CybersecurityJobs.io
← Back to all jobs

Job Description

Atlantic Health System supports your growth while you help protect cloud environments and the identities that access them. This onsite role in Morristown, NJ is part of a dynamic security team focused on practical risk reduction, regulated data protection, and incident response readiness, including participation in a rotating on-call schedule.

What you’ll focus on

The Cybersecurity Engineer II – Cloud Security and Identity role helps secure the organization’s cloud environments and enterprise identity security, with primary emphasis on AWS and Microsoft Entra ID. You will also support incident response activities related to cloud and identity-based attacks, contribute to protections for ePHI, and help advance cloud and identity security initiatives.

Responsibilities

  • Support the design, implementation, and ongoing operation of security controls across cloud environments, with primary emphasis on AWS and additional coverage of Microsoft Azure and Microsoft 365.
  • Administer and optimize a cloud-native application protection platform such as Wiz to continuously discover cloud assets and identify misconfigurations, excessive permissions, exposed data, and vulnerable workloads for triage.
  • Conduct risk-based analysis of cloud security findings and prioritize remediation by considering severity, exploitability, data sensitivity, and business context, partnering with cloud, infrastructure, application, and vendor teams to drive issues to closure.
  • Evaluate cloud environments against recognized benchmarks and best practices, including CIS Benchmarks, the AWS Well-Architected Framework security pillar, and internal standards, while tracking configuration drift and remediation over time.
  • Support cloud identity and entitlement security by reviewing and right-sizing AWS IAM roles, policies, and permission boundaries, and reducing standing and excessive privilege across cloud accounts.
  • Administer and support Microsoft Entra ID and hybrid Active Directory, including conditional access, multifactor authentication, authentication methods, application registrations, and single sign-on integrations.
  • Configure and operate Microsoft Entra Privileged Identity Management (PIM), supporting privileged access practices such as just-in-time elevation and periodic access reviews and certifications for sensitive roles and applications.
  • Monitor, triage, and investigate alerts from sources including Wiz, AWS-native services (GuardDuty, Security Hub, CloudTrail), Microsoft Defender for Cloud, Microsoft Entra ID Protection, and the enterprise SIEM.
  • Support secure cloud onboarding and architecture reviews for new cloud services, SaaS applications, and third-party integrations, including evaluation of authentication, authorization, logging, encryption, and data handling.
  • Maintain familiarity with infrastructure-as-code and container technologies (such as Terraform or CloudFormation, CI/CD pipelines, and Kubernetes) to review security findings and route them appropriately.
  • Contribute across the broader security program, assisting with vulnerability management, data protection, application security, and endpoint and email security as team priorities and organizational risk require.
  • Participate in incident response as part of a rotating on-call schedule, supporting detection, triage, investigation, containment, and remediation of security incidents, including cloud and identity-based attacks.
  • Develop and maintain cloud and identity security metrics, dashboards, runbooks, and technical documentation for technical teams and leadership.
  • Collaborate with ISS, as well as Privacy and Compliance, to protect ePHI and adhere to HIPAA and other regulatory requirements.
  • Contribute to cybersecurity strategies, policies, standards, and procedures, particularly those related to cloud and identity.

