Cybersecurity Sr Engineer Penetration Tester

Common Spirit Englewood , CO 80110

Posted 2 months ago

Overview

CommonSpirit Health was formed by the alignment of Catholic Health Initiatives (CHI) and Dignity Health. With more than 700 care sites across the U.S. from clinics and hospitals to home-based care and virtual care services CommonSpirit is accessible to nearly one out of every four U.S. residents. Our world needs compassion like never before. Our communities need caring and our families need protection. With our combined resources CommonSpirit is committed to building healthy communities advocating for those who are poor and vulnerable and innovating how and where healing can happen both inside our hospitals and out in the community.

Responsibilities

This is a remote position.

Job Summary

The Cybersecurity Engineer Penetration Tester position supports the Vulnerability Management and Cyber Hygiene (VMCH) program for CommonSpirit Health. This program provides cyber hygiene requirements and guidance, performs technical security assessment services, maintains VMCH security systems and workflows, and provides engagement and reporting services on specific and systemic security vulnerability and configuration issues for the enterprise.

The Cybersecurity Engineer will report to the Manager, Vulnerability Management and Cyber Hygiene as part of the overall Cyber Vigilance and Defence group, focused on identifying, protecting, responding and containing threats and Vulnerabilities to the overall CommonSpirit organization.

The Cybersecurity Engineer performs Penetration Testing activities to identify system and application weaknesses, misconfigurations, or other flaws in operating systems, network devices, mobile applications, web applications, or other technologies that could lead to security compromises, as well as gaps in current control states. Monitors the threat and vulnerability landscape and changing business requirements to identify functional, technological and/or control solutions. Independently develops, conducts, and reports on penetration testing activities with leadership approval. Engages in purple and red team exercises. Develops, integrates, and maintains penetration testing tools and platforms. Integrates all cybersecurity solutions in an optimal manner to best protect the organization from cyber threats and exposures. Technological solution owner responsible for technology selection based on business requirements.

May drive one or more projects, acts as a subject matter expert (SME) for one or more penetration testing methods, tools, and target environments. Develops and maintains testing methodologies to identify MitreAttack Framework related issues, and assists in the remediation of the same. May act as team-lead for other security personnel. Mentors other engineers as a leader in the organization.

Job Responsibilities

  • Designs, develops, and implements new penetration testing solutions to integrate into and test within existing or newly defined architectures.

  • Provide support on team related penetration testing engagements with Security Engineering, Identity Management Engineering, Security Architecture, CSOC, Network Engineering, Clinical Engineering, Systems Engineering, Application Development, and/or other IT Operations and business function owners.

  • Act as a security advocate for IT Operations team's adherence to CommonSpirit Health policies, security standards and requirements, and industry best practices.

  • Manage workload, prioritizing tasks and documenting time, and other duties as directed by management.

  • Pursue continuing education to grow and maintain knowledge of best practices, compliance requirements, penetration testing methodologies, vulnerabilities, threats and trends in information security, translating into operational action items, policies, procedures, standards and guidelines as part of the IT Security team.

  • Participate in the collection and documentation of departmental knowledge artifacts, participant in the development and population of knowledge management and collaboration systems for the IT Security team.

  • Communicates security and technical information to team members and across the IT Organization.

  • Assists Management in identifying knowledge, process, and technology gaps.

  • Provide service line support for penetration testing by conducting technical tests (OS, network, apps, mobile, etc.) as well as social engineering tests.

  • Perform reviews and analysis of system and applications vulnerabilities and configurations, and support Security technical Risk Management processes.

  • Proactively identify, engage on, and escalate vulnerability and configuration issues, either system/application specific or systemic. Lead specific engagement and remediation efforts.

  • Designs, develops, configures, and implements solutions to resolve intermediate technical and business issues related to information security.

  • Reviews and consults on security of technology solutions to resolve intermediate to high technical and business issues.

  • Provides support and works on multiple functions of intermediate to high complexity.

  • Serves as SME for one or more penetration testing methodologies.

Qualifications

  • Bachelor's Degree in Computer Science, Information Security, Information Systems, or related field, or equivalent professional experience required.

  • 4-5 years job related experience required, specifically conducting penetration testing on a multiple set of target types.

  • Experience in Windows, UNIX/Linux OS required.

  • Functional understanding of regulatory and compliance mandates and frameworks, including but not limited to: HIPAA, HITECH, PCI, Sarbanes-Oxley, Center for Internet Security (CIS), NIST, or MITRE Attack Framework preferred.

  • Experience conducting Vulnerability Testing (Network, Application, Database, and/or System Security), Analysis, Prioritization, and Documentation, and the management of communication with leadership and affected stakeholders preferred.

  • Knowledge of healthcare environments preferred.

  • Previous project management or project coordination experience preferred.

  • Previous Information Security experience in the healthcare/medical environment strongly preferred.

#LI-Remote

#LI-CSH


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Cybersecurity Sr Engineer Penetration Tester

Common Spirit