IT Security Engineer
2 months ago
MetroPlusHealth provides the highest quality healthcare services to residents of Bronx, Brooklyn, Manhattan, Queens and Staten Island through a comprehensive list of products, including, but not limited to, New York State Medicaid Managed Care, Medicare, Child Health Plus, Exchange, Partnership in Care, MetroPlus Gold, Essential Plan, etc. As a wholly-owned subsidiary of NYC Health + Hospitals, the largest public health system in the United States, MetroPlusHealth's network includes over 27,000 primary care providers, specialists and participating clinics. For more than 30 years, MetroPlusHealth has been committed to building strong relationships with its members and providers to enable New Yorkers to live their healthiest life.
Position Overview
The security engineer is responsible for implementing, maintaining, monitoring and managing secure solutions. The engineer delivers these solutions in accordance with the organization's architectural designs, best practices, and regulatory or compliance requirements. As risks change, the security engineer is responsible for recommending modifications and enhancements to ensure the organization is evolving with the threat landscape.
The security engineer is expected to contribute to the corporate security strategy with security leadership and other senior security staffers and technologists. Recipients of the engineer's implementations and management include IT infrastructure, application development, security operations, security audit and end users. With an emphasis on securing systems, applications, third-party connections, service providers and ancillary systems, the security engineer is responsible for securing business-to-business initiatives, third-party relationships, outsourced solutions and vendors. Considered a highly knowledgeable individual, the security engineer is expected to implement, monitor and manage secure solutions that address modern day issues.
Job Description
- Handle day-to-day implementation, monitoring and operational support of security hardware, software, customer applications, and managed solutions.
- Actively participate security team meetings that facilitate secure design.
- Engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects. Additionally, deliver projects on time and within budget.
- Assist with incident response and system stability issues as they occur. This may include involvement outside of regular work hours, and responsiveness is expected.
- Implement solutions observing compliance - Health Information Portability and Accountability Act (HIPAA), Payment Card Industry (PCI), New York State Department of Financial Services Cybersecurity Requirements (23 NYCRR 500).
- Work in tandem with architects, the security operations center (SOC), incident responders (in cases of anomalous activity and host compromise), and technology infrastructure and development team members.
- Respond to and handle service and escalation tickets within SLA expectations.
- Develop security test plans from architectural design. Identify deficiencies and make enhancements to ensure production is not impacted.
- Participate in change project and change management meetings as required.
- Research, validate and deploy solutions meeting security and business needs.
- Follow security engineering fundamentals and processes as outlined in NIST 800-160
Influence the planning and execution of incident response and postmortem exercises, with a focus on creating measurable benchmarks to show progress (or deficiencies requiring additional attention). - Focus on driving security efficiencies, enabling security team members to work on more advanced tasks.
- Conduct performance testing to stress the limitations of security solutions while at the same time ensuring business innovation and day-to-day processes are not negatively impacted.
- Perform other duties as assigned
- Bachelor's degree in computer science, information assurance, Cybersecurity or related field, or equivalent.
- 10+ years of related experience required.
- CISSP (preferred); CISM and/or SANS certification or Cisco-related certifications a plus.
- Experience with:
- Microsoft Azure or Amazon Web Services (AWS).
- Vulnerability tools such as Rapid7, Qualys, Nessus, NMAP, Kismet, Airsnort
- SIEM platforms and technologies
- Private and Public PKI Infrastructure
- Network security management, design, and deployment.
- DevOps background with experience in compliance obligations.
- Experience with one or more of the following standard frameworks:
- ISO 27001, NIST, PCI Data Security Standard (PCI DSS), HIPAA, Health Information Technology for Economic and Clinical Health (HITECH) Act, Center for Internet Security (CIS) standards or Service Organization Controls (SOC) 2.
- Working knowledge of Windows and Linux.
- Familiarity with state privacy laws.
- Ability to think strategically and tactically, with effective decision-making skills.
- Highly trustworthy; leads by example.
- Experience supporting and utilizing SIEM platforms.
