Cybersecurity Engineer II
Job Description
Banner Health is hiring a Cybersecurity Engineer II to mature Azure identity and access governance, deliver identity solutions, and support secure controls across a multi-cloud environment.
Responsibilities
- Lead the design and implementation of cybersecurity solutions.
- Provide technical expertise and operational support across cybersecurity solutions, including software, hardware, and network and firewall components.
- Lead secure configuration design, implementation, and compliance for application and infrastructure components.
- Conduct technical assessments of systems and applications to confirm compliance with policy, standards, and regulations.
- Evaluate and evolve security policies and procedures, including policy and procedure revisions as needed.
- Serve as technical lead for cybersecurity projects, including defining project scope requirements, implementing cybersecurity products, tuning solutions, and creating an operational support model.
- Operate under general direction to support cybersecurity across multiple departments system-wide, collaborating with staff and management across functions and IT teams.
- Design, develop, configure, implement, tune, and maintain cybersecurity threat and vulnerability management, identity management, security operations center, forensics, and data protection capabilities.
- Work with cybersecurity architects to execute strategic cybersecurity initiatives, evaluate security components across network, applications, and end-user devices, and guide standards alignment for new systems.
- Participate in root-cause analysis to identify improvement opportunities after failures.
- Manage cybersecurity systems to ensure tuning, current releases, and appropriate change management across IT and business stakeholders.
Requirements
- Education: bachelor’s degree in Computer Science, Information Security, Information Systems, or a related field.
- Experience: 4 years minimum; four to six years of enterprise-scale information security engineering, preferably in healthcare.
- Healthcare experience: 1 to 3 years in a healthcare environment or equivalent combination of relevant education, technical, business, and healthcare experience.
- Experience assessing cyber products, including vendor selection, defining requirements, and developing contractual documentation.
- Demonstrated ability to plan, design, implement, operate, maintain, upgrade, and manage the lifecycle of cybersecurity solutions.
- Experience in IT operations and automation of cybersecurity processes, including coding and scripting; ability to document cybersecurity processes and develop use cases.
- Proficient understanding of regulatory and compliance mandates, including HIPAA, HITECH, PCI, and Sarbanes-Oxley.
- Advanced knowledge of security engineering principles, including risk management, resilience, and vulnerability management, plus NIST and MITRE ATT&CK.
- Expertise with cybersecurity products and capabilities supporting Data Loss Prevention, EDR, AntiVirus, Perimeter services, threat systems, cyber platform analytics, SIEM, CASB, and CLOUD Security.
- Independent judgment and critical decision making; strong analytical skills and excellent verbal and written communication.
- Ability to think quickly during difficult or complex conditions and communicate clearly to appropriate staff; balance project workloads with customer support and on-call demands.
- Communication and presentation skills to engage technical and non-technical audiences.
- Ability to communicate and interact across facilities and at various levels.
- Ability to mentor less experienced team members.
- Variable shifts and hours and responding to after-hours notifications may be required.
- Certifications in two or more: SSCP, HCISPP, CompTIA Security+, CISSP-ISSEP, CEH, SANS GIAC, or CISA.
- Either: 3+ years as a System Administrator, Security Operations, or in IT Operations, or 3+ years in risk management or GRC in a healthcare/medical environment.
- Additionally: 3+ years of healthcare environment experience or an equivalent combination of relevant education, technical, business, and healthcare experience.
Technologies
- Microsoft Azure, Azure Identity and Access Management (IAM), Active Directory, Entra ID, Azure AD Connect
- Conditional Access Policies, Identity Governance, RBAC
- Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate
- AWS (identity in AWS preferred)
- HIPAA, HITECH, PCI, Sarbanes-Oxley
- NIST, MITRE ATT&CK
- Data Loss Prevention, EDR, AntiVirus, SIEM, CASB, CLOUD Security
- Perimeter services, cyber platform analytics
Location and Work Details
- Location: Phoenix, AZ (remote)
- Work shift: Day
- Department: IT Identity Access Mgmt-Corp
- Job category: Information Technology
- Remote position: remote role; Monday through Friday normal business hours
- Remote eligibility states: AL, AK, AR, AZ, CA, CO, FL, GA, IA, ID, IN, KS, KY, LA, MD, MI, MN, MO, MS, NC, ND, NE, NH, NM, NV, NY, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WI, WV, WY
Compensation
- $40.91 - $68.19 / hour
- Actual pay determined at offer based on years of relevant work experience, education, certifications, skills, geographic location, and review of current employees for pay equity.
Benefits
- Health and financial security options
- Variety of benefit plans