Requirements

  • Bachelor’s degree or higher in Cybersecurity, Information Technology, or a related field is preferred; equivalent professional experience will be considered in lieu of a degree for the right candidate.
  • 3+ years of experience in cybersecurity, cloud engineering, identity and access management, or IT with meaningful security responsibilities in a large organization, preferably a large healthcare environment.
  • Hands-on experience securing AWS environments, including working knowledge of AWS IAM (roles, policies, trust relationships, permission boundaries), organizational structure and guardrails, VPC and network controls, S3 and data storage security, encryption and key management, and native services such as CloudTrail, GuardDuty, Security Hub, and Config.
  • Working experience with Microsoft Azure and Microsoft 365 security, including Defender for Cloud and subscription and resource-level controls.
  • Practical experience with a cloud security posture management or CNAPP platform such as Wiz, Prisma Cloud, Orca, or Microsoft Defender for Cloud, including interpreting findings, tuning policies, and driving remediation.
  • Solid working knowledge of Microsoft Entra ID and hybrid identity, including conditional access, multifactor authentication, Entra Connect and directory synchronization, application registrations and enterprise applications, SSO protocols (SAML, OAuth 2.0, OpenID Connect), and Entra PIM.
  • Understanding of core IAM concepts including least privilege, role-based access control, separation of duties, joiner-mover-leaver processes, access reviews, and privileged access management.
  • Familiarity with common cloud and identity attack techniques such as credential and token theft, consent phishing, privilege escalation through misconfigured roles, and abuse of public or misconfigured cloud resources and relevant mitigating controls.
  • Well-rounded knowledge beyond cloud and identity, including vulnerability management, data protection, application security, network security, and endpoint and email security.
  • Working knowledge of HIPAA and requirements for protecting ePHI in a healthcare environment, or ability to develop knowledge quickly.
  • Hands-on experience contributing to cybersecurity incident response, including alert triage, investigation, containment, and remediation as part of a team.
  • Scripting or automation experience with PowerShell, Python, or the AWS CLI is a plus, including comfort working with APIs to extract data and reduce manual effort.
  • Willingness and availability to participate in a rotating on-call schedule.

Technologies you’ll work with

AWS, Microsoft Azure, Microsoft 365, Wiz, Microsoft Entra ID, Microsoft Entra PIM, hybrid Active Directory, conditional access, multifactor authentication, AWS IAM, AWS Well-Architected Framework, CIS Benchmarks, Microsoft Defender for Cloud, Microsoft Entra ID Protection, GuardDuty, Security Hub, CloudTrail, Terraform, CloudFormation, Kubernetes, CI/CD pipelines, infrastructure-as-code, Prisma Cloud, Orca, enterprise SIEM, S3, VPC, Config, Entra Connect, SAML, OAuth 2.0, OpenID Connect, PowerShell, Python, AWS CLI, HIPAA, ePHI, CNAPP.

Benefits

  • Medical, Dental, Vision, Prescription Coverage
  • Life & AD&D Insurance
  • Short-Term and Long-Term Disability (with options to supplement)
  • 403(b) Retirement Plan: Employer match and additional non-elective contribution
  • PTO & Paid Sick Leave
  • Tuition Assistance, Advancement & Academic Advising
  • Parental, Adoption, Surrogacy Leave
  • Backup and On-Site Childcare
  • Well-Being Rewards
  • Employee Assistance Program (EAP)
  • Fertility Benefits, Healthy Pregnancy Program
  • Flexible Spending & Commuter Accounts
  • Pet, Home & Auto, Identity Theft and Legal Insurance

Education, training, and certification

  • Cloud certifications are highly desirable, particularly AWS Certified Security – Specialty or AWS Certified Solutions Architect, and Microsoft certifications such as AZ-500 or SC-300.
  • Broad security certifications such as CompTIA Security+, GIAC GCLD (Cloud Security Essentials) or GCSA, or (ISC)² CCSP are valued.
  • Progress toward or interest in a senior-level certification such as CISSP is viewed favorably.

About Atlantic Health System

Atlantic Health System is a leading non-profit health care system headquartered in Morristown, New Jersey. Facilities and sites of care include multiple hospitals and care centers such as Atlantic Health Morristown Medical Center, Atlantic Health Overlook Medical Center, Atlantic Health Newton Medical Center, Atlantic Health Chilton Medical Center, Atlantic Health Hackettstown Medical Center, Atlantic Health Goryeb Children's Hospital, Atlantic Health CentraState Healthcare System, Atlantic Medical Group, Atlantic Visiting Nurse, Atlantic Mobile Health, and Atlantic Rehabilitation. Atlantic Medical Group includes more than 900 community-based healthcare providers affiliated.

Similar Jobs