Search jobs > Salt Lake City, UT > Information security

Information Security & Risk Engineer

Cardinal Health
Salt Lake City, UT, United States
$92.1K-$131.6K a year
Full-time

Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE : CAH) is a global, integrated healthcare services and products company connecting patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management.

Backed by nearly 100 years of experience, with more than 50,000 employees in nearly 60 countries, Cardinal Health ranks among the top 20 on the Fortune 500.

Cardinal Health’s Information Security team aims to be a world-class cybersecurity and risk management organization that enables Cardinal Health to be healthcare’s most trusted partner.

We define solutions that balance information security requirements against business needs. We are a remote-first team and are excited to offer full-time remote opportunities.

We boast tremendous opportunities to grow and apply technical skills to meet organizational needs, empower talented team members who mentor and uplift others, be led by leaders with a critical focus on employee development and well-being, provide dedicated training programs with a fun and collaborative atmosphere.

Functional OverviewThe primary goal of this position is to ensure delivery of best-in-class cybersecurity, risk management, and compliance for Cardinal Health.

This role will support other Security Officers in managing their portfolio as well as independently manage compliance tasks within the security space.

Job OverviewThe Information Security & Risk Engineer will be responsible for day-to-day activities in implementing the corporate information security and compliance program.

The individual will be a front-line partner to technical teams and work across the organization to deliver security and compliance initiatives aligning to corporate policies, standards, procedures and audit activities.

Success in the role will be measured by the effectiveness of the implementation of information security, risk management and compliance directives.

This role will work with various IT and business teams to drive both information security and compliance initiatives. The individual will assist with internal and external security compliance monitoring activities, review client audits, IT control audits, architecture reviews, threat modeling, security risk assessments and will assist in the management of compliance activities such as NIST, HIPAA, SOC 2, FedRAMP, PCI, ISO27001, HITRUST and SOX.

Good interpersonal and relationship building skills are essential for success.Job Responsibilities Include : Maintain governance program that ensures that the security policies, standards and process are in placeServe as liaison to other Cardinal Health teams to ensure knowledge share and best practicesPartner with the engineering, architecture and operations teams to ensure delivery of infrastructure design and threat models which prove security requirementsMonitor security trends and drive security best practices throughout the organizationEvaluate, design, test, and recommend new or improved controlsWork with third party firms and consultants to conduct independent security audits, vulnerability scans, and penetration testsInvestigate, drive resolution and document security incidentsQualificationsBachelors Degree in related field, or equivalent work experience leading cybersecurity or information security initiativesHave 3+ years information security related work experience, preferably within the healthcare industryExperience in vulnerability management programs, vulnerability assessments and advanced understanding of risk managementFamiliarity with at least one common programming language, software development pipelines, and system lifecyclesFamiliarity with security frameworks and assessments such as HIPAA / HITECH, ISO, ITIL, NIST, PCI DSS, & SOXFamiliarity with common security vulnerabilities like OWASP Top 10Experience advising and mentoring diverse teams where you do not have direct authorityStrong written and verbal communication skillsAnticipated salary range : $92,100 - $131,600Bonus eligible : NoBenefits : Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

Medical, dental and vision coveragePaid time off planHealth savings account (HSA)401k savings planAccess to wages before pay day with myFlexPayFlexible spending accounts (FSAs)Short- and long-term disability coverageWork-Life resourcesPaid parental leaveHealthy lifestyle programsApplication window anticipated to close : 5 / 15 / 2024 *if interested in opportunity, please submit application as soon as possible.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day.

Cardinal Health is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity / expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here ()

2 days ago
Related jobs
Promoted
L3Harris Technologies
Salt Lake City, Utah

Lead, Information Security Systems Engineer. Information Security Systems Engineer . As a Lead, Information Security Systems Engineer at L3Harris Technologies, you will be involved in the cryptography that enables communication capabilities for the warfighter. Other security or technical certificati...

Promoted
Myriad Genetics
Salt Lake City, Utah

Responsible for the management, monitoring and implementation of various security systems and controls including, O365, AWS Cloud Security, vulnerability management, security information and event management (SIEM), Intrusion Detection and prevention, network access controls, network and host based ...

Promoted
L3Harris Technologies
Irving Park Addition, Utah

Lead, Information Security Systems Engineer. Information Security Systems Engineer . As a Lead, Information Security Systems Engineer at L3Harris Technologies, you will be involved in the cryptography that enables communication capabilities for the warfighter. Other security or technical certificati...

Promoted
Cardinal Health
Salt Lake City, Utah

Cardinal Health’s Information Security team is on a tremendous growth journey adding a number of new team members in our Cyber Threat Operations Center, IT Risk and Compliance, and Security Architecture teams. We aim to be a world-class cybersecurity and risk management organization that enables Car...

Promoted
L3Harris Technologies
Salt Lake City, Utah

Leads and contribute to all Product or Network Information Security Engineering activities pertaining to CDRLs, trade studies, security requirements analysis, secure architecture development, management & compliance with security controls, design review milestones (SRR, SDR, PDR, CDR) and security t...

Promoted
General Dynamics Information Technology
Salt Lake City, Utah

The ISSE employs best practices when implementing security requirements within an information system including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques. Assesses and mitigates system security threats/...

L3Harris Technologies
Salt Lake City, Utah

Leads and contribute to all Product or Network Information Security Engineering activities pertaining to CDRLs, trade studies, security requirements analysis, secure architecture development, management & compliance with security controls, design review milestones (SRR, SDR, PDR, CDR) and security t...

GDIT
Salt Lake City, Utah

The Information System Security Engineer (ISSE) is primarily responsible for conducting information system security engineering activities with a focus on lifecycle of current systems and future requirement scoping. The ISSE employs best practices when implementing security requirements within an in...

L3Harris Technologies
Salt Lake City, Utah

Leads and contribute to all Product or Network Information Security Engineering activities pertaining to CDRLs, trade studies, security requirements analysis, secure architecture development, management & compliance with security controls, design review milestones (SRR, SDR, PDR, CDR) and security t...

L3Harris Technologies
Salt Lake City, Utah

As a Specialist, Information Security Systems Engineer at L3Harris Technologies, you will be involved in the cryptography that enables communication capabilities for the warfighter. Other security or technical certifications: CISA, CISM, CEH, CPT, MCSE, CCNA, Red Hat, Network+, SANS GIAC, Security+,...