Post job

Security Engineer jobs at Community Health Systems - 457 jobs

  • Cyber Security Engineer Sr

    Community Health Systems 4.5company rating

    Security engineer job at Community Health Systems

    As a member of the Community Health Systems (CHS) Cyber Security Team, the Cyber Security (IAM) Engineer, Sr will be responsible for design, implementation, and support of IAM integrations, with a strong focus on automating user provisioning lifecycle processes across a wide range of enterprise applications. The engineer role will serve as subject matter expert for Sailpoint ISC environment and work with cross functional teams to mature the platform and ensure it meets business and application needs. Essential Functions Design, develop, implement, and support enterprise Identity and Access Management (IAM) systems and solutions. Serve as a Subject Matter Expert (SME) for SailPoint Identity Security Cloud (ISC), providing guidance and support for integrations across a wide range of applications Lead the implementation of core IAM functions, including Joiner-Mover-Leaver (JML) lifecycle processes, role management, connector integrations, provisioning policies, rules, transforms, and workflows. Work with a variety of applications and systems, including Active Directory, Ping, GSuite, and more, to support identity integrations and access management processes. Knowledge of working with medical applications like Med host, Cerner is desirable Collaborate with enterprise architecture and business stakeholders to drive the strategic growth and maturity of the IAM program. Maintain continuous oversight of the IAM environment to ensure security, system integrity, and operational stability. Proactively identify security vulnerabilities, conduct risk assessments, and implement remediation measures to strengthen the overall identity security posture and reduce exposure to threats. Track and analyze IAM-related metrics, using insights to drive improvements in system performance, access governance, and operational efficiency. Partner with audit, compliance, application owners, and business teams to support ongoing operations and new business initiatives. Work with teams to proactively troubleshoot and resolve critical issues, and performing root cause analysis to maintain system availability, health, and continuous access provisioning/deprovisioning to applications. Work with internal audit and compliance teams to ensure IAM platform aligns with internal policy requirements, respond to audit requests, provide required documentation and evidence reports. Build and review business and technical requirements, solution designs, and use case documentation to support the successful implementation of IAM functionalities. Maintain up-to-date documentation including architecture diagrams, technical specifications, and run books to support onboarding applications, cross-team collaboration, and smooth handoffs across IAM-related projects. Business and Soft Skill expectations: Communicate and interact effectively and professionally with co-workers, management, customers and vendors. Communicate with management regarding development within areas of assigned responsibilities and perform special projects as required or requested. Qualifications Bachelor's Degree in Cyber Security, Computer Science, Information Systems (or other related field) or equivalent work experience 6+ years of Identity and Access Management 4+ years of Sailpoint experience 2+ years of Sailpoint ISC experience Knowledge, Skills and Abilities Deep knowledge of cyber security tools, techniques, and standards across infrastructure, applications, and cloud environments. Strong understanding of security frameworks including NIST, CIS, and ISO 27001. Ability to analyze complex technical and business problems and develop effective, scalable solutions. Skilled in incident response, forensic analysis, and root cause determination. Excellent written and verbal communication skills, with the ability to clearly convey technical concepts to non-technical audiences. Licenses and Certifications Relevant security certifications such as CISSP, CISM, GIAC, or CEH required Additional technical certifications (e.g., Azure Security Engineer, AWS Security Specialty) preferred
    $87k-113k yearly est. Auto-Apply 28d ago
  • Job icon imageJob icon image 2

    Looking for a job?

    Let Zippia find it for you.

  • Senior Security Engineer, Apps

    Hinge-Health 4.4company rating

    San Francisco, CA jobs

    About the role We're looking for a detail oriented, technically skilled engineer to join our Application Security team. This role offers opportunities to influence the group's growth and direction while integrating security within the entire Software Development Life Cycle (SDLC). Security Engineers will collaborate with Product and Engineering teams to embed security into all phases of the SDLC from feature design and implementation to deployment. They also establish and evaluate authentication, authorization, and privacy controls for B2C, B2B and M2M entity types and use cases. They will identify, prioritize, and remediate vulnerabilities identified via internal and third party penetration testing, Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST). They will also deploy, maintain and tune the tools used to perform this testing. Security Engineers serve as subject matter experts on authentication and authorization security, partnering with product and engineering teams to implement security and privacy best practices for healthcare applications. The ideal candidate will have experience securing, hardening, and identifying vulnerabilities in web applications, RESTful and GraphQL APIs, and mobile applications (iOS and Android) in a cloud hosted microservice environment. The ideal candidate will also have experience risk assessing the results of automated SCA, SAST and DAST to validate severity before assigning to engineers for remediation. They may also have experience in securing Generative AI LLM services, including, but not limited to security guardrails to prevent jailbreaks, sensitive information disclosure, data/model poisoning, and safety guardrail verification and testing. What You'll Accomplish Implement and maintain automated security scanning tools (SCA, SAST, DAST) and perform manual and AI assisted security assessments including source code review to identify and remediate vulnerabilities in Hinge Health web applications, mobile applications and API endpoints. Enable the product teams to create secure by design product features and services by working alongside product managers and engineers during the design phase of projects including Generative AI projects. Assist with third party security assessments and penetration tests of Hinge Health web applications, API endpoints, and mobile applications, including interpretation of results and verification of remediations. Contribute to the improvement of Software Development Life Cycle management policies, procedures, and standards. Basic Qualifications 3+ years of experience in application security, product security, or related security engineering roles Experience securing web applications, mobile applications (iOS/Android), or API endpoints Experience with automated security testing, including configuring and automating security scans as part of the CI/CD process, and interpreting the results and working directly with engineers on prioritization and remediation. Experience in examining source code in multiple languages to evaluate security controls and identifying common coding and design vulnerabilities. Experience with OWASP Top 10 and other common security flaw patterns. Demonstrated ability to collaborate with engineering and product teams to address security concerns. Preferred Qualifications Experience securing applications in Health Care, securing ePHI and HIPAA/HITECH regulations. Experience with modern authentication and authorization technologies including OAuth 2.0, OIDC, SAML, JWT validation, SSO integrations, MFA/OTP implementations, API tokens, and identity platforms such as Auth0 or Okta. Understanding of session management, refresh tokens, and secure authentication flows for B2C, B2B, and M2M use cases. Experience assessing the security and safety of Generative AI LLM solutions and in evaluating and implementing solutions for their continuous monitoring Familiarity with HITRUST CSF and NIST control frameworks. Experience in Threat Modeling Experience performing security assessments and secure design of hardware and firmware of medical devices communicating over Bluetooth Experience with any of the following, deploying web based services on AWS infrastructure, Kubernetes, Typescript, ReactNative, Python, Go, Ruby on Rails, GraphQL, IaC using Terraform. Incident Handling: Be able to work as a subject matter expert in the security controls, internal communications, and infrastructure of Hinge Health applications during security incidents. Hinge Health Hybrid Model We believe that remote work and in-person work have their own advantages and disadvantages, and we want to be able to leverage the best of both worlds. Employees in hybrid roles are required to be in the office 3 days/week. The San Francisco office has a dog-friendly workplace program. Compensation This position will have an annual salary, plus equity and benefits. Please note the annual salary range is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. The annual salary range for this position is $192,000 - $230,400. About Hinge Health Hinge Health leverages software, including AI, to largely automate care for joint and muscle health, delivering an outstanding member experience, improved member outcomes, and cost reductions for its clients. The company has designed its platform to address a broad spectrum of MSK care-from acute injury, to chronic pain, to post-surgical rehabilitation-and the platform can help to ease members' pain, improve their function, and reduce their need for surgeries, all while driving health equity by allowing members to engage in their exercise therapy sessions from anywhere. The company is headquartered in San Francisco, California. Learn more at ************************** What You'll Love About Us Inclusive healthcare and benefits: On top of comprehensive medical, dental, and vision coverage, we offer employees and their family members help with gender-affirming care, tools for family and fertility planning, and travel reimbursements if healthcare isn't available where you live. Planning for the future: Start saving for the future with our traditional or Roth 401k retirement plan options which include a 2% company match. Modern life stipends: Manage your own learning and development Culture & Engagement Hinge Health is an equal opportunity employer and prohibits discrimination and harassment of any kind. We make employment decisions without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, pregnancy, or any other basis protected by federal, state or local law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We provide reasonable accommodations for candidates with disabilities. If you feel you need assistance or an accommodation due to a disability, let us know by reaching out to your recruiter. By submitting your application you are acknowledging we are using your personal data as outlined in personnel and candidate privacy policy. #J-18808-Ljbffr
    $192k-230.4k yearly 3d ago
  • Hybrid Senior Security Engineer: Corporate Security Lead

