IS Security Engineer II
Careoregon---------------------------------------------------------------
The IS Security Engineer II is responsible for implementing and maintaining corporate security along with influencing and recommending the selection of effective solutions to support business strategies. This role is essential toward maturing CareOregon’s security model. This position will spend substantial time evaluating, architecting, and implementing IS policies and systems (plan, design, install, and maintain).Estimated Hiring Range:
$102,330.00 - $125,070.00Bonus Target:
Bonus - SIP Target, 5% AnnualCurrent CareOregon Employees: Please use the internal Workday site to submit an application for this job.
---------------------------------------------------------------
Essential Responsibilities
Security Design and Development
- Actively participate in the design and maintenance of security technologies, including but not limited to firewalls, proxy systems, logging, and other security devices.
- Provide advanced security technology knowledge to the organization; participate in and consult on projects.
- Advise other IS teams about best practices for security design.
Security Administration and Operations
- Execute tasks related to tickets and service requests for basic to advanced activities.
- Actively maintain security systems, including firewalls, proxy systems, logging, and other security devices, and vendor provided services.
- Analyze business needs; research and recommend solutions which include potential risks and mitigation.
- Help define, as well as build, run, and review, reports on information security system performance and event anomalies; make minor and advanced internal adjustments and identify substantial gaps based on findings.
- Develop and maintain appropriate technology documentation, including current design and operation.
Standards and Policy Administration
- Propose requirements and standards for information security.
- Participate in the ongoing review existing systems to ensure they are designed to comply with established standards and to empower business operations.
- Participate in developing and maintaining information securing policies.
- Integrate network engineers in the development and management of security policies and systems, such as firewalls, intrusion detection, and intrusion prevention devices.
- Participate in planning for and supporting disaster recovery and business continuity initiatives.
Vendor Coordination and Relations
- Develop, monitor, and maintain electronic data exchanges with outside entities.
- Maintain service contracts and licensing; monitor adherence to SLAs with outside parties; escalate issues as needed.
Experience and/or Education
Required
- Minimum 3 years’ experience delivering information security solutions and related services. Experience should include some or all of the following:
- WAN firewalls, load balancers and proxies
- Designing, configuration, and ongoing support of a network DMZ
- Developing secure collaboration solutions for external partners or affiliates
- Computer security combined with risk analysis, audit, and compliance objectives
- ITIL concepts and practices
Preferred
- Palo Alto Firewalls experience
- One or more of the following certifications: CISSP, GIAC certifications (GSEC, GCIA, GCIH, GPEN, etc.), CCSP, CISM and/or Microsoft Security certifications (SC-100, SC-200, AZ-500).
- Additional experience in related technology support and/or operational positions
Knowledge, Skills and Abilities Required
Knowledge
- Knowledge of Vulnerability Management systems and processes
- Knowledge of Security Incident and Event Management (SIEM) systems
Skills and Abilities
- Advanced in data loss prevention (DLP), Intrusion Detection systems (IDS), and Intrusion Prevention systems (IPS)
- Advanced in troubleshooting of system performance issues and root cause
- Advanced in network transport protocols and industry standards
- Ability to program using scripting languages Python, Powershell, VB, C++, and/or others
- Strong process-oriented individual with awareness or knowledge of ITIL concepts
- Effective communication skills, including listening, verbal, written, and customer service
- Ability to clearly articulate policies and instructions
- Demonstrated progress in conveying appropriate level of detail effectively to all levels of the organization including non-technical staff
- Demonstrated progress in simplifying and presenting complex concepts in an easily understood way
- Ability to proactively and appropriately communicate status and needs
- Ability to recommend policies, document risks, and propose solutions to information technology management and senior leadership
- Possess a high degree of initiative and motivation
- Ability to effectively collaborate with coworkers, staff, and leaders across all departments
- Demonstrated progress in leading teams of people without oversight
- Demonstrated progress in seeing the big picture beyond a request and takes appropriate holistic action, employing “systems thinking”
- Effective project management skills
- Effective vendor management skills
- Effective organizational skills
- Prioritizes work based on business need and direction
- Effective analytical and research skills
- Demonstrated progress in being able to see patterns in data and draw appropriate conclusions.
- Demonstrated progress in proposing solutions and communicating business value
- Positive attitude
- Understanding of and ability to adhere to governance and process
- Ability to work effectively with diverse individuals and groups
- Ability to learn, focus, understand, and evaluate information and determine appropriate actions
- Ability to accept direction and feedback, as well as tolerate and manage stress
- Ability to see, read, and perform repetitive finger and wrist movement for at least 6 hours/day
- Ability to hear and speak clearly for at least 3-6 hours/day
Working Conditions
Work Environment(s): ☒ Indoor/Office ☐ Community ☐ Facilities/Security ☐ Outdoor Exposure
Member/Patient Facing: ☒ No ☐ Telephonic ☐ In Person
Hazards: May include, but not limited to, physical and ergonomic hazards.
Equipment: General office equipment and ladders
Travel: May include occasional required or optional travel outside of the workplace; the employee’s personal vehicle, local transit or other means of transportation may be used.
Work Location: Work from home
Schedule: Ability to occasionally work outside of standard office hours
We offer a strong Total Rewards Program. This includes competitive pay, bonus opportunity, and a comprehensive benefits package. Eligibility for bonuses and benefits is dependent on factors such as the position type and the number of scheduled weekly hours. Benefits-eligible employees qualify for benefits beginning on the first of the month on or after their start date. CareOregon offers medical, dental, vision, life, AD&D, and disability insurance, as well as health savings account, flexible spending account(s), lifestyle spending account, employee assistance program, wellness program, discounts, and multiple supplemental benefits (e.g., voluntary life, critical illness, accident, hospital indemnity, identity theft protection, pre-tax parking, pet insurance, 529 College Savings, etc.). We also offer a strong retirement plan with employer contributions. Benefits-eligible employees accrue PTO and Paid State Sick Time based on hours worked/scheduled hours and the primary work state. Employees may also receive paid holidays, volunteer time, jury duty, bereavement leave, and more, depending on eligibility. Non-benefits eligible employees can enjoy 401(k) contributions, Paid State Sick Time, wellness and employee assistance program benefits, and other perks. Please contact your recruiter for more information.
We are an equal opportunity employer
CareOregon is an equal opportunity employer. The organization selects the best individual for the job based upon job related qualifications, regardless of race, color, religion, sexual orientation, national origin, gender, gender identity, gender expression, genetic information, age, veteran status, ancestry, marital status or disability. The organization will make a reasonable accommodation to known physical or mental limitations of a qualified applicant or employee with a disability unless the accommodation will impose an undue hardship on the operation of our organization.