Avatar for Summa Health
Summa Health
Actively Hiring
Integrated healthcare system providing patient-centered care

Cybersecurity Access Engineer II

Posted: 2 weeks ago• Recruiter recently active
Hires remotely in
Remote Work Policy

Remote only

Company Location
Akron
Visa Sponsorship

Not Available

RelocationAllowed
Skills
Backup and Recovery
SharePoint
Performance Tuning
Telemetry
Fault Tolerance
Monitoring
Directory Services
CompTIA Security+
MS Office Suite
Exception Handling
Reconciliation
Systems Testing
Conditional Access
SSCP
High Availability Design
Network Traffic Analysis
Identity Governance
SYSTEM VULNERABILITIES
Data Backup
Access Reviews
Least Privilege
Lifecycle Events
Integration Patterns
Log Ingestion
CCNA-Security
Application Vulnerabilities
Systems Engineering Process
Passwordless Authentication
Resilience Engineering
Separation of Duties
Phishing-Resistant MFA
Application Security Threats
User Authentication Methods
Automated Provisioning
Continuous Evaluation
Identity Platforms
Access Certification
Information Assurance Principles
System Security Threats
Identity Signals
Identity Attestation
Recovery Tools
Secure Configuration Management
Network Access Control Mechanisms
Strong Authentication
Rollout Strategies
Systems Management Tools
Patching Practices
Credential Lifecycle Management
Recovery Concepts
Escalation Design
Microsoft Technology Associate - Security Fundamentals
Modern Authentication Capabilities
Identity Proofing Concepts
Access Creep
Excessive Privilege
Orphaned Accounts
IAM Platform Operations
Connector-Based Provisioning
Attribute Mapping
Privileged Access Control Enforcement
Types of Backups
CompTIA Healthcare IT Tech
Identity Security Architecture Principles
Zero Trust Approaches
Entitlement Risk Concepts
Toxic Access Combinations
Upgrade Practices
Identity Governance and Administration (IGA) Integration Patterns
Policy Design Considerations
Host Access Control Mechanisms
Systems Evaluation Methods
Systems Management Principles
Systems Management Models
Systems Management Methods
Identity Automation Methods
Identity Automation Patterns
Automated Deprovisioning
Policy-Driven Access Enforcement
Identity-Related Logging
Authentication Events
Privileged Access Events
Access Decision Signals
Detection and Response Workflows
IAM-Specific Alerting
Detection Thresholds
Credential Events
Correlation with SIEM
Security Monitoring Workflows

About the job

Summa Health

Full-Time / Benefit Eligible

Remote Opportunity

Summa Health System is recognized as one of the region’s top employers by a number of third party organizations, including NorthCoast 99. Exceptional candidates gravitate to Summa because of its culture, passion for delivering excellent service to our patients and families commitment to our philosophy of servant leadership, collegial working relationships at every level of the organization and competitive pay and benefits.

Summary

Supports the implementation, operation, and maintenance of the organization’s identity and access management capabilities to ensure secure and reliable access to systems, services, and critical resources.

Supports the organization’s access security capabilities including Identity and Access Management platforms, integrations, and supporting controls. Working under the direction of senior engineers and architects, the Engineer installs, configures, tests, maintains, and troubleshoots IAM capabilities; integrates IAM services into the enterprise architecture and supported systems; supports automation of identity lifecycle and access provisioning/deprovisioning; and supports secure access patterns such as least privilege, strong authentication, and Conditional Access. Works in close partnership with peers and other subject matter experts across the organization to achieve desired outcomes.

Minimum Qualifications

  • Formal Education Required:
  • Bachelor’s Degree or equivalent in Computer Science, Cybersecurity, IT, or Engineering or equivalent combination of education and/or experience.
  • Experience & Training Required:
  • Three (3) years of IT related experience
  • Preferred experience in a healthcare environment with exposure to HIPAA, PCI DSS, or other relevant regulations.
  • Certifications required:
  • (CompTIA Security+ or CompTIA Healthcare IT Tech or SSCP or CCNA-Security or Microsoft Technology Associate - Security Fundamentals) (or equivalent)
  • Certifications preferred:
  • ITIL Foundation (or equivalent)

ii. ISC2 CCSP, SSCP (or equivalent)

iii. GIAC Certifications

iv. CompTIA CASP

  • Other Skills, Competencies and Qualifications:

Intermediate knowledge of information assurance (IA) principles and organizational requirements to protect confidentiality, integrity, availability, authenticity, and non-repudiation of information and data.

