Jobs and Careers
AT

Cybersecurity Engineer III

Atlantic Health System
Morristown, United Statesfull_timeVerifiedPosted 14 Jul 2026

About the role

This Cybersecurity Engineer III position, with a primary focus on senior-level vulnerability management, is responsible for providing thought leadership and enhancing the cybersecurity team in identifying, assessing, prioritizing, and remediating security vulnerabilities across the organization’s endpoints, servers, networks, cloud, and applications. This role involves designing, implementing, and optimizing enterprise vulnerability management solutions—including Rapid7 and Tenable Nessus—to reduce risk to protected health information (PHI) and other regulated data, as well as performing vulnerability scanning, risk-based prioritization, remediation tracking, metrics and reporting, and mentoring junior team members while providing strategic direction to the team and organization. While vulnerability management is the primary focus of this position, the successful applicant will also work as part of a dynamic team responsible for cybersecurity incident response, as well as other cybersecurity-related initiatives, and will share in rotating on-call responsibilities, drawing on broad cybersecurity knowledge to support detection, triage, and response activities.

Duties and Responsibilities

  • Lead efforts in designing, deploying, and maintaining enterprise vulnerability management solutions and scanning infrastructure across endpoints, servers, network devices, cloud, and applications.
  • Administer, configure, and optimize Rapid7 (InsightVM/Nexpose) and Tenable Nessus to discover assets, scan for vulnerabilities, and assess exposure across the environment.
  • Perform risk-based prioritization of vulnerabilities using CVSS, threat intelligence, and asset criticality, and develop, tune, and continuously improve scanning policies and remediation workflows.
  • Track and drive vulnerability remediation to closure in coordination with IT, infrastructure, application, and patch management teams, including validation and root cause analysis of recurring findings.
  • Develop and maintain vulnerability metrics, dashboards, and reporting for technical teams and leadership, and collaborate with teams throughout ISS, as well as Privacy and Compliance, to ensure the protection of PHI and adherence to HIPAA and other regulatory requirements.
  • Provide mentorship and guidance to junior and mid-level cybersecurity engineers.
  • Participate in the development and implementation of cybersecurity strategies and policies.
  • Serve as part of a dynamic incident response team, assisting with the detection, triage, investigation, containment, and remediation of security incidents.
  • Conduct offensive security exercises, such as penetration testing and red team activities, to proactively identify vulnerabilities and validate defenses across the network.
  • Participate in a rotating on-call schedule to support time-sensitive vulnerability and incident response activities outside of normal business hours.

 

Education, Training and Certification

  • Bachelor's degree or higher in Cybersecurity, Information Technology, or a related field is preferred; equivalent experience may be considered in lieu of a degree for exceptionally qualified candidates.
  • Relevant certifications such as CISSP, GIAC GEVA (GIAC Enterprise Vulnerability Assessor), CompTIA Security+, CompTIA PenTest+, or equivalent are highly desirable.

 

Knowledge and Experience

  • Strong understanding of vulnerability management principles, the vulnerability lifecycle, CVSS scoring, and risk-based remediation practices.
  • Hands-on proficiency with Rapid7 (InsightVM/Nexpose), Tenable Nessus, and other vulnerability scanning and assessment technologies across endpoints, servers, network, cloud, and applications.
  • Extensive experience implementing and operating enterprise vulnerability management programs, including scan configuration, risk-based prioritization, and remediation tracking.
  • 3–5 years of experience in vulnerability management, information security, or information technology in a large organization, preferably a large healthcare environment.
  • Hands-on experience contributing to incident response, including alert triage, investigation, containment, and remediation.
  • While not a requirement, the candidate should have so

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Atlantic Health System

View company profile →