Senior Network Security Engineer
Job Description
HCA Healthcare is seeking a Senior Network Security Engineer to lead the implementation, modernization, standardization, and enhancement of network security controls. In this role based in Nashville, TN (onsite), you will help protect enterprise infrastructure, patients, and sensitive data by reducing risk and strengthening continuous security control maturity across a Fortune 100 environment.
Reporting into the network security effort, you will perform and oversee policy and security assessments, evaluate security tooling and architecture, and translate findings into remediation recommendations, designs, and configuration changes. You will also collaborate with other IT teams to align network security controls with evolving operational and compliance needs.
Responsibilities
- Lead implementation, modernization, standardization, and enhancement of network security controls to protect infrastructure, patients, and data from increasing risk and threats.
- Perform and oversee reviews and assessments of policies for risk and vulnerabilities, identify hardening opportunities, and provide remediation recommendations, designs, and solutions.
- Collaborate with IT teams to implement risk management practices, optimize technology solutions, monitor and adjust infrastructure, ensure regulatory compliance, and improve security posture over time.
- Evaluate, recommend, and implement security measures including next-generation firewall features, intrusion detection or prevention systems, VPN, network segmentation and zero trust, and multifactor and access control mechanisms.
- Conduct firewall rule reviews, security audits, baseline and best-practice compliance checks, and forensic network investigations to support adherence for data transmission and implement recommendations.
- Support and manage network security solutions aligned with regulatory and industry requirements, including PCI DSS, SOX, NIST, ISO 27000, and HIPAA.
- Evaluate vulnerability assessments and penetration tests, review metrics and security audits, and provide remediation recommendations and solutions.
- Recommend and implement complex solutions and configuration changes within a large enterprise network to support continuous security control maturity and risk reduction.
- Participate in incident response and disaster recovery planning and testing.
- Collaborate with other IT teams to integrate network security controls with systems and applications, ensuring alignment with security standards.
- Routinely perform audits and control tests on deployed technologies, collecting and consolidating performance indicators, risks, and trends, and providing baseline and regulatory compliance ratings.
- Manage relationships with vendors and contractors to ensure security services are delivered on time and implemented in alignment with security policies.
- Collaborate on development and documentation of security policies and procedures, including training and awareness.
- Provide guidance and training to peers on compliance and best practices.
- Research design enhancements and identify automated solutions or best-of-breed technologies while assisting with integration tests with vendors.
- Stay current on threats, vulnerabilities, regulations, and industry best practices, and implement recommendations to improve security posture and control maturity.
Requirements
- Bachelor’s degree preferred
- 5+ years of experience required
- Extensive experience with security technologies including next-generation firewalls, intrusion detection or prevention systems, VPN, network segmentation, access control mechanisms, and security design and policy management in large 1000+ firewall environments.
- Expertise in Checkpoint Firewall including CMA, Provider-1, Maestro, VSX/VSLS, and CloudGuard.
- Experience with Cisco Network Security Products & Technologies including Firepower, ASA, VPN, WSA, ISE, Stealthwatch, and related tools.
- Strong understanding of network protocols, topologies, tools, subnetting, and architectures.
- Aptitude with network security policy management tools such as Algosec and Tufin and/or experience conducting risk assessments, firewall rule reviews, and security audits.
- Strong knowledge of enterprise security technologies and processes including Zscaler, advanced threat detection tools, Antibot, Antimalware, threat emulation, SIEM, IDS/IPS, network packet analysis, and Netflow.
- Experience designing solutions for security standards and frameworks including HIPAA, SOX, PCI DSS, HITECH, ISO/IEC 27001, and the NIST Cybersecurity Framework.
- Experience with network security management tools and technologies such as Splunk, Trustsec, segmentation, and syslog.
- Excellent verbal and written communication, interpersonal, analytical, and problem-solving skills.
- Demonstrated leadership and mentorship skills, including the ability to guide and train junior engineers.
- Ability to work independently and as part of a team.
- Relevant certifications from ISC2 (CISSP), GIAC (GISP), ISACA (CISA), Cisco Security, or CompTIA are a plus.
Technologies
- Next-generation firewalls; intrusion detection and prevention systems
- VPN; network segmentation and zero trust
- Multifactor and access control mechanisms
- PCI DSS, SOX, NIST, ISO 27000, HIPAA
- Checkpoint Firewall, CMA, Provider-1, Maestro, VSX/VSLS, CloudGuard
- Cisco Firepower, ASA, WSA, ISE, Stealthwatch
- Algosec, Tufin
- Zscaler, Advanced Threat Detection Tools, Antibot, Antimalware, Threat Emulation
- SIEM; IDS/IPS; Network Packet Analysis; Netflow
- HITECH; ISO/IEC 27001; NIST Cybersecurity Framework
- Splunk; Trustsec; segmentation; syslog
- Incident response and disaster recovery planning and testing
Benefits
- Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health, and telemedicine services
- Wellbeing support including free counseling and referral services
- Time away from work programs including paid time off, paid family leave, long- and short-term disability coverage, and leaves of absence
- 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support, and financial wellbeing counseling
- Education support via tuition assistance, student loan assistance, certification support, dependent scholarships, and a partnership with Galen College of Nursing
- Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection, and consumer discounts
Physical Demands / Working Conditions
- Position expectations involve minimal supervision due to design, service, and support knowledge and skillsets
- May require periodic after-hours work and light travel at times with little notice
- Requires sitting for extended periods