand organizational procedures such as the system development lifecycle
- Use defensive measures and information to identify, analyze and report security events
- Research and understand pertinent information technology laws, policies and procedures
- Establish timelines and delivery of requirements
- Apply IT-related laws and policies, and provide IT-related guidance throughout the software acquisition lifecycle
- Collect and analyze information to identify vulnerabilities and potential for exploitation
- Manage and administer processes and tools that enable the organization to identify, document, and access intellectual capital and information content
- Execute duties governing hardware, software, and information system acquisition programs and other program management policies with support
Required Qualifications:
- Master's Degree or a Bachelor's degree in Computer Science, Information Systems, Engineering or related major and a minimum one (1) year experience in the information security field required, OR Associates degree and two (2) years' experience in the information security field
- Understands the use and efficacy of information security tools, server configurations and controls with the ability to install, configure, test and operate them
- Able to test, implement, deploy, maintain, review and administer the infrastructure hardware and software required to effectively secure the enterprise, protect data, identify and mitigate risks
- Ability to collect, process, preserve, analyze and present computer related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence or law enforcement investigations
- Provides technical opinions/conclusions re. security tools, trends, and controls which are supported by documented evidence, based on multiple perspectives and leverage of a variety of resources
- Demonstrates knowledge of standard operating procedures, workflows and supporting technology across numerous critical user areas and an in-depth knowledge of multiple computing technologies either being actively used or of significant interest to Mayo; understands how systems fit into larger picture of technology at Mayo
- Capacity to work independently and willingness to seek advice/assistance
- Must have one of the following certifications (or equivalent) at time of hire: CISSP, GSEC, CISM, HCISPP, OSCP. In lieu of certification at time of hire, candidate must pass the exam within two years, and complete the certification process once years of service requirements of the certifying body have been met
Required Skills: Endpoint security infrastructure, Information security tools, Server configurations and controls, Security infrastructure hardware and software, Network vulnerability mitigation, Computer evidence analysis, CISSP, GSEC, CISM, HCISPP, OSCP, Capacity to work independently, Willingness to seek advice/assistance
Benefits: Benefits Eligible: Yes, Flexibility of both remote and on-site work, Hybrid, which requires that the selected applicant lives within 100 miles of a main Mayo Clinic site for periodic on-campus work, On-call rotation participation is required
Benefits
Benefits Eligible: Yes
Flexibility of both remote and on-site work
Hybrid, which requires that the selected applicant lives within 100 miles of a main Mayo Clinic site for periodic on-campus work
On-call rotation participation is required