MEDITECH

Information Security Engineer

MEDITECH Canton, Massachusetts, United States · $66K–$105K/yr

IT Services and IT Consulting · 1,001-5,000 employees

Oct 02
security Mid (2-5 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Information Security Engineer is responsible for maintaining system security, implementing controls, and ensuring data privacy. They coordinate with IT groups to remediate vulnerabilities, monitor security threats, and design secure system configurations.

What they look for

Information security Risk assessment Vulnerability assessment Cloud security Security monitoring Remediation System configuration Scripting ISO 27001 NIST Access control Data privacy Analytical skills Problem solving Communication skills

Requirements

Candidates should have a bachelor's or associate degree and 2-3 years of relevant work experience. Knowledge of security standards like ISO 27001 or NIST and experience with security tools and scripting are required.

Benefits

Health insurance Dental insurance Vision insurance Profit sharing trust 401(k) Tuition reimbursement Paid time off Sick days Personal time Paid holidays

Full description

Description

Information Security Engineers are responsible for the day-to-day access to and security of system resources. This includes identifying, implementing, and maintaining appropriate controls to provide confidentiality, integrity, and availability (C-I-A) to the system resources facilitating the routine functions of the business. This role coordinates closely with other groups on a wide range of security projects. As a member of our Cloud Services team, your job would involve:

  • Ensuring corporate data privacy and security
  • Evaluating output from various security monitoring tools
  • Coordinating with monitoring group to prioritize action
  • Planning and implementing remediation and/or mitigating controls
  • Carrying out security based risk assessments and advising on any potential risk acceptance
  • Planning and implementing remediation and/or mitigating controls
  • Implementing controls and working with other teams to ensure appropriate access to corporate assets
  • Maintaining knowledge of security/regulatory concepts such as least privilege
  • Providing security feedback and expertise
  • Implementing any controls needed to end the current incident and protect against future occurrences
  • Designing, implementing, and maintaining secure system configurations
  • Assisting in the security evaluation of system design and implementation
  • Communicating and coordinating with other security and IT groups.

Requirements

  • Bachelor’s or associate degree preferred, and/or 2-3 years applicable work or military experience
  • Security specific certifications preferred, but not required: • Certified Information Systems Security Professional, (ISC)² - CISSP
  • Certified Information Systems Auditor, ISACA - CISA
  • Global Information Assurance Certifications, GIAC - GISF, GCED, GNFA, etc.
  • Certified Cloud Security Professional, (ISC)² - CCSP
  • Certificate of Cloud Security Knowledge, CSA - CCSK
  • Certified Cloud Security Specialist, GSTF - CCSS
  • Knowledge and awareness of applicable information security standards, guidelines, regulations, and industry standard best practices: • Information Security Management (ISO 27001/27002/27017)
  • Security Operations Center (SOC I & II)
  • Quality Management (ISO 9001)
  • National Institute of Standards & Technology (NIST)
  • Scripting experience (especially in IT operations)
  • Multiple years of experience or education dealing with information security tools and techniques
  • Ability to identify and work with application and system experts to help identify and remediate vulnerabilities
  • Ability to work with various monitoring resources to understand current security threats and engineer solutions
  • Advanced knowledge of information security principles and practices, including any of the following: security risk assessment standards, risk assessment methodologies, and vulnerability assessment
  • Strong analytical, reasoning, and problem solving skills and technical aptitude
  • Exceptional written and verbal communication skills
  • Ability to work well with stakeholders and interested parties of varying position and tenure
  • Ability to use discretion when handling confidential information
  • Ability to learn new tools and technologies quickly.

Hiring salary range: $66,000- $105,000 per year.

Actual salary will be determined based on an individual's skills, experience, education, and other job-related factors permitted by law.

MEDITECH offers competitive employee benefits including but not limited to health, dental, & vision insurance; profit sharing trust and 401(k); tuition reimbursement, generous paid time off, sick days, personal time, and paid holidays.

This is a hybrid role which includes a blend of in-office and remote work as designated by the management team.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. MEDITECH will not sponsor applicants for work visas.

Similar roles