Skip to main content

Senior Information Security Engineer (Remote)

Job ID 348558 Date posted 12/16/2024 Job Expiration Date 12/20/2024
  • Rochester, MN
  • Full Time
  • Remote: Yes
Apply Now

Not ready to apply? Join our talent community


Overview

Be challenged to deliver innovative solutions that will change health care.

Mayo Clinic’s tech culture is rooted in passion for technology, embraces innovative thinking and strives for high performance. Our teams drive change in health care through comprehensive connected health and digital transformation strategies.

Some examples of our major initiatives are:

  • Utilizing artificial intelligence and machine learning principles to develop next generation patient centric care systems
  • Transforming the practice by applying data science techniques to discover new approaches to health care delivery
  • Leveraging Enterprise Architecture to construct integration centricity, promote data liquidity, and provide innovation support

This transformation creates, connects and applies integrated knowledge to deliver the best health care, health guidance and health information to patients, customers, partners, providers, employees anywhere and anytime so the needs of the patient come first.

Job Description

CityRochester

StateMN

RemoteYES

DepartmentInformation Security

Why Mayo Clinic

Mayo Clinic is top-ranked in more specialties than any other care provider according to U.S. News & World Report. As we work together to put the needs of the patient first, we are also dedicated to our employees, investing in competitive compensation and comprehensive benefit plans – to take care of you and your family, now and in the future. And with continuing education and advancement opportunities at every turn, you can build a long, successful career with Mayo Clinic. You’ll thrive in an environment that supports innovation, is committed to ending racism and supporting diversity, equity and inclusion, and provides the resources you need to succeed.

Benefits Highlights
  • Medical: Multiple plan options.
  • Dental: Delta Dental or reimbursement account for flexible coverage.
  • Vision: Affordable plan with national network.
  • Pre-Tax Savings: HSA and FSAs for eligible expenses.
  • Retirement: Competitive retirement package to secure your future.


Responsibilities

The senior information security engineer serves in a security researcher role and is a hands-on representative of the Mayo Clinic Office of Information Security (OIS) team.  While some automated tools will be leveraged, the role requires hands-on experience with a variety of tools to emulate attacker tactics, techniques, and procedures (TTPs).  A candidate must possess a solid understanding of information security, preferably with a strong computer science or engineering background and professional experience.  They must understand applications, networking, and various operating systems along with tools and frameworks.  Candidates must also maintain a high level of rigor to stay up to date with advancements in technology while also retaining knowledge of older systems and applications that may still be in use in the enterprise. 

A candidate for this position must be results oriented, multi-disciplined, and comfortable working with engineering staff, architecture staff, and management to discover vulnerabilities in existing services, infrastructure, and applications across the enterprise before our adversaries do. They also act as an information security liaison to various business units and the information technology department to recommend ways to address security concerns present in moderately complex Mayo Clinic services and systems.

The essential job duties for a senior information security engineer are:

  • Work with business partners within the department to achieve organizational and OIS goals
  • Apply technical expertise in penetration testing, vulnerability research, red teaming, code auditing, and reverse engineering to perform in-depth security assessments of IT infrastructure (on-prem and cloud), medical devices, and various types of software (including web and mobile applications)
  • Identify, understand, and explain the root cause of technical security vulnerabilities and clearly report steps to reproduce a vulnerability
  • Develop and recommend technical strategies to mitigate or remediate identified vulnerabilities to asset owners
  • Regularly research and learn new TTPs in public and closed forums, and work with teammates to assess risk and implement and validate controls as necessary
  • Develop and maintain tools and scripts used in penetration-testing and red team processes
  • Support purple team exercises designed to build strength across the cybersecurity operations center, threat hunting, and red team
  • Train offensive and defensive colleagues on new TTPs and mentor junior teammates
  • Occasionally attend and participate in risk assessment or policy discussion meetings
  • Undertake complex projects requiring specialized technical knowledge
  • Perform other security-related duties or enhancements as assigned
  • Establish timelines and delivery of requirements.

This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.



Qualifications

The Senior Information Security Engineer requires the following skills and abilities:

  • Strong written and verbal skills
  • Professional, focused, penetration testing experience
  • Good understanding of at least three operating systems (Microsoft Windows, GNU/Linux, Android, macOS, or iOS)
  • Advanced experience with security tools, including Metasploit Framework, Burp Suite, Frida, Wireshark, and Responder
  • Provide security recommendations about cryptographic implementations
  • Understands system-level concepts
  • Understands OWASP, NIST CVSS, and the software development lifecycle (SDLC).
  • Experience in at least one programming language (Rust, Go, Java, .NET, C or C++) or one scripting language (Python, PHP, Ruby)
  • Experience in testing at least one of the following:
    • cloud infrastructures (AWS, GCP)
    • mobile applications (iOS and Android)
  • Have an astute attention to detail
  • Highly organized and efficient
  • Demonstrates a deep and broad knowledge of standard operating procedures, workflows and supporting technology across numerous critical user areas and an in-depth knowledge of multiple computing technologies either being actively used or of significant interest to Mayo; understands how systems fit into larger picture of technology at Mayo
  • Capacity to work remotely, independently, and be willing to seek advice/assistance

Good to have:

  • Experience in secure systems architecture designs
  • Experience in reverse engineering (x86, x64, ARM32, ARM64 architectures), and familiarity with relevant tools (IDA Pro or Ghidra)
  • Experience with hardware security testing

Minimum Education and/or Experience Required:

Master’s degree with one (3) years of experience or bachelor’s degree in computer science, Information Systems, Engineering or related major and a minimum two (5) years’ experience in the information security field required.

Licensure/Certification Required: Must have one of the following certifications (or equivalent) at time of hire. In lieu of certification at time of hire, candidate must pass the exam within two years and complete the certification process once years of service requirements of the certifying body have been met.

