Cybersecurity Engineer II
Job Description
Banner Health offers a role centered on strengthening identity security and governance in a multi-cloud environment. You will help mature Azure IAM governance, design and implement identity solutions, and ensure secure, seamless identity controls across enterprise systems. This position also supports broader cybersecurity capabilities, including threat and vulnerability management, security operations, and data protection, working closely with cross-functional IT teams.
Responsibilities
- Lead the design and implementation of cybersecurity solutions.
- Provide technical expertise and operational support across cybersecurity solutions, including software, hardware, network/firewall components.
- Lead the design, implementation, and compliance of secure configurations for applications and infrastructure.
- Conduct technical assessments of systems and applications to ensure alignment with policy, standards, and regulations.
- Evaluate and evolve security policies and procedures, including revising them as needed.
- Serve as technical lead for cybersecurity projects, including development of project scope requirements, cybersecurity product implementation, tuning, and creation of an operational support model.
- Operate under general direction with system-wide cybersecurity accountability across multiple departments, interacting with staff and management across all levels and collaborating with cross-functional IT teams.
Position Summary
This role designs, develops, configures, implements, tunes, maintains solutions, and resolves technical and business issues related to cybersecurity threat and vulnerability management, identity management, security operations, forensics, and data protection. You will work with Cybersecurity Architects to execute strategic cyber initiatives, evaluate security components across networks, applications, and end-user devices, and provide guidance to ensure new systems meet regulatory and technical standards. You will also participate in root-cause analysis to identify improvement opportunities following failures. In addition, you will manage cyber systems, ensuring they are tuned, on current releases, and supported through appropriate change management across IT and the business.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Information Systems, or related field, with strong knowledge of business, information security, and/or computer science.
- Four to six years of enterprise-scale information security engineering experience, preferably in healthcare.
- One to three years experience in a healthcare environment (or an equivalent combination of relevant education, technical, business, and healthcare experience).
- Experience with IT operations, automation of cybersecurity processes, and coding and scripting languages; ability to document cybersecurity processes and support use case development.
- Experience assessing cyber products, including vendor selection, defining requirements, and developing contractual documentation.
- Experience planning, designing, and implementing cybersecurity solutions.
- Experience operating, maintaining, implementing, upgrading, and managing the lifecycle of cybersecurity solutions.
- Proficient understanding of regulatory and compliance mandates, including HIPAA, HITECH, PCI, and Sarbanes-Oxley.
- Advanced knowledge of Security Engineering Principles, including risk management, resilience, vulnerability management, Information Security, NIST, and MITRE ATT&CK.
- Expertise with cyber products supporting Data Loss Prevention (DLP), EDR, AntiVirus, perimeter services, threat systems, cyber platform analytics, SIEM, CASB, and cloud security.
- Ability to exercise independent judgment, critical decision-making, strong analytical skills, and excellent verbal and written communication.
- Ability to think quickly under difficult or complex conditions, clearly communicate to appropriate staff, and balance project workloads with customer support and on-call demands.
- Strong information technology and information security principles and practices knowledge.
- Communication and presentation skills to engage both technical and non-technical audiences.
- Ability to communicate and interact across facilities and at various levels; skills to mentor less experienced team members.
- Variable shifts and hours and responding to after-hours notifications may be required.
- Certification in two or more of the following: SSCP, HCISPP, CompTIA Security+, CISSP-Engineering (ISSEP), CEH, SANS GIAC, or CISA.
- Three plus years as a System Administrator, Security Operations, or in IT Operations, or three plus years in risk management or GRC experience in the healthcare/medical environment.
- Must also possess three plus years experience in a healthcare environment (or an equivalent combination of relevant education, technical, business, and healthcare experience).
Technologies
- Microsoft Azure, Azure Identity and Access Management (IAM), Active Directory, Entra ID
- Azure AD Connect, Conditional Access Policies, Identity Governance, RBAC
- Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate
- AWS (identity in AWS preferred)
- HIPAA, HITECH, PCI, Sarbanes-Oxley
- NIST, MITRE ATT&CK
- Data Loss Prevention, EDR, AntiVirus, SIEM, CASB, Cloud Security, Perimeter services
- Cyber platform analytics
Work Shift and Location
- Work shift: Day
- Department: IT Identity Access Mgmt-Corp
- Job category: Information Technology
- Location: Phoenix, AZ (remote)
Remote Position Statement
- This is a remote position.
- In this role you would work Monday through Friday normal business hours.
- Remote position eligibility: can be remote if you live in AL, AK, AR, AZ, CA, CO, FL, GA, IA, ID, IN, KS, KY, LA, MD, MI, MN, MO, MS, NC, ND, NE, NH, NM, NV, NY, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WI, WV, or WY.
Estimated Pay Range
$40.91 - $68.19 / hour
Actual pay determined at offer will be based on years of relevant work experience, education, certifications, skills, and geographic location. Pay equity will be maintained through a review of current employees in similar roles.
Benefits
- Health and financial security options
- Variety of benefit plans