    Persona 4.3company rating

    San Francisco, CA jobs

    A leading identity platform company in San Francisco is seeking a Corporate Security Lead to fortify defenses against evolving threats. This full-time role involves developing endpoint security solutions and collaborating with cross-functional teams. The ideal candidate has over 3 years of IT security experience, including endpoint hardening and scripting skills. Enjoy competitive benefits like unlimited PTO, mental health days, and professional development stipends in a vibrant work culture. #J-18808-Ljbffr
    $135k-181k yearly est. 2d ago
  • Senior Security Software Engineer - Encryption & Auth

    Persona 4.3company rating

    San Francisco, CA jobs

    A leading identity platform company is seeking a Software Engineer to join their Security Team in San Francisco. You will design and maintain security libraries, refine authentication processes, and contribute to the overall protection of customer data. This role offers competitive benefits, including medical, unlimited PTO, and wellness support. Ideal candidates have over 5 years of experience in security software engineering and a passion for proactive problem-solving. #J-18808-Ljbffr
    $135k-181k yearly est. 5d ago
  • Senior Security Engineer, Corporate Security San Francisco

    Persona 4.3company rating

    San Francisco, CA jobs

    Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly. We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live. We're growing rapidly and looking for exceptional people to join us! About the Role Persona's Security Team is looking for someone to lead our corporate security efforts. You'll play a pivotal role in fortifying our defenses against evolving threats. Your mission is to protect fellow Personerds and the systems we use to do our work. You'll have the opportunity to employ cutting-edge technologies, innovative strategies, and your expertise to thwart potential attacks before they disrupt our operations. This is a full-time position based in our headquarters in downtown San Francisco. Our in-office days are Tuesday - Thursday, with the option to work from home on Monday and Friday. What you'll do at Persona Develop, enhance, and implement endpoint detection and response rules and tooling for endpoint devices Collaborate cross-functionally with our TechOps Team in implementing security best practices for SaaS and endpoint environments and support security initiatives like 2-factor authentication, automated encryption of client devices, DLP, etc. Build tools and processes for automating security controls and monitoring at scale Support security initiatives across the organization and harden our corporate infrastructure against attack Recommend endpoint and SaaS mitigations and controls based on generated telemetry Provide recommendations and support for insider threat programs Participate in the on-call rotation for the Security Team What you'll bring to Persona 3+ years of experience in IT security or building endpoint security solutions, including experience supporting mac OS devices Experience with planning and executing endpoint hardening initiatives Experience with mobile device management (MDM) and endpoint detection and response (EDR) tools and technologies Experience with data loss prevention (DLP) and insider threat concepts and mitigations Experience with email security concepts and protecting a workforce against phishing Ability to explain security topics clearly to non-technical business representatives Ability to write code in Ruby, Python, or similar scripting languages, as well as SQL queries Full-time Employee Benefits and Perks For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits are a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor. #J-18808-Ljbffr
    $135k-181k yearly est. 5d ago
  • Senior Security Engineer, Product San Francisco

    Persona 4.3company rating

    San Francisco, CA jobs

    Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly. We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live. We're growing rapidly and looking for exceptional people to join us! About the Role We're building something special here at Persona, and our Security Team is a big part of that. Our team is made up of veterans from industry leaders like Square and Dropbox, and we're looking for someone to join us in shipping innovative products quickly and securely. Your job? Work with our engineering teams to make sure we're delivering rock-solid security for our customers and users. As we grow fast (and we mean fast), you'll be key in managing the risks that come with that speed. We're not just looking for someone to play defense - we want you to think ahead and outsmart the bad guys before they even know what hit them. You'll get to work with the latest tech and come up with clever ways to keep our systems locked down tight. What you'll do at Persona Collaborate cross-functionally with our product teams to understand, manage, and mitigate the security risks associated with their work, while supporting their ability to ship quickly Build tools and processes for automating product security controls and monitoring at scale Support product security initiatives across our fast-growing engineering team Participate in the on-call rotation for the Security Team What you'll bring to Persona Communication and Collaboration skills. Ability to explain security topics clearly to non-technical business representatives. Drive to enable other engineers to ship securely. Bias toward shipping. Improving our product quickly and continually is one of Persona's greatest strengths. You should be excited about finding ways to integrate security into our product delivery processes without slowing things down. Proactive approach to solving problems. We're looking for someone that can tell us how to solve our problems, not someone who waits to be told how to solve problems. Passion for security. You should be excited about keeping your skills and knowledge sharp, and sharing that with your peers and the rest of the company. Experience. 2+ years of software engineering, 2+ years of product security at a fast-moving technology company. Nice to have Experience securing a large Ruby on Rails application. Full-time Employee Benefits and Perks For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits is a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor. #J-18808-Ljbffr
    $135k-181k yearly est. 5d ago
  • Senior Security Engineer - Ship Securely at Speed

