Senior IT Security Engineer-Architect
Job Description
Chicago, IL (Hybrid)
The American Medical Association (AMA) is the nation's largest professional Association of physicians and a non-profit organization. We are a unifying voice and powerful ally for America's physicians, the patients they care for, and the promise of a healthier nation. To be part of the AMA is to be part of our Mission to promote the art and science of medicine and the betterment of public health.
We continuously work to embed equity in our internal practices and are committed to increasing the diversity of our staff across all levels of the organization. We intentionally work to create the right conditions to enable our employees to feel that they can be their authentic selves and fully participate in the life of the enterprise.
We encourage and support professional development for our employees, and we are dedicated to social responsibility. We invite you to learn more about us and we look forward to getting to know you.
We have an opportunity at our corporate offices in Chicago for a Senior IT Security Engineer-Architect on our Information Technology team. This position can be hybrid (working from both office and home), with a schedule to be determined by business needs.
As a Senior IT Security Engineer-Architect you will responsible for performing all functionsrequired to support the day-to-day IT Security Program including data security,collaboration with the security operations team, and maintaining a broad suiteof information security infrastructure. Accountable for security and networkinginfrastructure component availability and integrity, monitoring compliance withIT security policy, and coordinating investigation and reporting of securityincidents. Provide subject matter expertise on the design, implementation, andoperation of technical and process security controls for the AMA's ITDepartment and business units by assessing risk within projects and planned changesand to support achievement of the goals and objectives of the AMA's InformationSecurity Management System (ISMS).
RESPONSIBILITIES:
System/Network/Application Security
- Design, evaluate, and test the security of AMA applications, systems and networks to ensure the operational effectiveness of technical controls implemented by the organization; purpose-built security tools such as data loss prevention, logging and event management, enterprise encryption systems and also security controls embedded in enterprise systems and applications such as authentication and access controls
- Responsible for the operation of AMA security systems including enhancements, upgrades, and lifecycle management
- Ensure the technical integration of security components within the AMA's environment to optimize the value and control benefits including ease of use, effectiveness, and breadth of coverage
Technology Risk Management
- Assess technical risks in the AMA's environment both pre and post-production through the AMA's Software Development Lifecycle (SDLC) and Change & Release Management Boards; communicate identified risks and recommend solutions
- Manage the research, appropriate response, and remediation of malicious and inappropriate activity; ensure consistency of the risk assessment approach across the organization
Service Delivery
- Manage continuous improvement process to identify technical improvements in the delivery of IT Security services to increase service quality
- Prioritize improvements on a cost/benefit basis, communicating opportunities to management.
- Serve as backup and/or escalation point in the fulfillment of IT Security service requests
Project Management
- Manage IT Security-led projects following the AMA's applicable project governance processes, including Software Development Life Cycle; ensure successful project outcomes, such as completing projects within time and budget tolerances
- Support new software and service provider product and contract reviews
May include other responsibilities as assigned
REQUIREMENTS:
- Minimum 10+ years engineering/design experience with a mix of the following security platforms is required: network and application-layer firewalls and secure network design; infrastructure and application-layer vulnerability management, security information and event management (SIEM); Security, Orchestration, Automation and Response (SOAR), data loss prevention (DLP); enterprise encryption solutions for database, file systems and data in motion; Internet/Web Gateway; end point security controls (such as anti-virus, anti-malware XDR, host-based firewall, and full disk encryption solutions); and intrusion detection and prevention systems. Knowledge of Attack and Penetration methodologies, tools and techniques.
- Minimum 5 years conducting infrastructure and application project design reviews. Engineering/design experience with a mix of the following infrastructure technologies is required: Microsoft/Azure (Active Directory (ADFS), O365, Sharepoint 2019, Windows Server 2019-2022, Windows 10-11); Red Hat Linux VMware, AWS EC2, S3, IAM.
- Working knowledge of security scanning and analyzing tools; Commercial Application and Infrastructure/Operating System and Opensource Vulnerability scanning/management, and freeware/commercial Wireshark, NMAP, Burp Suite, Nikto, Qualys, Tenable, Snyk, SonarQube
- Polished verbal and written communication, interpersonal, analytical, and organizational skills, attention to detail, and a high level of integrity are required.
- Experience with project management and software development lifecycle methodologies preferred.
- Professional IT Security and IT Audit certifications such as CISSP, CISM, CEH, CISA and/or technical certifications preferred.