- Working technical knowledge of Advance Threat Protection tools such as Crowdstrike, Trellix, etc.
- Next Generation Firewalls (NGFW), Software-Defined Wide Area Networking (SD-WAN), Advanced Threat Protection and Sandboxing solutions.
- Detection/Prevention Systems: Anomaly-based, signature-based, and host-based.
- DLP and Data in rest encryption.
#L-Hybrid
-
Cloud Security Engineer with UI Focus
4 weeks ago
New York, New York, United States Armis Security Full timeSecure the Future of Cyber Exposure ManagementAt Armis Security, we're revolutionizing the way organizations protect their attack surface and manage cyber risk exposure in real-time. As a Senior Full Stack Engineer on our team, you'll have the opportunity to make a significant impact in an important field while maintaining a healthy work-life balance.About...
-
New York, New York, United States Abnormal Security Full timeAbout the RoleAt Abnormal Security, we are seeking a highly experienced Senior Software Engineer to join our Inbound Email Products - Systems (IEPS) team. As a key member of this team, you will be responsible for designing and building critical components of our flagship Email Security product.
-
New York, United States Georgia IT Inc Full timeJob Title: GCP Security SecDevOps Engineer Location: Onsite: 3 days a week NYC, NY or Alpharetta, GA Rate: DOE Duration: 06 Months plus contract Position Overview: We are seeking a highly skilled GCP Security SecDevOps Engineer to join our dynamic team and strengthen our security posture across our Google Cloud Platform (GCP) environment. In this critical...
-
Cloud Security Architect
6 days ago
New York, New York, United States Zip Security Full timeCompany OverviewAt Zip Security, we're revolutionizing enterprise cybersecurity by making it reasonable. Our goal is to reduce bloat by bundling and configuring opinionated security tooling, synchronizing everything from device management to application security under one central pane of glass.The RoleWe're seeking a Founding Backend Engineer to help build...
-
Enterprise Security Specialist
4 weeks ago
New York, New York, United States Zip Security Full timeCloud Native Security RoleAt Zip Security, we're seeking a talented Enterprise Security Specialist to design and implement secure APIs that harmonize functionality across multiple enterprise software providers. This role offers a unique opportunity to integrate and build a full-stack, opinionated, enterprise security company with new government efforts to...
-
Network Security Architect Position
6 days ago
New York, New York, United States Lincoln IT Full timeJob Title: Cybersecurity Network ProfessionalAt Lincoln Computer Services, we are seeking an experienced Cybersecurity Network Professional to join our IT team. As a key member of our department, you will be responsible for designing and implementing secure network architectures, ensuring the confidentiality, integrity, and availability of our data.The ideal...
-
Senior Enterprise Security Sales Representative
4 weeks ago
New York, New York, United States Abnormal Security Full timeAbout the RoleWe are seeking an experienced Senior Enterprise Security Sales Representative to join our team at Abnormal Security. This is a unique opportunity to sell cutting-edge security solutions to State/Local Government & K-12 Education (SLED) accounts and drive revenue growth. As a key member of our sales team, you will work closely with internal...
-
Founding Software Engineer
2 weeks ago
New York, New York, United States Zip Security Full timeJoin Our TeamWe're seeking a skilled software engineer to help us build a next-generation enterprise security platform. As a Founding Backend Engineer at Zip Security, you'll play a key role in shaping the future of our company and contributing to the development of innovative security solutions.Your ResponsibilitiesYou'll be responsible for designing and...
-
Security Engineer
4 weeks ago
New York, United States Nationstaff Full timeAbout This Role We are seeking a highly capable Security Engineer / Senior Security Engineer, who will be responsible for various technical and cryptographic security aspects. This role requires a certain range of experience and an in-depth understanding of security engineering facets. Primary ResponsibilitiesPerform security analysis/audits/reviews/testing,...