    Persona 4.3company rating

    San Francisco, CA jobs

    A leading identity platform in San Francisco seeks a Security Engineer to enhance product security while supporting the fast-paced delivery processes of engineering teams. The candidate will collaborate cross-functionally to manage risks, build security automation tools, and participate in on-call rotations. Required skills include communication, collaboration, and a passion for security, with 2+ years in software engineering and product security at a tech company. This full-time role offers competitive benefits and emphasizes a culture of proactive problem-solving. #J-18808-Ljbffr
    $135k-181k yearly est. 5d ago
  • Senior Security Engineer - Endpoint Defense

    Persona 4.3company rating

    San Francisco, CA jobs

    A forward-thinking technology company in San Francisco seeks a skilled individual to lead their corporate security efforts. In this full-time role, you'll enhance security practices, develop innovative defense strategies, and protect the organization's operations from evolving threats. The ideal candidate has over 3 years of experience in IT security, particularly in endpoint security solutions. The company offers competitive medical, dental, and mental health benefits along with an engaging workplace culture. #J-18808-Ljbffr
    $135k-181k yearly est. 5d ago
  • Senior Engineer, Secure Mfg Software for Medical Devices

    El Camino Health 4.4company rating

    San Francisco, CA jobs

    A leading digital healthcare company in San Francisco is seeking a Software Developer with strong experience in C#. The role involves designing and developing secure software for manufacturing tools, ensuring compliance with medical cybersecurity standards. Candidates should possess a relevant degree and have at least 2 years of experience in a security-focused role. This full-time position offers competitive compensation and excellent benefits. #J-18808-Ljbffr
    $125k-168k yearly est. 1d ago
  • WORKDAY SECURITY ANALYST III

    Moffitt Cancer Center 4.9company rating

    Tampa, FL jobs

    Workday Security Analyst III The Workday Security Analyst III is responsible for leading security processes, governance, and oversight across Workday and related platforms (UKG, Hyland OnBase). This role ensures that security practices align with organizational goals, regulatory requirements, audit standards, SOX and data privacy compliance controls. The Workday Security Analyst III serves as the primary escalation point for Workday security analysts, provides coaching and guidance, and acts as a trusted advisor to leadership on risk mitigation and security strategy. This role maintains a dotted-line relationship to influence and mentor analysts and to support development and performance feedback. Responsibilities: Serve as a trusted advisor to leadership on security strategy, risk mitigation, and compliance. Contribute to technical roadmap meetings to embed security standards into new features and integrations. Monitor emerging threats and recommend proactive enhancements to strengthen Workday security posture. Provide guidance, coaching, and feedback to Security Analysts on best practices, technical approaches, and issue resolution. Mentor and guide Security Analysts across both Governance/Policy and Operations tracks. Maintain a dotted-line relationship with Security Analysts: provide input and influence performance without direct management authority. Define and maintain role-based access control, separation of duties, and domain/business process security. Design and maintain enterprise security architecture for Workday, UKG, Hyland OnBase and other supported platforms. Align Workday security groups with the organization's identity access management tools (e.g., SailPoint). Ensure sensitive data (e.g., SSNs, compensation) is masked or restricted according to policy. Ensure Workday roles do not violate separation of duties. Collaborate with technical and business stakeholders to ensure secure system design and access controls. Lead security governance, role-change approvals, and SOX/privacy compliance controls. Develop and enforce security policies, standards, and governance frameworks. Oversee security audits, assessments, and readiness for internal and external compliance requirements. Support audit processes by providing Workday access logs, while cybersecurity performs cross-system audits. Ensure security practices align with organizational goals and regulatory standards. Lead incident response planning, investigation, and resolution for Workday-related security events. Manage oversight of Workday roles and assignments, while cybersecurity manages enterprise-wide roles. Work with cybersecurity to monitor suspicious activity within Workday. Serve as the primary escalation point for Workday security analysts on complex or high-risk issues. Lead the execution and oversight of Workday security processes, ensuring compliance with governance and audit requirements. Credentials and Experience: Bachelor's degree: field of study - Information Security, Computer Science or a related field Workday Security Certification (within 9 months of hire) 5+ years of experience in enterprise security roles, including architecture, policy, and incident management. Prior Workday Security experience to include minimum of 3 years hands on with progressive responsibilities. Proven experience designing and implementing security frameworks across cloud-based enterprise applications.
    $57k-81k yearly est. 4d ago
  • AI Engineer - Shape Next-Gen AI Systems (SF/NYC)

    Pathwork 3.7company rating

    San Francisco, CA jobs

    An innovative insurance technology company is seeking an AI Engineer to lead the development of cutting-edge AI systems. The role requires 5-10 years of experience, focusing on transforming prototypes into impactful products. Ideal candidates will have a strong background in AI system development, full-stack capabilities, and experience shipping products. You will work closely with founders in a collaborative environment, contributing to meaningful projects within a vibrant culture and hybrid work model. #J-18808-Ljbffr
    $96k-128k yearly est. 5d ago
  • System Engineer II

