Lead Security Engineer
Cybersecurity at Providence is responsible for appropriately protecting all information relating to its caregivers and affiliates, as well as protecting its confidential business information (including information relating to its caregivers, affiliates, and patients)
What will you be responsible for?
- Responsible for driving automation with Providence Enterprise security tools and services to bring in process efficiency and improvements in cyber security teams.
- Driving security automation workflows and build automation to bring impact in everyday workflows in threat management, security incident response and security operations teams.
- Identify scope for automation that improves security best practices and implement process workflows that strengthen the overall security posture.
- Participate in all Security operation and engineering meetings, including design, implementation, and identify scope for automation wherever needed in the overall workflow.
- Troubleshoot, debug, and optimize existing and new automation code/scripts and stay ahead of with cyber threats in healthcare and overall threat landscape and attack methods in cyber security industry.
What would your work week look like?
- Collaborate with cross-functional teams and engage in building process and tool automation opportunities in threat and cyber incident response.
- Constantly look for healthcare-oriented threats and risks and build automation workflows using enterprise tools for alerting and response.
- Work in XSOAR automation tool to create new or review/optimize existing automation workflows.
- Identify and implement SOAR automation use cases that aligns with industry standard frameworks such as NIST, CIS and Providence information security policies etc.
- Set-up regular meetings with stakeholders to show progress of SOAR automation use cases and automation use cases implemented with applicable metrics.
- Clearly communicate security automation roadmap, backlog, and team updates across the organization.
Who are we looking for?
- Bachelor’s degree in related filed, to include computer science, cyber security or equivalent combination of education and experience.
- 4-8 years of relevant post-qualification experience, with at least 3 years of proven experience in building automation workflows using SOAR for security engineering and security operation functions.
- Solid understanding of building or writing automation scripts using Python, PowerShell or any other scripting language.
- Hands-on experience in any vendor SOAR automation tool- Palo alto XSOAR preferred.
- Solid understanding in building secure API integration with industry standard EDR, SIEM, firewall and vulnerability management tools.
- Good understanding in implementing automation best practices and workflows- Secure key management and rotation, efficient resource handling etc.
- Understanding of AI and Large Learning Models (LLMs) and ability to leverage them to build security automation workflows.
- Familiarity with cloud native solutions, application containerization and container orchestration (Docker, Kubernetes), Infrastructure as Code (IaC), helm charts and YAML template configuration.
- Scripting or programming understanding with Shell scripting, Power Shell, KQL, CQL query languages is desirable.