Security Operations Engineer
NewYork-Presbyterian HospitalAbout the role
Location
New York, New YorkShift:
Day (United States of America)Description:
Security Operations Engineer
Position Summary
The Security Operations Engineer operates and maintains the InfoSec team’s portfolio of 24x7 Security Operation center , Security Monitoring, Security Incident and Event Management (SIEM), automation, and authentication tools. Additional tasks include forensic recovery/support, event management, spam investigation, threat feed management, proactive defense, network sensor auditing, and security event management. This is a multi-dimensional role, partnering closely with peer teams inside the Information Security department, and business partners across a large, multi-campus healthcare organization. These partnerships ultimately result in an enhanced defense posture and proactive development of secure, robust solutions across the organization.
Essential Job Duties
- Responsible for the daily duties associated with NYP’s Security Operations team including the extension of services provided to all of NYP’s campus and regional affiliates.
- Implements and supports the SIEM tool, to include the inclusion of data sources and any applicable monitoring agents.
- Implements and supports the scanning platform, vulnerability attack platform, privileged account management solution and other discovery tools as required.
- Implements and supports the Security event management platform to include all correlation and automation capabilities for security functions.
- Implements and supports web security platforms, the threat prevention system, and other network based sensors as required.
- Review daily threat feeds, host alarms, cloud based reporting, and similar information in order to proactively mitigate threats
- Collects and disseminates reports, metrics, and other indicators of event and incident management functions.
- Partners with the Vulnerability Management, Security Engineering, and Event and Incident Management teams in order to provide critical development and automation tasks in support of the group’s mission.
- Partners with the Event and Incident Management team in order to take security event intelligence and produce actionable alarming for the purpose of proactive management of security incidents.
- Develops test plans, test data and testing schedules. Conducts unit and system tests to verify results of software solutions.
- Installs/performs in-house and vendor updates, in a timely and efficient manner in accordance with IS change control standards and procedures.
- May work in multiple phases of systems and applications analysis, and considers the business implications of the application of technology to the current business environment.
“May require occasional on-site presence; therefore, should live within a commutable distance. No relocation assistance available.”
Preferred Qualifications
- CISSP, SANS Certification (GPEN, GSOC)
- Knowledge and experience with SIEM tools such as Splunk
- Knowledge and experience with vulnerability management platforms such as Nexpose, Nessus, etc
- Knowledge and experience with network security platforms including SIEM, firewalls, intrusion detection and prevention, web proxies and internet content filtering.
- Knowledge of cryptography and encryption products, data loss prevention, mobile device management.
- Functional and practical experience with scripting and automation techniques
- Strong organization skills to prioritize work/life balance, and lead complex projects.
- Strong interpersonal skills and ability to interact with customers, senior level personnel, subordinates, and team members.
- Strong leadership skills to explain and guide peer business partners with vulnerability remediation.
Required Qualifications
- Bachelor’s degree in a technical or engineering discipline; or equivalent experience
- At least 3-5 years or equivalent of technical experience in an IT related field
- Knowledge and experience with SIEM tools such as Splunk
- Knowledge and experience with vulnerability management platforms such as Nexpose, Nessus, etc
- Knowledge and experience with network security platforms including SIEM, firewalls, intrusion detection and prevention, web proxies and internet content filtering.
- Knowledge of cryptography and encryption products, data loss prevention, mobile device management.
- Functional and practical experience with scripting and automation techniques
- Strong organization skills to prioritize work/life balance, and lead complex projects.
- Strong interpersonal skills and ability to intera
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s