    El Camino Health 4.4company rating

    San Francisco, CA jobs

    System Engineer II page is loaded## System Engineer IIremote type: Hybridlocations: San Francisco, CAtime type: Full timeposted on: Posted Yesterdayjob requisition id: JR748**Career-defining. Life-changing.**At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions. Every day, we collaborate, create, and constantly reimagine what's possible. We think big and move fast, driven by our commitment to put patients first and improve lives. We need builders like you. Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career**About This Role:**About the RoleAs a Systems Engineer II on the Product Development System Engineering team, you'll play a key role in developing and improving test solutions that enhance our wearable medical devices and manufacturing systems. You will collaborate across disciplines including Electrical, Mechanical, Firmware, Software, and Design Engineering to deliver robust and innovative test tools that ensure product reliability and quality.This role offers the opportunity to develop technical and leadership skills within a highly regulated MedTech environment while contributing directly to products that improve patient outcomes.Key Responsibilities* Collaborate cross-functionally with R&D, manufacturing, and product development teams to design and improve test fixtures and systems.* Develop automated test processes and procedures to support verification, validation, and manufacturing activities.* Create and maintain technical documentation, including Test Plans, System Requirements, and Test Reports.* Analyze test data, derive limits, and verify capability using statistical tools (e.g., GR&R studies).* Utilize bench-top equipment such as power supplies, digital multimeters (DMMs), and oscilloscopes for system evaluation and debugging.* Read and interpret circuit board schematics and layouts.* Ensure all work complies with applicable medical device regulatory standards and internal quality system procedures.Required Qualifications* Bachelor's degree in Electrical Engineering, Biomedical Engineering, or related field (Master's preferred).* 3-5 years of relevant engineering experience in system test, manufacturing test, or product development.* Proficiency in Python or C# for test automation and data analysis.* Strong understanding of test instrumentation and measurement principles.* Excellent documentation, organizational, and communication skills.Preferred Qualifications* Experience with electromechanical or wearable medical devices.* Prior work in a regulated manufacturing or medical device environment.* Experience with design of experiments (DOE), statistical analysis, or measurement system analysis (MSA).* Familiarity with ISO 13485, FDA 21 CFR Part 820, or similar quality system standards.Work Arrangement* Hybrid role - requires a minimum of 50% in-office presence at our San Francisco office.* Applicants must be legally authorized to work in the United States at the time of application and on an ongoing basis.* iRhythm is unable to sponsor or assume sponsorship of employment visas.Why Join iRhythmAt iRhythm, you'll be part of a mission-driven organization that values innovation, collaboration, and impact. We offer a dynamic work environment, competitive benefits, and the opportunity to work on products that make a real difference in patients' lives.**Location:**San FranciscoActual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.**Estimated Pay Range**$91,200.00 - $114,000.00As a part of our core values, we ensure an inclusive workforce. We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer. We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.iRhythm provides reasonable accommodations for qualified individuals with disabilities in job application procedures, including those who may have any difficulty using our online system. If you need such an accommodation, you may contact us at ***********************About iRhythm Technologies** iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm's vision is to deliver better data, better insights, and better health for all.**Make iRhythm your path forward. Zio, the heart monitor that changed the game.**There have been instances where individuals not associated with iRhythm have impersonated iRhythm employees pretending to be involved in the iRhythm recruiting process, or created postings for positions that do not exist. Please note that all open positions will always be shown here on the iRhythm Careers page, and all communications regarding the application, interview and hiring process will come from a @irhythmtech.com email address. Please check any communications to be sure they come directly from @irhythmtech.com email address. If you believe you have been the victim of an imposter or want to confirm that the person you are communicating with is legitimate, please contact *********************. Written offers of employment will be extended in a formal offer letter from an @irhythmtech.com email address **ONLY**.For more information, see and At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. Together, we are reimagining the way cardiac arrhythmias are diagnosed. We need curious problem solvers like you. With opportunities remotely, at our office, in manufacturing, and in locations across the globe, this is your chance to meaningfully shape the future of cardiac health, our company, and your career.**Driven By Purpose** - Cardiac health touches the lives of people all around us. Providing life-changing healthcare solutions that impact patients around the world drives us to bring our best every single day.**Growth Means Opportunity** - We are growing rapidly. And with that growth comes a wealth of opportunities to learn and advance at iRhythm. The potential to deepen your impact, seek new opportunities, and advance your career is yours to pursue.**Build the Future** - We are a boundary-pushing organization that values innovative thinking and impacts healthcare at a global level. The expectation is to think big and build the future you see for iRhythm, our patients, and yourself.### Get In TouchIntroduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match. #J-18808-Ljbffr
    $91.2k-114k yearly 1d ago
  • System Engineer I

    El Camino Health 4.4company rating

    San Francisco, CA jobs

    System Engineer I page is loaded## System Engineer Iremote type: Hybridlocations: San Francisco, CAtime type: Full timeposted on: Posted 3 Days Agojob requisition id: JR747**Career-defining. Life-changing.**At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions. Every day, we collaborate, create, and constantly reimagine what's possible. We think big and move fast, driven by our commitment to put patients first and improve lives. We need builders like you. Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career**About This Role:**As a System Engineer I in iRhythm's Product Development - System Engineering Group, you will contribute to the development and improvement of innovative testing solutions that enhance our products and manufacturing processes. This entry-level position provides an excellent opportunity to grow within the MedTech and wearable device industry, collaborating with cross-functional teams including Design, Firmware, Software, Electrical, and Mechanical Engineering.You will work closely with R&D, product development, and manufacturing teams to design, refine, and support test fixtures and tools for iRhythm's products. This role offers hands-on experience, exposure to multiple engineering disciplines, and a collaborative environment that supports career development.Key Responsibilities* Support the design, development, and validation of test systems for iRhythm's medical devices.* Collaborate cross-functionally with design, software, firmware, and manufacturing teams to enhance testing efficiency and reliability.* Assist in creating and maintaining technical documentation including test plans, system requirements, and test reports.* Contribute to root cause analysis and troubleshooting activities for test and system-level issues.* Participate in continuous improvement initiatives to optimize test processes and tools.* Ensure work complies with quality system and regulatory requirements relevant to medical device development.Required Qualifications* Bachelor's degree in Electrical, Biomedical, or a related engineering discipline (Master's degree preferred).* Familiarity with bench-top lab equipment (e.g., power supplies, DMMs, oscilloscopes).* Ability to read and interpret circuit schematics and PCB layouts.* Basic programming or scripting skills in Python or C#.* Strong written and verbal communication skills for documentation and cross-functional collaboration.* Attention to detail with the ability to follow procedures while contributing innovative ideas.Preferred Qualifications* Experience automating test processes or procedures.* Understanding of statistical analysis and deriving test limits using GR&R or similar methods.* Exposure to electromechanical devices and/or medical device testing.* Familiarity with manufacturing processes or collaboration with manufacturing teams.* Experience with engineering documentation (Test Plans, Requirements, Validation Reports).Work Arrangement* Hybrid role - requires a minimum of 50% in-office presence at our San Francisco office.**Location:**San FranciscoActual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.**Estimated Pay Range**$83,200.00 - $104,000.00As a part of our core values, we ensure an inclusive workforce. We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer. We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.iRhythm provides reasonable accommodations for qualified individuals with disabilities in job application procedures, including those who may have any difficulty using our online system. If you need such an accommodation, you may contact us at ***********************About iRhythm Technologies** iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm's vision is to deliver better data, better insights, and better health for all.**Make iRhythm your path forward. Zio, the heart monitor that changed the game.**There have been instances where individuals not associated with iRhythm have impersonated iRhythm employees pretending to be involved in the iRhythm recruiting process, or created postings for positions that do not exist. Please note that all open positions will always be shown here on the iRhythm Careers page, and all communications regarding the application, interview and hiring process will come from a @irhythmtech.com email address. Please check any communications to be sure they come directly from @irhythmtech.com email address. If you believe you have been the victim of an imposter or want to confirm that the person you are communicating with is legitimate, please contact *********************. Written offers of employment will be extended in a formal offer letter from an @irhythmtech.com email address **ONLY**.For more information, see and At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. Together, we are reimagining the way cardiac arrhythmias are diagnosed. We need curious problem solvers like you. With opportunities remotely, at our office, in manufacturing, and in locations across the globe, this is your chance to meaningfully shape the future of cardiac health, our company, and your career.**Driven By Purpose** - Cardiac health touches the lives of people all around us. Providing life-changing healthcare solutions that impact patients around the world drives us to bring our best every single day.**Growth Means Opportunity** - We are growing rapidly. And with that growth comes a wealth of opportunities to learn and advance at iRhythm. The potential to deepen your impact, seek new opportunities, and advance your career is yours to pursue.**Build the Future** - We are a boundary-pushing organization that values innovative thinking and impacts healthcare at a global level. The expectation is to think big and build the future you see for iRhythm, our patients, and yourself.### Get In TouchIntroduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match. #J-18808-Ljbffr
    $83.2k-104k yearly 5d ago
  • Network Engineer

