Job Details

Cyber Security Specialist II

Baylor Scott & White Healthcare
Dallas, Texas, United States
Job Summary The Security Specialist II role supports specialized functions within the security organization and plays a key role in enhancing our security posture by minimizing the overall attack surface and risk exposure. Candidates must have hands on experience in threat and vulnerability management, insider threat management, cyber security, or an intelligence related discipline. Applicates must have the ability to methodically examine the organization through the perspective of a threat actor and articulate observed risks with accuracy and precision. Essential functions Engage in tactical and strategic design and deployment of defensive operations, preventive measures, and cyber security controls to enhance overall organizational security and minimize attack surface. Collect, analyze and interpret both structured and unstructured data to formulate a comprehensive view into current and emerging threats. Engage with technical and non-technical staff to develop, deploy, maintain scalable controls to minimize risk exposure across numerous systems and technologies. Engage with clinical leaders to evaluate medical devices and other critical systems, identify threats, develop mitigating controls, and communicate business risk as it relates to the overall threat posture. Conduct end-to-end investigations and identify attack tactics, paths, methods, capabilities with the goal of developing comprehensive threat detection models and enterprise wide recommendations for scalable mitigating controls. Develop and analyze dynamic attack indicators or risk detection models to identify patterns of noncompliance and develop capabilities to minimize security risks. Conduct vulnerability assessments in support of security, compliance, and regulatory controls in alignment with business requirements. Perform assessments of systems and network environments or enclaves to measure risk associated with assets based on enclave policies, configuration information, vulnerability details, or other risk indicators. Collaborate and engage internal groups such as security engineering, security operations, network operations, Biomed, Human resources, clinical groups, physical security and other internal stakeholders to identify threats and reach holistic mitigations. Develop processes and standard operating procedures to support team resiliency and knowledge transfer. Own and execute on strategic and tactical projects and key initiatives in alignment with organizational goals and objectives. Experience, Knowledge, Skills, abilities Experience in an intelligence role, engineering, information security, threat intelligence, military intelligence, defense intelligence or equivalent. Advanced experience with enterprise threat and vulnerability management programs, Insider threat programs, security testing and remediation, and infrastructure scanning. Advanced Knowledge of OWASP and experience in cyber risks management and threat intelligence related to cyber attackers including common hacking tools, common attack vectors, and knowledge of behavioral patterns connected to fraud, risk, and abuse. Advanced knowledge and hands-on experience implementing system hardening techniques and best practices. Moderate knowledge of security technologies, including, SIEM, IDS/IPS, firewalls, endpoint security, content filtering, and packet inspection. Advanced knowledge of threat hunting tools, open source intelligence collection methods, and related technologies. Moderate knowledge of common tools and operating systems such as Wireshark, Metasploit, Nmap, Burp suite, Nessus, Kali, Windows, and OSX. General networking knowledge and an understanding of the OSI Model and TCP/IP. Experience performing security investigations, triage, and response on cloud platforms (AWS, Azure, Google Cloud). Strong analytical skills and ability to identify advanced threats by analyzing various raw data streams. Experienced with scripting languages such as Python, Perl, PowerShell, bash or similar. Moderate knowledge and hands on experience with common industry frameworks such as ATT, Kill Chain, Diamond Model, NIST, HIPPA, PCI. Experienced with supporting joint enterprise security group in major incidents and cyber investigations. Experience handling highly confidential, business critical information in a professional manner. Strategic thinker, data-driven and analytical in approach to solving problems. Excellent teamwork, interpersonal, effective oral and written communication skills along with prior experience in a dynamic team environment. Excellent judgment, problem-solving, decision-making skills. Specialty/Department/Practice - IS Risk Management Shift/Schedule - Fulltime / Day's Benefits - Our competitive benefits package includes*: Immediate eligibility for health and welfare benefits 401(k) savings plan with dollar-for-dollar match up to 5% Tuition Reimbursement PTO accrual beginning Day 1 *Note: Benefits may vary based upon position type and/or level. QUALIFICATIONS EDUCATION - Bachelors or Equivalent Exp EXPERIENCE - A minimum of 8 years' experience required, Minimum 4 years managing people, Minimum 4 years in IS

Send application

Mail this job to me so I can apply later

Apply With CV

You are not logged in. If you have an account, log in to your account. If you do not have an account, why not sign up? It only takes a minute!

latest videos

Upcoming Events