HCA HealthcareActive opening

Enterprise Security Engineer

Nashville, TN, USIndividual contributorFound 2 days ago
Apply to this job

Free credits included. Sign up to start applying with Jobfinder.

cybersecurityautomationnetworkingnistrisk-assessment

Are you passionate about the patient experience? At HCA Healthcare, we are committed to caring for patients with purpose and integrity. We care like family! Jump-start your career as an Enterprise Security Engineer today with HCA Healthcare.

Job Summary and Qualifications

The Enterprise Security Engineer I will support the analysis of applications, network, and security architectures for the enterprise to help ensure the security, integrity, and regulatory compliance of critical information transmitted over the network or in storage. This position will report to the Threat Informed Engineering Team Manager and, with guidance from more senior team members, will help ensure security requirements are addressed in enterprise architecture, solution designs, and systems that protect and support organizational mission and business processes.

The ideal candidate will have foundational cybersecurity knowledge with practical software development and/or automation skills and be interested in using engineering approaches to solve security problems at enterprise scale. This role will serve as a developing information security advisor to the business and the ITG (Information Technology Group), supporting balanced cyber risk management and the secure development and deployment of technology solutions. The position will apply established security standards and patterns, participate in security reviews, document risks and recommendations, and assist with the evaluation, design, build, and implementation of information security technologies and processes.

  • Security Posture Review: Assist with security posture reviews of applications, networks, and environments; gather relevant information, identify common security concerns, document findings, and track remediation activities with guidance from senior team members.
  • Solution and Process Engineering: Work with senior team members to develop solutions and processes to expand and automate HCA’s security review capabilities at scale.
  • Compliance: Apply HCA and NIST security standards and relevant regulatory requirements to assigned work, maintain current knowledge of applicable requirements, and escalate questions or exceptions when guidance is needed.
  • Documentation: Produce clear and accurate documentation for security assessments, assigned projects, decisions, and recommendations so that technical and non-technical stakeholders can understand required actions.
  • Collaboration: Work collaboratively with Information Security, ITG, business teams, and vendors to support the integration of appropriate security requirements and controls.
  • Training and Development: Continuously build knowledge and skills in information security, participate in team knowledge-sharing, seek feedback and mentorship, and apply new learning to assigned responsibilities.
  • Operational Execution: Plan, track, and complete assigned security tasks and workstreams on time, manage day-to-day priorities, maintain organized records, and promptly escalate blockers or material risks.
  • Research and Improvement: Research security technologies, patterns, and practices; summarize findings; and contribute ideas and recommendations that may improve HCA's security posture while supporting business objectives.
  • Ethical Standards: Maintain and promote high ethical standards in all security-related activities, protecting the integrity and trustworthiness of the Information Security department.
  • Communication: Communicate security risks, requirements, standards, and practices clearly to security and non-security personnel, and seek assistance when issues exceed the scope of assigned responsibility.
  • Performance Metrics: Maintain accurate records and metrics for security design reviews, architecture review activities, remediation tracking, and compliance efforts, and contribute to team reporting and continuous improvement.
  • Assist HCA business units with Information Security Agreements by reviewing required security information, documenting gaps, and escalating exceptions or complex issues for additional review.
  • Translate established security standards and protocols into clear, actionable requirements for non-security personnel with guidance from senior security teammates as needed.
  • Participate in peer reviews and team knowledge-sharing activities, incorporate feedback, and contribute to a collaborative learning environment.

What qualifications you will need:

  • Bachelor's Degree preferred
  • One year or less relevant work experience

Other Special Qualifications

  • Relevant experience in information security, software development, systems engineering, cloud engineering, DevOps, or a related technical discipline in an enterprise or similarly complex technical environment is preferred.
  • Foundational knowledge of information security principles, standards, practices, and technologies.
  • Foundational understanding of risk assessment, risk management, security controls, and risk reduction concepts.
  • Working knowledge of modern scripting, automation and/or software development techniques and principles.
  • Working knowledge of using AI tools to assist with solving complex problems, including the use and/or development of agentic AI tools.
  • Strong analytical, critical-thinking, problem-solving, and decision-making skills appropriate for an entry-level engineering role.
  • Basic understanding of secure design, availability, resiliency, and high-availability concepts.
  • Familiarity with industry and regulatory requirements such as HIPAA, PCI, SOX, and GDPR is a plus.
  • Ability to organize assigned work, meet deadlines, maintain attention to detail, and manage competing priorities with appropriate guidance.
  • Familiarity with identity and access management concepts and technologies such as AD, Azure Entra ID, GCS, and AWS is a plus.
  • Working knowledge of one or more Information Security domains such as Identity and Access Management, Endpoint, Network, Mobile, Cloud, and/or Application Security.
  • Familiarity with IT security and operational processes and how security controls are applied within those processes.
  • Basic understanding of information security threats, vulnerability detection, risk assessment, remediation, and risk reduction procedures.
  • Professional written and verbal communication skills and the ability to work constructively through differing viewpoints or priorities.
  • Comfortable working independently on well-defined tasks and collaboratively in a diverse team environment; able to recognize when escalation or additional guidance is needed.
  • Experience working in a healthcare environment or securing clinical applications and information is a plus.
  • Demonstrated commitment to continuous learning and the ability to incorporate technical feedback into future work.
  • An entry-level security certification such as CompTIA Security+, ISC2 Certified in Cybersecurity (CC), SSCP, GSEC, or equivalent is a plus.
  • Experience and/or Technical Training may be substituted for education.
Benefits

HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:

  • Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
  • Wellbeing support, including free counseling and referral services
  • Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
  • Savings and retirement resources, including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
  • Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
  • Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts

Learn more about Employee Benefits

Note: Eligibility for benefits may vary by location.

HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.

"The great hospitals will always put the patient and the patient's family first, and the really great institutions will provide care with warmth, compassion, and dignity for the individual."- Dr. Thomas Frist, Sr.

HCA Healthcare Co-Founder

If you are looking for an opportunity that provides satisfaction and personal growth, we encourage you to apply for our Enterprise Security Engineer opening. We promptly review all applications. Highly qualified candidates will be contacted for interviews. Unlock the possibilities and apply today!

We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

HCA HealthcareEnterprise Security Engineer
Apply to this job