    Statrad 3.3company rating

    San Diego, CA jobs

    This is a unique opportunity to join a market-leading company in the telehealth industry. We support healthcare providers around the country through our teleradiology services. Using our novel cloud enabled medical image management and interpretation services, we help to advance patient care by facilitating rapid diagnosis from our large network of radiologists and clinical support professionals who all work from their homes. POSITION OVERVIEW We are seeking a Network Engineer to help maintain, secure, and improve the network infrastructure supporting our nationwide teleradiology operations. This role is hands-on and execution-focused, working across on-prem, cloud-connected, and remote access environments. The Network Engineer will collaborate closely with DevOps, security, and IT teams, with senior engineering guidance available for architecture and complex design decisions. The ideal candidate is reliable, security-minded, and comfortable operating in a regulated healthcare environment where uptime and data protection are critical. PRIMARY RESPONSIBILITIES • Maintain and support the company's network infrastructure, including firewalls, VPNs, routing, switching, and network segmentation. • Monitor network performance, availability, and security events; troubleshoot and resolve issues efficiently to minimize downtime. • Support hybrid environments spanning on-prem infrastructure, Azure/AWS services, and remote users. • Implement network security best practices in collaboration with DevOps and cybersecurity teams. • Assist with network-related aspects of compliance efforts (HIPAA, SOC 2, ISO/MDSAP-aligned controls), including documentation and audits. • Participate in planning and executing network changes, upgrades, and maintenance activities. • Maintain accurate documentation of network configurations, diagrams, and procedures. • Participate in client-facing technical calls as needed to help troubleshoot and resolve connectivity issues between client environments and company infrastructure. • Work with vendors and service providers to resolve connectivity issues and support infrastructure improvements. • Other projects and duties as assigned. JOB REQUIREMENTS AND SKILLS • Strong working knowledge of core networking concepts including TCP/IP, DNS, DHCP, VLANs, routing, and switching. • Hands-on experience configuring and supporting firewalls and VPNs (site-to-site and remote access). • Solid understanding of network security principles and best practices in a regulated or security-conscious environment. • Ability to troubleshoot network issues methodically and communicate findings clearly to technical and non-technical stakeholders. • Comfortable working collaboratively with DevOps, security, and IT teams while taking ownership of assigned network responsibilities. EDUCATION AND EXPERIENCE • 5+ years' experience in a networking role. • Professional experience supporting and maintaining production network environments in a business or enterprise setting. • Experience working with network infrastructure in a hybrid environment (on-prem and cloud-connected); Azure/AWS exposure is a plus. • Relevant education, certifications, or equivalent practical experience in networking, systems, or information technology. WORK LOCATION AND CONDITIONS • Corporate office in San Diego. Optional Hybrid Model, 3 days in the office and 2 days remote, with manager approval. • Job Type: Full-time; Non-Exempt. • Minimal travel requirements. REQUIRED TRAININGS • Internal Regulatory and Quality System training required for IT. PAY RANGE Hourly Pay Range: $43.00 - $57.00 The stated pay scale has been implemented to reward employees fairly and competitively, as well as to support recognition of employees' career progress, ranging from entry level to experts in their field, and talent mobility. It reflects the range that StatRad reasonably expects to pay for this position at various levels of experience. The actual starting pay rate for this position will be dependent on a variety of factors, including an applicant's relevant experience, unique skills and abilities, education, market demand, and employer business practices, and will be discussed at the offer stage with the selected candidate.
    $43-57 hourly 2d ago
  • Security Engineer - Application & AI Security (REMOTE)

