{"22253555":{"jobPath":"/jobs/22253555/manager-of-information-technology","source":"naylor","job":"22253555","jobTitle":"Manager of Information Technology"},"22256828":{"jobPath":"/jobs/22256828/chief-information-officer","source":"naylor","job":"22256828","jobTitle":"Chief Information Officer"},"22267835":{"jobPath":"/jobs/22267835/institute-auditor","source":"naylor","job":"22267835","jobTitle":"Institute Auditor"},"22262464":{"jobPath":"/jobs/22262464/director-of-information-technology-audits-hybrid","source":"naylor","job":"22262464","jobTitle":"Director of Information Technology Audits - Hybrid"},"22241129":{"jobPath":"/jobs/22241129/information-systems-assistant-director","source":"naylor","job":"22241129","jobTitle":"Information Systems Assistant Director"},"22293229":{"jobPath":"/jobs/22293229/senior-it-security-engineer","source":"naylor","job":"22293229","jobTitle":"Senior IT Security Engineer"},"22282057":{"jobPath":"/jobs/22282057/senior-accountant-government-consulting-services","source":"naylor","job":"22282057","jobTitle":"Senior Accountant – Government/Consulting Services"},"22293243":{"jobPath":"/jobs/22293243/director-of-safety-security-health-and-preparedness","source":"naylor","job":"22293243","jobTitle":"Director of Safety, Security, Health, and Preparedness"},"22262469":{"jobPath":"/jobs/22262469/director-of-information-technology-audits-hybrid","source":"naylor","job":"22262469","jobTitle":"Director of Information Technology Audits - Hybrid"},"22273056":{"jobPath":"/jobs/22273056/it-audit-manager","source":"naylor","job":"22273056","jobTitle":"IT Audit Manager"},"22279677":{"jobPath":"/jobs/22279677/coordinator-association-governance-operations","source":"naylor","job":"22279677","jobTitle":"Coordinator, Association Governance Operations"},"22298833":{"jobPath":"/jobs/22298833/security-officer","source":"naylor","job":"22298833","jobTitle":"SECURITY OFFICER"},"22253462":{"jobPath":"/jobs/22253462/director-business-integrations-application","source":"naylor","job":"22253462","jobTitle":"Director, Business Integrations & Application"},"22166418":{"jobPath":"/jobs/22166418/it-auditor-cisa-certified","source":"naylor","job":"22166418","jobTitle":"IT Auditor - CISA certified "},"22273337":{"jobPath":"/jobs/22273337/senior-internal-auditor-it-risk-advisory","source":"naylor","job":"22273337","jobTitle":"Senior Internal Auditor - IT Risk & Advisory"},"22295748":{"jobPath":"/jobs/22295748/director-internal-audit","source":"naylor","job":"22295748","jobTitle":"Director, Internal Audit"},"22270824":{"jobPath":"/jobs/22270824/security-engineer-application-security","source":"naylor","job":"22270824","jobTitle":"Security Engineer, Application Security"},"22233678":{"jobPath":"/jobs/22233678/information-security-operations-manager","source":"naylor","job":"22233678","jobTitle":"Information Security Operations Manager "},"22259329":{"jobPath":"/jobs/22259329/senior-information-security-analyst","source":"naylor","job":"22259329","jobTitle":"Senior/Information Security Analyst"},"22251028":{"jobPath":"/jobs/22251028/manager-physical-security-systems","source":"naylor","job":"22251028","jobTitle":"Manager Physical Security Systems "},"22262214":{"jobPath":"/jobs/22262214/supervisor-health-information-and-data","source":"naylor","job":"22262214","jobTitle":"Supervisor, Health Information and Data"},"22259654":{"jobPath":"/jobs/22259654/senior-manager-cyber-security-product-innovation","source":"naylor","job":"22259654","jobTitle":"Senior Manager, Cyber Security Product & Innovation"},"22241111":{"jobPath":"/jobs/22241111/cyber-security-architect","source":"naylor","job":"22241111","jobTitle":"Cyber Security Architect"},"22241232":{"jobPath":"/jobs/22241232/security-engineer","source":"naylor","job":"22241232","jobTitle":"Security Engineer"},"22241116":{"jobPath":"/jobs/22241116/senior-cyber-security-specialist","source":"naylor","job":"22241116","jobTitle":"Senior Cyber Security Specialist"}}
The Senior IT Security Engineer is responsible for identifying, evaluating, and implementing technical security controls to prevent, detect, contain, and respond to information security threats, which includes supporting the technology efforts of AltaMed. This person is required to analyze threats using a variety of security technologies, including email filtering, anti-malware, access control, phishing detection, Cloud Access Security Broker (CASB)/web filtering, firewalls, intrusion detection/prevention, data loss prevention, and data encryption. Reviews and guides security configuration of a variety of applications and endpoint systems, including servers, desktops, network devices, and Internet of Things (IOT)/Operational Technology (OT) devices. Required to lead projects and project teams within and outside the security department. Must maintain an in-depth understanding of current and emerging security threats, recommending technical and process improvements to protect against such threats. This individual also assists in the development and maintenance of information security strategy and will be required to provide support across other technology and business units, ensuring the implementation and operation of the appropriate security controls across the organization are aligned with Information Security policies and standards.