- Experience with IT Infrastructure Library (ITIL) - particularly incident, change, release, and/or problem management preferred.
- Experience with IT security standards, such as CIS Top 20, ISO 27001, NIST CSF, NIST 800-53, HITRUST, MITRE, OWASP, CWE/SANS Top 25 Programming Errors, and attestation reports such as SOC 1/2/3 and technology risk management methodologies, such as NIST 800-30 preferred.
- Experience with compliance standards such as Payment Card Industry (PCI), Sarbanes Oxley (SOX) and Health Insurance Portability & Accountability Act (HIPAA) preferred.
- High School Diploma or equivalent required, Bachelors and or Masters Degree in Computer Science or related discipline preferred.
- AMA's safety and policy protocols require proof of full vaccination against COVID19 for employment at AMA (including booster when eligible). Employees may apply for a religious or medical exemption from getting the vaccine.
Additional Technical Background
- Experience with:
- Cloud-based security tools (CloudTrail, WAF, Security Center, etc.)
- Source code management tools (GitHub, BitBucket, etc.)
- Code scanning tools (Dynamic, Static and Opensource)
- Vulnerability Management solutions (Qualys, Tenable)
2. Knowledge Of:
- User authentication such as Zero Trust concepts, SAML and OAuth-based SSO architectures and IDP integrations, MFA, Virtual Private Networks (VPNs), TLS, PAM, corporate wifi, device identity, 802.1x port-based authentication, server identification, authentication of web applications, S/MIME Email Signing, is desirable
- Programming languages (.Net, Java, JavaScript, Angular, Drupal, Python, etc.)
- Web services, API, REST, RPC
- Infrastructure as Code (CloudFormation, Terraform) preferred
- Administration of Azure suite, including; Azure Active Directory, Conditional Access, Intune, Mobile Application Management, Microsoft Cloud App Security and/or advanced Azure security services like Azure Security Center, Advanced DDoS Protection, Azure Firewall, and Azure WAF
- Administration of AWS security services and related best practices: GuardDuty, Cognito, Inspector, Detective and advocate AWS Identity & Access Management (IAM)
- Operating systems: Windows, Mac, Linux, WVD, VDI and Jump Boxes/Bastion Servers
- Network routing and communication frameworks, protocols, and technologies such as OSI, TCP/IP v4 & v6, RIP, OSPF, VPN, HTTPS, TLS, and SSH is required.
- Working knowledge of SQL, LDAP, and/or regex is a plus.
The American Medical Association is located at 330 N. Wabash Avenue, Chicago, IL 60611 and is convenient to all public transportation in Chicago.
We are an equal opportunity employer, committed to diversity in our workforce. All qualified applicants will receive consideration for employment. As an EOE/AA employer, the American Medical Association will not discriminate in its employment practices due to an applicant's race, color, religion, sex, age, national origin, sexual orientation, gender identity and veteran or disability status.
THE AMA IS COMMITTED TO IMPROVING THE HEALTH OF THE NATION
Date Posted
12/04/2022
Views
6
Similar Jobs
Sr. Software Engineer - OEMS Team - Enfusion
Views in the last 30 days - 8
Enfusion is a pioneer in developing innovative cloud investment management software analytics and managed services They help fund managers streamline ...
View DetailsMachine Learning Engineer - Oak Street Health
Views in the last 30 days - 8
Oak Street Health is a rapidly growing company that is looking for a machine learning engineer to support their production modeling efforts The compan...
View DetailsPhysical Security Intelligence Specialist - Tempus
Views in the last 30 days - 12
The job posting is for a security manager position at Tempus a company that uses AI to provide realtime insights to physicians The responsibilities in...
View DetailsSenior Benefit Analyst - Lockton Companies
Views in the last 30 days - 6
The Lockton team is seeking a dynamic Senior Benefit Analyst for their Employee Benefits consulting group The analyst will assist in marketing and ser...
View DetailsSoftware Engineer 431407 - Experfy
Views in the last 30 days - 8
The job description is for a Software Engineer position that requires designing developing testing and deploying software systems and applications The...
View DetailsAccount Manager (Advertising Sales Team) - Chicago - CafeMedia
Views in the last 30 days - 6
This is an excellent opportunity to get broad experience in all aspects of digital media The position is based in Chicago IL and requires excellent co...
View Details