    Enablecomp 3.7company rating

    Franklin, TN jobs

    EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise and its unified E360 RCM ™ intelligent automation platform to improve financial sustainability for hospitals, health systems, and ambulatory surgery centers (ASCs) nationwide. Powered by proprietary algorithms, iterative intelligence from 10M+ processed claims, and expert human-in-the-loop integration, EnableComp provides solutions across the revenue lifecycle for Veterans Administration, Workers' Compensation, Motor Vehicle Accidents, and Out-of-State Medicaid claims as well as denials for all payer classes. By partnering with clients to supercharge the reimbursement process, EnableComp removes the burden of payment from patients and provider organizations while enabling accelerated cash, higher and more accurate yield, clean AR management, reduced denials, and data-rich performance management. EnableComp is a multi-year recipient the Top Workplaces award and was recognized as Black Book's #1 Specialty Revenue Cycle Management Solution provider in 2024 and is among the top one percent of companies to make the Inc. 5000 list of the fastest-growing private companies in the United States for the last eleven years. Position Summary The Security Engineer (Application & AI Security) will serve as the technical implementation bridge between our security policy team and development operations. The Security Engineer will be embedded with development teams, writing code, configuring systems, and directly implementing security controls across applications, databases, and AI systems during a major Agentic AI platform transformation.Key Responsibilities Bridge security policy and technical execution by translating organizational security requirements into practical, deployable solutions across applications, data environments, and AI systems. Design, build, and deploy security controls across web applications, data pipelines, APIs, and Agentic AI systems to ensure confidentiality, integrity, and availability. Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations, configuration hardening, and secure infrastructure deployment. Develop automation scripts and infrastructure-as-code to integrate security into CI/CD pipelines, enabling continuous compliance, secrets management, vulnerability scanning, and environment hardening. Implement and operationalize AI-specific security frameworks by building guardrails for agentic models, securing data flows, and integrating AI security tooling into development workflows. Perform hands-on technical security assessments, including penetration testing, threat modeling, and code reviews, and directly remediate identified vulnerabilities. Collaborate with cloud and DevOps teams to deploy monitoring and detection controls and ensure secure configuration baselines across environments. Provide practical security guidance and training to developers and engineers during architecture reviews, sprint planning, and project delivery. Continuously evaluate and improve the organization's security posture through testing, feedback loops, and adoption of emerging best practices for AI and distributed systems. Document security architectures, configurations, and implementation patterns to support ongoing operations, compliance, and knowledge sharing. Other duties as required Requirements & Qualifications Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field required 3+ years in hands-on application security, DevSecOps, or security engineering roles. Proven experience building and configuring secure CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, Azure DevOps). Equivalent combination of education and experience will be considered. Deep proficiency with cloud security in AWS, Azure, or GCP environments. Strong implementation experience with infrastructure as code (Terraform, CloudFormation) and container security (Docker, Kubernetes). Strong scripting and automation skills (Python, Bash, PowerShell) for security tooling. Versatility across web/API security, data pipeline security, microservices, and database security. Understanding of security frameworks (NIST, ISO 27001, SOC 2) and compliance requirements (GDPR, HIPAA, PCI-DSS). Hands-on experience deploying and configuring security scanning tools (SAST, DAST, SCA). Excellent communication skills-ability to translate security requirements into working technical implementations. Experience working embedded within cross-functional development teams. Proven track record of hands-on problem-solving in fast-paced development environments. Regular and predictable attendance. To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions Special Considerations & Prerequisites Practices and adheres to EnableComp's Core Values, Vision and Mission. Hands-on experience with AI/ML security, model security, and data governance Technical knowledge of LLM security, prompt injection prevention, and AI agent safety Security certifications (CISSP, CEH, OSCP, CSSLP, or cloud security certifications) Strong coding background in Python, Go, or similar languages. Background in software development or engineering transitioning to security. Direct experience implementing secrets management solutions (HashiCorp Vault, AWS Secrets Manager). Practical experience with zero trust architecture implementation. Familiarity with data security, ETL processes, and data warehouse security. Experience with microservices architectures and distributed systems security. EnableComp is an Equal Opportunity Employer M/F/D/V. All applicants will be considered for this position based upon experience and knowledge, without regard to race, color, religion, national origin, sexual orientation, ancestry, marital, disabled or veteran status. We are committed to creating and maintaining a workforce environment that is free from any form of discrimination or harassment. EnableComp recruits, develops and retains the industry's top talent. As the employer of choice in the complex claims industry, EnableComp takes pride in our continuous commitment to building and maintaining a culture centered around fostering the professional growth and development of our people. We believe that investing in our employees is the key to our success, and we are dedicated to providing them with the tools, resources, and support they need to thrive and grow their career here. At EnableComp, we are committed to living up to our core values each and every day, and we believe that this commitment is what sets us apart from other companies. If you are looking for a company that values its employees and is dedicated to helping them achieve their full potential, then EnableComp is the place for you. Don't just take our word for it! Hear what our people are saying: “I love my job because everyone shares the same vision and is determined and dedicated. People care about you as a person and your professional growth. There is a genuine spirit of cooperation and shared goals all revolving around helping each other.” - Revenue Specialist “I enjoy working for EnableComp because of the Core Values we believe in. EnableComp stands true to these values from empowering employees to ecstatic clients. This company is family oriented and flexible, along with understanding the balance of work, life, and fun.” - Supervisor, Operations
    $82k-110k yearly est. Auto-Apply 60d+ ago
  • Application Security Engineer

    Alignment Healthcare 4.7company rating

    Orange, CA jobs

    Alignment Health is breaking the mold in conventional health care, committed to serving seniors and those who need it most: the chronically ill and frail. It takes an entire team of passionate and caring people, united in our mission to put the senior first. We have built a team of talented and experienced people who are passionate about transforming the lives of the seniors we serve. In this fast-growing company, you will find ample room for growth and innovation alongside the Alignment Health community. Working at Alignment Health provides an opportunity to do work that really matters, not only changing lives but saving them. Together. This position is responsible for identifying, analyzing, and helping with remediate security vulnerabilities within our applications. This role requires a strong understanding of application security principles, hands-on experience with various security testing methodologies, and excellent communication skills to collaborate effectively with development teams and other stakeholders. Job Responsibilities: Conduct static application security testing (SAST), dynamic application security testing (DAST), and interactive application security testing (IAST) on a continuous basis. Identify, triage, and validate security vulnerabilities using both automated tools and manual review. Work closely with software development and DevOps teams to provide clear, actionable guidance on how to fix vulnerabilities and implement secure coding practices. Help integrate security controls and checks into the software development lifecycle (SDLC) and CI/CD pipelines. Drive and support application security reviews and threat modeling. Manage and configure a suite of application security tools, ensuring their effective use and reporting. Stay up-to-date with the latest security threats, trends, and technologies, and conduct research on new vulnerabilities and attack vectors. Contribute to the creation and maintenance of application security policies, standards, and procedures to guide development teams and ensure compliance. Develop and deliver security awareness and secure coding training to engineering teams. Support and lead third-party penetration testing. Job Requirements: Experience: Required: 5-7+ years of progressive experience in information security, with a strong focus on application security testing and vulnerability management. Proven track record of working directly with developers and engineering teams to identify and remediate security vulnerabilities in a fast-paced environment. Experience in a large-scale enterprise environment with complex application portfolios. Preferred: Experience in healthcare or another highly regulated field. Education: Required: Bachelor's degree or equivalent work experience in Computer Science, Information Security, or a related technical discipline. Preferred: Relevant professional certifications such as Offensive Security Certified Professional (OSCP), GIAC Web Application Penetration Tester (GWAPT), or Certified Secure Software Lifecycle Professional (CSSLP) are highly desirable. ISC2 Certified Information Systems Security Professional (CISSP) Specialized Skills: Required: Experience with general threat hunting techniques and tools. Experience with one or more programming languages (i.e., C#, Scala, Python). Essential Physical Functions: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 1. While performing the duties of this job, the employee is regularly required to talk or hear. The employee regularly is required to stand, walk, sit, use hand to finger, handle or feel objects, tools, or controls; and reach with hands and arms. 2. The employee frequently lifts and/or moves up to 10 pounds. Specific vision abilities required by this job include close vision and the ability to adjust focus. Pay Range: $113,332.00 - $169,999.00 Pay range may be based on a number of factors including market location, education, responsibilities, experience, etc. Alignment Health is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, age, protected veteran status, gender identity, or sexual orientation. *DISCLAIMER: Please beware of recruitment phishing scams affecting Alignment Health and other employers where individuals receive fraudulent employment-related offers in exchange for money or other sensitive personal information. Please be advised that Alignment Health and its subsidiaries will never ask you for a credit card, send you a check, or ask you for any type of payment as part of consideration for employment with our company. If you feel that you have been the victim of a scam such as this, please report the incident to the Federal Trade Commission at ******************************* If you would like to verify the legitimacy of an email sent by or on behalf of Alignment Health's talent acquisition team, please email ******************.
    $113.3k-170k yearly Auto-Apply 60d+ ago
  • Lead Info Security Engineer