Bachelor’s Degree in Computer Science, Health / Business Administration, or Information Technology, and 4 years of progressive experience in information security as an engineer, architect, or analyst.
Instead of a college degree, 6 years of progressive experience in information security as an engineer, architect, or analyst.
Knowledge and understanding of relevant legal and regulatory requirements (i.e., HIPAA, PCI, Privacy, etc.) are required.
Must hold an active Certified Information Systems Security Professional (CISSP) certification.
Skills and Abilities
Strong analytical skill set to decipher business needs and recommend solutions.
Must have the ability to manage multiple deadlines.
Excellent problem-solving abilities.
Detail-oriented and able to follow up and follow through on project actions and tasks.
Demonstrated ability to address IT risk by coming up with the appropriate security controls to mitigate the risk to the business.
Excellent communication and organization skills, both written and verbal
Superior customer focus and the ability to manage customer expectations.
Demonstrated commitment to and leadership of continuous process improvement.
Essential Job Functions
Serves as the primary technical security engineer responsible for maintaining and managing controls over secure email, anti-phishing, vulnerability management, anti-malware, Cloud Access Security Broker (CASB) / web filtering, Data Loss Prevention (DLP), and mobile device security, helping AltaMed Health Services comply with enterprise and IT security policies, Federal/State law, industry regulations, and best practices.
Designs and implements security controls to address information security policies, standards, and other requirements as they relate to specific internal and externally hosted IT systems. Where appropriate, collaborates with internal and external technology teams to understand and implement AltaMed's information security requirements.
Conducts risk and vulnerability assessments of existing and potential new systems and, as appropriate, recommends information security controls and remediation activities to address identified risks, threats, and vulnerabilities and identifies integration issues and potential cost estimates for recommended solutions.
Leading threat hunting activities and assisting in audits and third-party penetration tests to identify areas of risk to AltaMed.
Proactively reviews information security news sources for risk and threat trends as well as third-party software updates for systems potentially impacting AltaMed.
Proactively monitors updates to legal, regulatory, and industry requirements and control frameworks, such as HIPAA Security Rule, PCI Data Security Standards, State and Federal Privacy Laws, NIST Cyber Security Framework, NIST 800-30, NIST 800-53, etc.
Assists in the designing and engineering of internal information handling processes so that information is appropriately protected from a wide variety of problems, including unauthorized disclosure, unauthorized use, inappropriate modification, premature deletion, and unavailability
Assists in incident response efforts by investigating suspicious activity under direction from the VP, documenting work performed, and providing timely updates to the VP on progress and results.
Ensure all areas of the Information System and Technology environment adhere to regulatory requirements (HIPAA, CPRA/CCPA, HRSA, etc) and established standards of good practice or defined information security frameworks (NIST Cyber Security Framework, NIST 800-30, NIST 800-53, PCI Data Security Standard, etc.)
As the nation’s largest Federally Qualified Health Center (FQHC), AltaMed is at the forefront of providing affordable, high-quality health care to underserved communities in Los Angeles and Orange Counties. At AltaMed, you will have the opportunity to work with a diverse team of dedicated professionals who are passionate about making a difference and supporting our community of over 400,000 patients.