Security Engineer - Mmis

25 Mar 2024

Vacancy expired!

Location: Quincy, MA Description: Title: Security Engineer - MMIS Location: Quincy, MA

Job Description:

Detailed list of Duties and Responsibilities:
  • Lead efforts to develop and implement a robust MMIS security posture especially as client migrates MMIS to the AWS cloud datacenter.
  • Lead efforts to develop and implement a holistic strategy to identify, remediate infrastructure, application code and accessibility vulnerabilities and institute an operational process regularly monitor, track and report on progress.
  • Serve as MMIS Security Lead with client and EOTSS enterprise security organizations to develop and implement achievable vulnerability remediation policies based on objective industry standard, measures of risk impact, and probability.
  • Participate in efforts to integrate Static Application Security, Dynamic Application Security and Software Composition Analysis Tools (SAST, DAST & SCA) into MMIS Software Development Lifecycle (SDLC) emphasizing "Shift Left" early detection and remediation of potential threats and vulnerabilities, and automation, and process integration.
  • Participate in efforts to develop and implement security standards, secure common frameworks and developer documentation and educational materials; create and update learning resources for application security.
  • Participate in efforts to present and explain threat modelling, risks and risk mitigation strategies to business and IT stakeholders (including leadership) and effectively defend recommendations, where necessary.
  • Participate in efforts to define MMIS technical security hosting and software environments requirements.

Qualifications:
  • 3+ years of experience working in application and infrastructure security roles.
  • Strong technical knowledge of internet security issues, cloud architectures, and threat landscape.
  • Strong technical understanding of application and cloud security threats and vulnerabilities, including OWASP top 10, SANS top 25 etc.
  • Extensive knowledge of and experience with security standards such as NIST, FEDRamp, and ISO 27xxx.
  • Solid understanding of AWS networking and security tools and resources.
  • Strong technical knowledge of AWS security and network management tools and resources.
  • Strong background in web application development and/or code auditing.
  • Strong consensus building and interpersonal communications skills
  • Strong analytical abilities.
  • Strong writing and technical documentation skills.

Preferred Knowledge, Skills, and Abilities:
  • Extensive hands-on experience with implementing best security practices for AWS cloud
  • Extensive hands-on experience with implementing best security practices for AWS cloud hosted applications including the appropriate utilization of AWS security and networking tools and resources.
  • Experience with DevOps practices and Continuous Integration/Continuous Development (CI/CD) using GitLab and pipelines.
  • Experience with web and API development technologies.
  • Knowledge of current development practices, including containerized applications, microservice architectures, serverless architectures, etc.
  • Experience with Medicaid systems or in IT healthcare settings desired

Education and Certifications:
  • Bachelor's Degree in Computer Science, Information Systems/Technology, Business Administration, or other related field, or equivalent work experience.
  • Professional or related field, or equivalent work experience.
  • Professional security certification: CISSP, GIAC, GWEB, GWAP or other similar credentials a plus

Contact:

This job and many more are available through The Judge Group. Find us on the web at

  • ID: #49542849
  • State: Massachusetts Quincy 02169 Quincy USA
  • City: Quincy
  • Salary: USD TBD TBD
  • Job type: Permanent
  • Showed: 2023-03-25
  • Deadline: 2023-05-23
  • Category: Security