Upload Button Icon Add office photos
filter salaries All Filters

2 NextGen Healthcare Jobs

Nextgen Healthcare - Senior Security Engineer - GRC Tools (5-10 yrs)

5-10 years

Nextgen Healthcare - Senior Security Engineer - GRC Tools (5-10 yrs)

NextGen Healthcare

posted 1d ago

Job Description

Job Description

- Develop solutions using tools and technology to support GRC work, project, and initiatives.

- Act as system administrator for certain security or GRC tools such as phishing and training platform, Data Loss Prevention (DLP) solution, Third Party Risk Management (TPRM) platform, GRC tools, risk register, and repository for GRC artifacts.

- Integrate GRC related tools with other systems as needed.

- Engage with security vendors on design sessions, and help configure GRC solutions for use.

- Work with IT partners in Application Security, Security Engineering and Operations, Enterprise Applications, Desktop Support, Help Desk, Networking and Infrastructure Operations to get data and information needed to support GRC work.

- Work with GRC team and IT partners to extrapolate SIEM related data from source system logs such as security, application, system, and network logs to assess risks and help the GRC team determine compliance.

- Work with GRC team and IT partners to bridge technology between GRC goals and cybersecurity / technology solutions such as IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPD, XDR, MDM, SIEM, etc.

- Support GRC team data analysis and metrics by pulling data from source systems.

- Stay current with threat intelligence and make recommendation for GRC improvements.

- Participate in security incidents as needed.

- Support security assessment requests for customers, HITRUST, SOC 2, etc. by pulling appropriate data as needed.

- Work with IT partners to integrate GRC value-add into their secured software development life cycle, software engineering, infrastructure, network, and operation needs.

- Maximize the utilization of GRC and IT / Security tools and technology.

- Assist with the development of GRC policies and procedures.

- Stay current with changes in GRC, information security and cybersecurity regulations, industry frameworks, and best practices, and apply it to existing NextGen GRC solutions.

- Use security engineering skills to help streamline or automate NextGen methodology for maintaining accreditations or certifications (e.g., SOC 2, HITRUST, etc.).

- Use security engineering skills to help streamline or automate NextGen methodology for responding to customer security assessments or questionnaires.

- Perform other duties that support the overall objective of the position.

Education Required :

- Bachelor's Degree in Computer Science or related discipline or advanced degree.

- Or, any combination of education and experience which would provide the required qualifications for the position.

Experience Required:

- 4-6 years of relevant experience.

- Security engineering experience, including implementing information security or cybersecurity solutions.

- Experience in working with security technology, tools, or processes such as phishing campaigns, vulnerability scans, IRPs, playbooks, IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPD, XDR, MDM, SIEM, threat hunting, etc.

- Experience with one or more of the following frameworks: COSO, NIST CSF, RMF, ISO, COBIT.

- Experience working in an environment with one or more of the following: Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), Security Operation Center (SOC), Payment Card Industry (PCI), GRC

- Experience working with IT partners and adequate exposure to their areas such as SSDLC, software engineering, infrastructure, networking, service desk, desktop support, security operations, etc. This includes experience or sufficient exposure and familiarity with the tools they use.

License/Certification Required:

- Information security or cybersecurity related certifications such as CISA, CISSP, CISM, CRISC, CEH, GIAC (GCFA), or ability to acquire certification within 18 months.

- HITRUST Framework and CSF certification knowledge. Governance, Risk and Compliance tools.

Knowledge, Skills & Abilities:

- Knowledge of: GRC, information security, and cybersecurity principles, phishing campaigns, cybersecurity awareness and training, risk assessments, risk registers, security events and incidents, security frameworks, standards, guidelines, controls, federal and state security regulations and trends, current cybersecurity threats, data protection, administrative, technical and physical security controls, third party risk management (TPRM).


- IT / security processes or tools such as IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPD, XDR, MDM, SIEM, IRP, backups, DR & BCP, playbooks, MSP or MSSP, MDR or XDR, 24x7 SOC, endpoint security, SIEM, vulnerability scans, patching, pen testing, red/blue/purple teaming, tabletop exercises, encryption at rest and in transit, networking, firewalls, infrastructure, colo data centers, hosted environments such as Azure, AWS, or Google Cloud, and Active Directory.

- Skill in: Information security, cybersecurity, ethical hacking, some understanding of code and scripts, working as member of a team; communicating effectively; establishing and maintaining effective working relationships.

- Ability to: Determine how a system should work and how changes in conditions, operations, and the environment will affect outcomes; work in a fast-paced environment; stay organized, prioritize workload, multi-task, and meet deadlines.


Functional Areas: Software/Testing/Networking

Read full job description

Prepare for Senior Security Engineer roles with real interview advice

What people at NextGen Healthcare are saying

What NextGen Healthcare employees are saying about work life

based on 211 employees
80%
90%
82%
92%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

NextGen Healthcare Benefits

Submitted by Company
Better Health & Wellness
Better Learning
Better Life Balance
Submitted by Employees
Work From Home
Health Insurance
Free Food
Cafeteria
Team Outings
Job Training +6 more
View more benefits

Compare NextGen Healthcare with

Oracle Cerner

3.7
Compare

Veradigm

4.0
Compare

Athenahealth Technology

4.2
Compare

McKesson

4.5
Compare

Epic Systems Corporation (Wisconsin)

3.0
Compare

GE Healthcare

4.1
Compare

Siemens Healthineers

4.0
Compare

Optum

4.0
Compare

Merative

4.0
Compare

Thomson Reuters

4.1
Compare

R Systems International

3.4
Compare

Chetu

3.3
Compare

Onward Technologies Inc

3.1
Compare

Temenos

3.2
Compare

Globant

3.9
Compare

Ebix Software India

4.1
Compare

Duck Creek Technologies

4.4
Compare

Amadeus

4.0
Compare

UKG

3.1
Compare

FinThrive

3.8
Compare

Similar Jobs for you

Information Security Manager at Navi

5-8 Yrs

₹ 18-26 LPA

Security Engineer at Kiash Solutions LLp

7-15 Yrs

₹ 20-34 LPA

Cyber Security Consultant at AJ Consulting

4-8 Yrs

₹ 10-15 LPA

Information Security Engineer at HyrEzy Talent Solutions

10-15 Yrs

₹ 15-25 LPA

Security Architect at INFOCOM NETWORK PRIVATE LIMITED

5-8 Yrs

₹ 14-20 LPA

Security Analyst at MAI Labs

5-6 Yrs

₹ 12-16 LPA

Information Security Specialist at Cloudsufi

3-8 Yrs

₹ 11-22 LPA

Cyber Security Analyst at Applied Materials India Private Limited

7-9 Yrs

₹ 16-24 LPA

Information Security Engineer at Serving Skill

3-8 Yrs

₹ 10-20 LPA

Information Security Lead at Naukari Wale

4-7 Yrs

₹ 12-25 LPA

write
Share an Interview