    Temple University Health System 4.2company rating

    Philadelphia, PA jobs

    The Lead Information Security Engineer plays a crucial role in supervising the improvement, maintenance, and management of Temple Health's information security posture and related technologies. This position entails leading security projects, providing technical guidance and mentorship, overseeing blue team defensive operations and purple team exercises, coordinating vulnerability management, collaborating with business units and stakeholders, representing the security function, and managing vendor relationships including MSSPs, while working with cross functional IT and operational teams to ensure effective implementation and continuous enhancement of security controls and solutions This role requires three days on-site (Tuesday, Wednesday and Thursday) at Temple Health Women's and Families Hospital. Education • Bachelor's Degree in Computer, Information Sciences or Business Administration (Required) or • Combination of relevant education and experience may be considered in lieu of degree (Required) Experience • 3 years experience in a Leading Information Security Programs including mentoring / managing junior security engineers/analysts for organizations (Required) • 5 years experience leading Information security initiatives independently (Required) • 5 years experience with risk assessment tools, technologies, and methods (Required) • 7 years experience with anti-virus software, intrusion detection, firewalls, and content filtering (Required) • General Experience with communicating network security issues to peers and management (Required) • General Experience and knowledge with project management simultaneously leading and coordinating multiple projects (Required) • General Experience leading and mentoring a team in a high performing collaborative team environment (Required) • General Experience and knowledge with an in-depth understanding of hardware configurations, database management tools, query language, and application topologies (Required) • General Experience and knowledge with analyzing, diagnosing, suggesting, and implementing process improvements (Required) • General Experience in Healthcare IT (Preferred) Licenses • Cert Info Sys Security Prof (Required) • GIAC Cert Incident Handler (Preferred) • GIAC Penetration Tester (Preferred) • GIAC Cert Forensic Examiner (Preferred) Your Tomorrow is Here! Temple Health is committed to setting new standards for preventing, diagnosing and treating major diseases in our community and across the nation. Achieving that goal means investing in our employees' success through staff and leadership development. Our recruitment strategy is to attract and retain a diverse, high performing workforce that fosters a healthy, safe and productive environment for our patients and colleagues alike. Your Tomorrow is Here! Temple Health is a dynamic network of outstanding hospitals, specialty centers, and physician practices that is advancing the fight against disease, pushing the boundaries of medical science, and educating future healthcare professionals. Temple Health consists of Temple University Hospital (TUH), Fox Chase Cancer Center, TUH-Jeanes Campus, TUH-Episcopal Campus, TUH-Northeastern Campus, Temple Physicians, Inc., and Temple Transport Team. Temple Health is proudly affiliated with the Lewis Katz School of Medicine at Temple University. To support this mission, Temple Health is continuously recruiting top talent to join its diverse, 10,000 strong workforce that fosters a healthy, safe and productive environment for its patients, visitors, students and colleagues alike. At Temple Health, your tomorrow is here! Equal Opportunity Employer/Veterans/Disabled An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
    $83k-107k yearly est. Auto-Apply 5d ago
  • Lead Info Security Engineer

    Temple University Health System 4.2company rating

    Philadelphia, PA jobs

    The Lead Information Security Engineer plays a crucial role in supervising the improvement, maintenance, and management of Temple Health's information security posture and related technologies. This position entails leading security projects, providing technical guidance and mentorship, overseeing blue team defensive operations and purple team exercises, coordinating vulnerability management, collaborating with business units and stakeholders, representing the security function, and managing vendor relationships including MSSPs, while working with cross functional IT and operational teams to ensure effective implementation and continuous enhancement of security controls and solutions This role requires three days on-site (Tuesday, Wednesday and Thursday) at Temple Health Women's and Families Hospital. Education * Bachelor's Degree in Computer, Information Sciences or Business Administration (Required) or * Combination of relevant education and experience may be considered in lieu of degree (Required) Experience * 3 years experience in a Leading Information Security Programs including mentoring / managing junior security engineers/analysts for organizations (Required) * 5 years experience leading Information security initiatives independently (Required) * 5 years experience with risk assessment tools, technologies, and methods (Required) * 7 years experience with anti-virus software, intrusion detection, firewalls, and content filtering (Required) * General Experience with communicating network security issues to peers and management (Required) * General Experience and knowledge with project management simultaneously leading and coordinating multiple projects (Required) * General Experience leading and mentoring a team in a high performing collaborative team environment (Required) * General Experience and knowledge with an in-depth understanding of hardware configurations, database management tools, query language, and application topologies (Required) * General Experience and knowledge with analyzing, diagnosing, suggesting, and implementing process improvements (Required) * General Experience in Healthcare IT (Preferred) Licenses * Cert Info Sys Security Prof (Required) * GIAC Cert Incident Handler (Preferred) * GIAC Penetration Tester (Preferred) * GIAC Cert Forensic Examiner (Preferred) '395778
    $83k-107k yearly est. 5d ago
  • Data Security Analyst