  • OSCP – Preferred certification
  • CISSP
  • GIAC Certification (GPEN preferred)



Exemption Status

Exempt

Compensation Detail

$128,502.40 - $186,164.00 / year.

Benefits Eligible

Yes

Schedule

Full Time

Hours/Pay Period

80

Schedule Details

Core hours are Monday through Friday 8am to 4pm candidates local time with occasional time outside required outside core hours as needed.

Weekend Schedule

Not normal, but may be required if a test or schedule needs it. Again, this is not normal.

International Assignment

No

Site Description

Just as our reputation has spread beyond our Minnesota roots, so have our locations. Today, our employees are located at our three major campuses in Phoenix/Scottsdale, Arizona, Jacksonville, Florida, Rochester, Minnesota, and at Mayo Clinic Health System campuses throughout Midwestern communities, and at our international locations. Each Mayo Clinic location is a special place where our employees thrive in both their work and personal lives. Learn more about what each unique Mayo Clinic campus has to offer, and where your best fit is.

Affirmative Action and Equal Opportunity Employer

As an Affirmative Action and Equal Opportunity Employer Mayo Clinic is committed to creating an inclusive environment that values the diversity of its employees and does not discriminate against any employee or candidate. Women, minorities, veterans, people from the LGBTQ communities and people with disabilities are strongly encouraged to apply to join our teams. Reasonable accommodations to access job openings or to apply for a job are available.


Recruiter

Joy Kundrata
Apply Now

Career Path

Discover unlimited opportunities. Your IT career may start as a Help Desk Specialist or Work Station Technician, an intern, or entry-level Analyst/Programmer and develop into a mid- or senior-level technical position. You may choose to grow laterally as a technical expert, learning and supporting many different aspects of IT services. Or you may choose to become part of the leadership team.

  • Applications
  • Business Relationship Management
  • Enterprise Infrastructure
  • Enterprise Architecture
  • Information
    Security
  • Management
  • Project Management and Systems Analysis
  • Quality
    Assurance

The Life Changers

  • When you choose an IT career with Mayo Clinic you will have an opportunity to engage with new and innovative solutions which will improve quality of life and patient outcomes. You will partner with brilliant Physicians and Scientists to help drive translational medicine in a fast-paced environment where creativity, energy, and dedication will result in success.”

    Marie Koctecki
    Senior Manager, IT Service Delivery
  • Over the span of my career, I have worked in multiple divisions across IT and have now advanced to a Service Delivery Manager role, managing a Project Management Office (PMO). The opportunities within the department of IT are vast. I have been able to gain my Project Management Professional (PMP) certification as well as my Certified Scrum Master (CSM) certification while at Mayo Clinic.”

    Betty Hutchins
    Manager, IT Service Delivery
  • I appreciate the breadth of career paths within IT and the ability to branch out and diversify my professional expertise while remaining with Mayo Clinic. The diverse backgrounds and depth of expertise of my coworkers is an attribute of Mayo’s unique culture; I enjoy the opportunity to work with so many world-renowned experts and thought leaders across a wide array of professions.”

    Samanthie Epps
    Manager, IT Speciality Systems

Join our talent community.

Join our global talent community to receive alerts when new life-changing opportunities become available.

News

  • Image of Lab

    Mayo Clinic Laboratories uses enhanced technology to safeguard patient specimens

    To improve specimen safety and tracking, Mayo Clinic Laboratories is using an enhanced form of radio-frequency...

  • Virtual Reality

    Mayo Clinic and vMocion Introduce Technology which Creates the Sensation of Motion, Transforming Vir

    Mayo Clinic and vMocion, LLC, an entertainment technology company, today announced it is making...

Jobs for you

You have no Recently Viewed Jobs. View all available opportunities.

Join Our Talent Community

Sign up, stay connected and get opportunities that match your skills sent right to your inbox

(Must be under 1MB)

Interested InSelect a job category from the list of options. Select a location from the list of options. Finally, click “Add” to create your job alert.

  • Information Technology, RemoteRemove
  • Information Technology, Rochester, Minnesota, United StatesRemove

Equal opportunity

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, protected veteran status, or disability status. Learn more about "EEO is the Law." Mayo Clinic participates in E-Verify and may provide the Social Security Administration and, if necessary, the Department of Homeland Security with information from each new employee's Form I-9 to confirm work authorization.

Reasonable accommodations

Mayo Clinic provides reasonable accommodations to individuals with disabilities to increase opportunities and eliminate barriers to employment.  If you need a reasonable accommodation in the application process; to access job postings, to apply for a job, for a job interview, for pre-employment testing, or with the onboarding process, please contact HR Connect at 507-266-0440 or  888-266-0440.

Job offers

Job offers are contingent upon successful completion of a post offer placement assessment including a urine drug screen, immunization review and tuberculin (TB) skin testing, if applicable.

Recruitment Fraud

Learn more about recruitment fraud and job scams

Advertising

Mayo Clinic is a not-for-profit organization and proceeds from Web advertising help support our mission. Mayo Clinic does not endorse any of the third party products and services advertised.

Advertising and sponsorship policy | Advertising and sponsorship opportunities

Reprint permissions

A single copy of these materials may be reprinted for noncommercial personal use only. "Mayo," "Mayo Clinic," "MayoClinic.org," "Mayo Clinic Healthy Living," and the triple-shield Mayo Clinic logo are trademarks of Mayo Foundation for Medical Education and Research.

Any use of this site constitutes your agreement to the Terms and Conditions and Privacy Policy linked below.

Terms and Conditions | Privacy Policy | Notice of Privacy Practices | Notice of Nondiscrimination

© 1998-2024 Mayo Foundation for Medical Education and Research (MFMER). All rights reserved.

Top