Education
Bachelor's degree or current high-level IT security / cybersecurity certification. Associate's degree or mid-level IT security / cybersecurity certification plus 2 years of relevant experience may be considered for individuals with in-depth experience that is clearly related to the position
Degree must be in Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Mathematics, Computer Forensics, Cyber Security, Information Technology, Healthcare IT, Information Assurance, Information Security, and Information Systems)
Relevant experience must be in computer or information systems design/development, programming, information/cyber/network security, vulnerability analysis, penetration testing, computer forensics, information assurance, and/or systems engineering
Experience
2-5 years as a system security engineer or building and maintaining comprehensive IT security systems required
Knowledge, Skills and Abilities
- Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Demonstrated ability to work independently or under only general direction
- Demonstrate effective written and oral communication skills
- Experience with EPIC EMR
- Familiar with Vulnerability Management Process
- Familiar with Security Monitoring & Event Management
- Familiar with Infrastructure patching management process
- Experience using Tenable scanning tool, KnowBe4, Citrix NetScaler
- Familiar with BIOMED device and patch management
- Familiar with Forcepoint web filtering
- Familiar with Mobile Device Management
- Proficiency with Active Directory and Microsoft Office Admin 36
- Requires familiarity with domain structures, user authentication, and digital signatures
- Requires understanding of FISMA policies and procedures, including FIPS 199, FIPS 200, NIST HIPAA, -and other applicable policies
- Knowledge of network tools (e.g., ping, traceroute, nslookup)
- Knowledge of encryption methodologies
Licensures, Certifications
- Preference for certifications for EMR security, network security, cybersecurity or digital forensics from EC-Council, CompTIA, SANS
- Industry cyber tool certifications considered if relevant to GBMC
Patient & Workplace Safety:
Employee has knowledge and understanding of patient and workforce safety as it relates to job duties.
Patient Population:
Demonstrates competency in the delivery of care and applies the knowledge to meet age-specific needs if applicable.
Principal Duties and Responsibilities
SIEM analysis and configuration
- Building and applying infrastructure, policies, dashboards and alerting
Incident Response
- Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities
Systems Access
- Responsible for access control, passwords, and account creation and administration and auditing
Digital Forensics
- Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations
Vulnerability Assessment and Remediation
- Vulnerability detection analysis and remediation through SIEM analysis
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices
- Evaluates vulnerabilities and assist with planning and implement remediation procedures
Policy Administration
- Assist in the creation, auditing and maintenance of policies and procedures in relation to IT and cybersecurity
Patch Management
- Assist in the detection, analysis and remediation of security vulnerabilities in system
Cybersecurity Education
- Ability to prepare and deliver education and awareness briefings to ensure that systems, network, and data users are aware of and adhere to systems security policies and procedures
Knowledge of Cyber Threats/Global Trends
- Remain current in knowledge of cyber threats and global trends - Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise
- Develop content for cyber defense tools
- Performs Computer Security Incident Response according to industry best practice and assist with RCA and forensic documentation
- Assist with design, development and implementation of the Cybersecurity Framework policies and procedures
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices
- Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level
- Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation
- EMR Security Support
- Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance
- Assist with SSL certificate management
- Assist with implementing periodic BCA and HA validation
- Lead and/or participate in special projects as required
All roles must demonstrate GBMC Values:
Respect
I will treat everyone with courtesy. I will foster a healing environment.
- Treats others with fairness, kindness, and respect for personal dignity and privacy
- Listens and responds appropriately to others’ needs, feelings, and capabilities
Excellence
I will strive for superior performance in every aspect of my work. I will recognize and celebrate the accomplishments of others.
- Meets and/or exceeds customer expectations
- Actively pursues learning and self-development
- Pays attention to detail; follows through
Accountability
I will be professional in the way I act, look and speak. I will take ownership to solve problems.
- Sets a positive, professional example for others
- Takes ownership of problems and does what is needed to solve them
- Appropriately plans and utilizes required resources for various job duties
- Reports to work regularly and on time
Teamwork
I will be engaged and collaborative. I will keep people informed.
- Works cooperatively and collaboratively with others for the success of the team
- Addresses and resolves conflict in a positive way
- Seeks out the ideas of others to reach the best solutions
- Acknowledges and celebrates the contribution of others
Ethical Behavior
I will always act with honesty and integrity. I will protect the patient.
- Demonstrates honesty, integrity and good judgment
- Respects the cultural, psychosocial, and spiritual needs of patients/families/coworkers
Results
I will set goals and measure outcomes that support organizational goals. I will give and accept help to achieve goals.
- Embraces change and improvement in the work environment
- Continuously seeks to improve the quality of products/services
- Displays flexibility in dealing with new situations or obstacles
- Achieves results on time by focusing on priorities and manages time efficiently
Pay Range
$79,517.04 - $143,130.67Final salary offer will be based on the candidate's qualifications, education, experience and alignment with our organizational needs.
Equal Employment Opportunity
GBMC HealthCare and its affiliates are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, mental or physical disability, genetic information, veteran status, or any other status protected by federal, state, or local law.
Skills Required
- Bachelor's degree in Computer Science or a related field
- Current high-level IT security or cybersecurity certification may substitute for a bachelor's degree
- Associate's degree plus a mid-level IT security or cybersecurity certification and two years of relevant experience may be considered
- Two to five years of experience as a system security engineer or building and maintaining comprehensive IT security systems
- Relevant experience in computer or information systems design/development, programming, information/cyber/network security, vulnerability analysis, penetration testing, computer forensics, information assurance, or systems engineering
- Experience with EPIC EMR
- Familiarity with vulnerability management, security monitoring and event management, and infrastructure patch management
- Experience using Tenable, KnowBe4, and Citrix NetScaler
- Familiarity with BIOMED device and patch management, Forcepoint web filtering, and mobile device management
- Proficiency with Active Directory and Microsoft Office 365 administration
- Familiarity with domain structures, user authentication, and digital signatures
- Understanding of FISMA policies and procedures, FIPS 199, FIPS 200, NIST, HIPAA, and other applicable policies
- Knowledge of network tools including ping, traceroute, and nslookup
- Knowledge of encryption methodologies
- Certification in EMR security, network security, cybersecurity, or digital forensics from EC-Council, CompTIA, or SANS
- Relevant industry cyber tool certifications
What We Do
GBMC HealthCare is a private, not-for-profit corporation that operates the Greater Baltimore Medical Center, a regional community hospital. They are committed to delivering high-quality medical care and services with the mission of leading patients to health, healing, and hope.