    Texas Children's Medical Center 4.5company rating

    Houston, TX jobs

    The Data Security Analyst is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through the review of ServiceNow GRC tickets, assessment of associated risks, and preparation of clear, well-documented analyses. This role facilitates security exception reviews, maintains policy governance processes, and ensures organizational alignment to regulatory frameworks such as NIST and HIPAA. The Data Security Analyst collaborates with leaders, business owners, and technical teams to drive effective risk management and maintain audit-ready documentation. Think you've got what it takes? Key Responsibilities GRC Ticket Review & Risk Analysis • Review, triage, and analyze GRC-related ServiceNow tickets. • Identify and document risks, impacts, and business justifications. • Draft clear and complete responses for requestors and stakeholders. • Communicate updates, escalations, and decisions to leaders and service owners. Security Exception Management • Review and evaluate security exception requests to policies and standards. • Determine impact and likelihood using approved methodologies. • Document risk statements, compensating controls, and accountability expectations. • Prepare and communicate risk acceptance recommendations to leadership. • Analyze threats, vulnerabilities, likelihood, and impact to determine overall exposure. • Draft risk assessment summaries, recommendations, and mitigation strategies. • Maintain supporting documentation for audit and compliance review. Policy & Procedure Governance • Facilitate drafting, review, approval, and annual refresh of policies and procedures. • Maintain version control, ensure revisions are documented, and produce finalized clean versions. • Coordinate with policy owners to ensure alignment with internal standards and regulatory requirements. Regulatory & Framework Alignment • Interpret and apply NIST, HIPAA, and organizational control requirements. • Ensure assessments and documentation reflect regulatory and framework expectations. • Provide guidance on compliance requirements to stakeholders across the organization. Knowledge Management • Update and maintain Security Knowledge Articles within ServiceNow. • Ensure articles are accurate, current, and accessible to users. • Collaborate with subject matter experts to identify and close knowledge gaps. Operational Support & Ad-Hoc Assignments • Assist in audit preparation, compliance reporting, and evidence collection. • Support continuous improvement initiatives within the GRC program. • Respond to daily and ad-hoc requests from leadership and internal partners. • Participate in team meetings, special projects, and GRC initiatives. Performance Expectations Quality & Accuracy • Produces high-quality, complete, and well-organized risk analyses, assessments, and documentation. • Ensures all work aligns with NIST, HIPAA, and internal policy requirements. Timeliness • Responds to ServiceNow tickets within defined SLAs. • Delivers assessments and documentation by established deadlines. • Communicates proactively regarding delays or issues. Risk Judgment & Critical Thinking • Applies consistent, well-justified risk ratings and identifies mitigation opportunities. • Escalates high-risk items appropriately and collaborates effectively on resolutions. Communication & Collaboration • Drafts clear, professional communications for leaders, technical teams, and business owners. • Works collaboratively across departments to resolve issues and drive outcomes. Process Ownership • Maintains updated knowledge articles, accurate documentation, and organized tracking. • Demonstrates strong ownership of assigned GRC processes and tasks. Professionalism & Reliability • Maintains confidentiality and handles sensitive information responsibly. • Consistently meets expectations with minimal rework and limited supervision. Adaptability & Initiative • Responds effectively to shifting priorities and ad-hoc needs. • Demonstrates initiative by identifying risks early and suggesting process improvements. Skills & Requirements • Bachelor's degree in computer science required (Good to have Information Security, IT, Compliance, or related field) • 1 year computer management or networking field, including some in information security required • 2-5 years of experience in GRC, compliance, or security roles is preferred. • Familiarity with NIST frameworks, HIPAA Security Rule requirements, and risk methodologies is preferred. • Experience with ServiceNow GRC or similar platforms is a plus. • Strong analytical, communication, and documentation skills is preferred.
    $64k-81k yearly est. Auto-Apply 48d ago
  • Senior Cyber Security Engineer, Vulnerability Management (Remote)

    Community Health Systems 4.5company rating

    Security engineer job at Community Health Systems

    As a member of the Cyber Security team, the Cyber Security Senior Engineer for Vulnerability Management will be responsible for developing, implementing, and operating vulnerability management solutions to identify, classify, and report existing and emerging vulnerabilities detected in enterprise infrastructure. The Senior Engineer will operate within the existing exposure management team as an expert in vulnerability management, ensuring sound practices while designing, growing, and maintaining the vulnerability management program, contributing to vulnerability identification and remediation methodologies, supporting penetration testing practices, report generation, and more. The Senior Engineer will be responsible for seeking out and reporting on vulnerability discoveries and classifications of new vulnerabilities as well as partnering with Threat Intelligence to incorporate current threat activity into risk prioritization. The Senior Engineer will work directly with other security and information technology team members to develop plans for reporting and remediation of vulnerabilities across all operating systems and applications in the enterprise. Essential Duties and Responsibilities Develop, implement, and operate vulnerability management solutions to identify, classify, and report existing and emerging vulnerabilities in enterprise infrastructure including application and multi-cloud technologies. Serve as the subject matter expert in vulnerability management within the exposure management team, contributing to the development, engineering, and maintenance of the vulnerability management program. Apply industry best practices and standards to vulnerability identification and remediation methodologies, penetration testing practices, and report generation. Stay up to date on the latest vulnerability discoveries and classifications, and proactively assess and report their potential impact on the organization's systems and applications. Collaborate with security and IT team members to develop comprehensive plans for reporting and remediation of vulnerabilities across all operating systems, cloud computing systems, and applications in the enterprise. Conduct regular vulnerability assessments, utilizing automated tools and manual techniques to ensure thorough coverage and accuracy. Analyze vulnerability assessment results and provide recommendations for prioritizing and remediating vulnerabilities based on risk and impact. Collaborate with the Threat Intelligence and Incident Response teams to correlate emerging threats with exposure data. Contribute to the development and maintenance of vulnerability management policies, procedures, and documentation. Provide guidance and support to junior team members, fostering knowledge sharing and professional growth within the vulnerability management team. Develop and present metrics, dashboards, and executive reports related to vulnerability trends, SLA compliance and risk posture. Business and Soft Skill expectations: Communicate and interact effectively and professionally with co-workers, management, customers, etc. Maintain complete confidentiality of company business. Communicate with management regarding development within areas of assigned responsibilities and perform special projects as required or requested. Education H.S. Diploma or GED required Bachelor's or Master's Degree in Cyber Security, Computer Science, Information Systems (or other related field), or equivalent work experience preferred Required Experience Duration: 3+ years of IT or information security, and 2+ years of vulnerability management Activities: Practical experience with designing and implementing technologies related to vulnerability management including vulnerability scanning, penetration testing, and configuration management Served as expert thought leader for vulnerability management technologies and influenced the strategy for remediation Worked in process-driven structured environments and participated in process optimization activities. Competencies: In-depth knowledge of CVEs, CVSS, threat modeling, and vulnerability scanning technologies. Familiarity with industry frameworks and standards such as NIST, CIS, and CVSS. Strong understanding of operating systems, network protocols, and web applications. Hands-on experience with vulnerability scanning and assessment tools (e.g., Nessus, Qualys, OpenVAS). Excellent analytical and problem-solving skills, with the ability to prioritize and address vulnerabilities based on risk. Strong communication and collaboration skills to work effectively with cross-functional teams. Relevant certifications such as CISSP, CISA, or GIAC certifications are a plus. Commitment to continuous learning and staying updated on the latest trends and threats in the field of vulnerability management. Strong understand of lifecycle management principles and their application to the remediation of cybersecurity vulnerabilities Effective communication of technical concepts to a non-technical audience Excellent written and verbal communication skills Preferred Experience 3+ years of vulnerability management Computer Skills Required ● Productivity suite software required ● Python, Powershell, Microsoft SQL, industry standard vulnerability scanning software, and various other cybersecurity tools preferred Licenses and Certifications SANS Certifications, GIAC Certifications, EC Council CEH preferred Physical Demands In order to successfully perform this job, with or without a reasonable accommodation, the following are outlined below: The Employee is required to read, review, prepare and analyze written data and figures, using a PC or similar, and should possess visual acuity. The Employee may be required to occasionally climb, push, stand, walk, reach, grasp, kneel, stoop, and/or perform repetitive motions. The Employee is not substantially exposed to adverse environmental conditions and; therefore, job functions are typically performed under conditions such as those found within general office or administrative work.
    $87k-113k yearly est. Auto-Apply 60d+ ago

Learn more about Community Health Systems jobs

View all jobs