-
Security Engineer
2 months ago
New York, United States Nationstaff Full timeAbout This Role We are seeking a highly capable Security Engineer / Senior Security Engineer, who will be responsible for various technical and cryptographic security aspects. This role requires a certain range of experience and an in-depth understanding of security engineering facets. Primary ResponsibilitiesPerform security analysis/audits/reviews/testing,...
-
Cybersecurity Engineer Lead
5 days ago
New York, New York, United States Lincoln IT Full timeJob Description:Lincoln IT is a growing custom IT solution provider looking for an experienced Cybersecurity Engineer Lead to join our team. In this role, you will be responsible for leading our cybersecurity efforts and developing strategies to protect our clients' data.About the Role:Lead our cybersecurity efforts and develop strategies to protect client...
-
Security Engineer
25 minutes ago
New York, United States MetroPlusHealth Full timeEmpower. Unite. Care. MetroPlusHealth is committed to empowering New Yorkers by uniting communities through care. We believe that Health care is a right, not a privilege. If you have compassion and a collaborative spirit, work with us. You can come to work being proud of what you do every day. About NYC Health + Hospitals MetroPlusHealth provides the highest...
-
Backend Engineer
5 months ago
New York, United States Zip Security Full timeCompany Enterprise cybersecurity is broken. Current annual cybersecurity spending is roughly $150B, with most enterprises spending heavily to deploy, manage, and configure 100s of different tools for marginal security benefit. At Zip, our goal is to build software that makes enterprise cybersecurity reasonable - to reduce bloat by bundling and configuring...
-
Unix Security Specialist
1 day ago
New York, New York, United States SSH Communications Security Full timeJob DescriptionAs a Senior Unix Engineer at SSH Communications Security, you will be responsible for providing expert consulting on IT security, including training on SSH products, architectural design, project planning, risk assessments, and the development of custom scripts and tools.You will act as the primary point of contact for customers, managing...
-
Security Engineer
2 months ago
New York, United States Motion Recruitment Full timeOur client is looking for a Security Engineer to lead their security initiatives and protect sensitive company data. The role involves developing security tools, automating workflows, responding to incidents, and collaborating with engineering teams to ensure data security and governance. Ideal candidates will have, hands-on experience in DevOps/DevSecOps...
-
Cloud Security Solutions Architect
2 weeks ago
New York, New York, United States Opal Security Full timeOpal Security OverviewAs a leading provider of identity security solutions, Opal Security empowers organizations to manage access and privileges in the cloud. Our platform enables scalable and efficient implementation of least-privilege access, reducing the risk of breach and blast radius.With a proven track record of success and over $32M in funding from...
-
New York, New York, United States pro it Full timeJob DescriptionThe role involves establishing a team of onsite consultants at various locations to support the client’s Operational Technology (OT) groups in cybersecurity projects. We seek a Cybersecurity Engineer with a network background, possessing the following skills:A minimum of 2 years of experience with an Associate’s, Bachelor’s, Master’s,...
-
New York, New York, United States Abnormal Security Full timeAbout the Role:Abnormal Security is a leading cybersecurity firm seeking an experienced Full Stack Engineer to lead the development of its Inbound Email Portal. This role involves managing key areas of the Messaging Security Products (MSP) IEPP team, responsible for ensuring product stability, enhancing scalability, and broadening impact on...
-
Network and Voice Systems Engineer
3 weeks ago
New York, New York, United States Lincoln IT Full timeLincoln IT is seeking a highly skilled Network and Voice Systems Engineer to join our team.Job OverviewWe are currently looking for a Full Time Tier I/II Network Voice / Field Engineer with a minimum of 3 years of hands-on experience in network engineering.Key Responsibilities:Provide phone, remote and onsite support and remediation for network device...
-
Security Engineering Manager
6 days ago
New York, New York, United States MongoDB Full timeLead Security Initiatives at MongoDBWe're looking for a skilled security engineer to lead security initiatives and drive innovation within our Product Security organization. As a Security Engineering Manager, you will be responsible for taking ownership of one or more security programs, such as appsec, cloud, or detect/response, and seeing projects through...