Intermediate knowledge of the systems engineering process; user authentication methods and factors; secure configuration management techniques.

Intermediate knowledge of directory services and identity platforms and how identity and access requests traverse enterprise systems (e.g., authentication flows, token/assertion use, authorization decision points, and access enforcement paths).

Intermediate knowledge of identity security architecture principles, including identity-centric and Zero Trust approaches (e.g., strong authentication, conditional access, least privilege, separation of duties, and continuous evaluation).

Intermediate knowledge of modern authentication capabilities and practices, including phishing-resistant MFA, passwordless authentication, credential lifecycle management, and identity proofing concepts.

Intermediate knowledge of identity governance and entitlement risk concepts, including access creep, excessive privilege, orphaned accounts, toxic access combinations, and the engineering controls that support access reviews, access certification, and identity attestation.

Intermediate knowledge of IAM platform operations and resilience engineering, including high availability design considerations, patching/upgrade practices, backup and recovery, and performance tuning for identity services and integrations.

Intermediate knowledge of identity governance and administration (IGA) integration patterns, including connector-based provisioning, attribute mapping, reconciliation, and troubleshooting for identity management platforms and source systems.

Intermediate knowledge of Conditional Access and privileged access control enforcement, including policy design considerations, rollout strategies, and exception handling.

Intermediate knowledge of host and network access control mechanisms; systems testing and evaluation methods; fault tolerance; system and application security threats and vulnerabilities; data backup, types of backups and recovery concepts and tools; systems management principles, models, methods and tools; and network traffic analysis methods as they relate to identity services and access pathways.

Intermediate knowledge of identity automation methods and patterns, including automated provisioning and deprovisioning workflows, integration patterns (e.g., APIs/connectors), and policy-driven access enforcement.

Intermediate knowledge of identity-related logging, monitoring, and telemetry (e.g., authentication events, privileged access events, lifecycle events, and access decision signals) and how to integrate identity signals into detection and response workflows.

Intermediate knowledge of IAM-specific alerting and escalation design, including detection thresholds for credential, lifecycle, and access events, and coordination of log ingestion and correlation with SIEM and security monitoring workflows.

Basic knowledge of risk management processes; incident response and handling methodologies; cyber defense policies, procedures, and regulations.

Basic knowledge of information technology (IT) supply chain security/risk management; laws, regulations, policies, and ethics as they relate to cybersecurity (e.g., Personally Identifiable Information (PII) and Personal Health Information (PHI)).

Intermediate analysis and critical thinking skills.

Intermediate interpersonal communication skill, both written and oral, with the ability to communicate effectively to technical and non-technical audiences.

Intermediate technical writing skill; MS Office suite of tools and SharePoint.

Ability to optimize identity and access management systems to meet organizational cybersecurity requirements.

Ability to think strategically and creatively to solve complex access security problems.

Ability to stay up to date on emerging identity-related threats and access security technologies.

Ability to communicate effectively with technical and non-technical audiences.

Ability to take direction and operate independently in moderately ambiguous situations.

Ability to effectively interact with populations of patients/customers with an understanding of their needs for self-respect and dignity.

  • Level of Physical Demands:
  • Sedentary: Exerts up to ten pounds of force occasionally and/or a negligible amount of force frequently.
  • Minimal, may occasionally move computer equipment (desktop, laptop, monitor, printer, and peripherals) when necessary.

Equal Opportunity Employer/Veterans/Disabled

$49.78/hr - $74.68/hr

About the company

Summa Health company logo

Summa Health

Actively Hiring
Integrated healthcare system providing patient-centered care5000+ Employees
Company Location
Akron
Company Size
5000+
Learn more about Summa Health image

Funding

AMOUNT RAISED
$1.5M
FUNDED OVER
1 round
Round
S
$1500000
Seed - Jan 2024