Live opening · Posted 5 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Engagement Overview
EMS|MC is seeking an experienced independent contractor to provide information security engineering services within the EMS|MC corporate environment. The engagement will focus on security engineering, monitoring and analysis, incident response support, threat intelligence, security administration, compliance and risk management, and security awareness activities in accordance with agreed-upon deliverables.
Scope of Services
Providing design analysis and recommendations for new and existing security tools and solutions.
Evaluating, deploying, configuring, administering, and troubleshooting security solutions, and preparing related technical procedures and documentation.
Ensuring appropriate security logging and reporting are enabled and configured and monitoring security tools and alerts for indicators of threats or unauthorized activity.
Performing triage and analysis of security events and investigating identified vulnerabilities, including supporting patch-management verification and remediation efforts.
Addressing assigned security portal matters in accordance with applicable service level agreements (SLAs), including documenting resolution or escalation as appropriate.
Reviewing vulnerability-management data and providing remediation recommendations to designated system owners in accordance with applicable policy SLAs.
Documenting security incident findings and response steps and supporting incident detection, containment, and remediation in accordance with established protocols.
Identifying opportunities to automate security processes where appropriate.
Monitoring current threat trends and vulnerabilities, gathering and analyzing threat intelligence, and recommending or implementing approved proactive defense measures.
Administering or supporting endpoint protection, firewalls, and other security systems in accordance with applicable change-management requirements.
Reviewing and supporting agreed-upon access-control configurations, including access control lists, user permissions, and role-based access.
Consulting with designated IT resources to support effective security controls aligned with applicable policies and regulatory requirements.
Supporting security audits, compliance activities, and control assessments related to HIPAA, PCI DSS, SOC 1, SOC 2, and other applicable requirements or frameworks.
Reviewing security logs and reports, verifying security controls, and reporting identified abnormalities or improper access to designated EMS|MC stakeholders.
Supporting security awareness activities, including security awareness training and periodic security testing such as phishing simulations.
Supporting the maintenance, review, and application of IT security policies and procedures for agreed-upon initiatives.
Expected Deliverables
Security tool design assessments, recommendations, configurations, and implementation documentation for agreed-upon initiatives.
Operational security monitoring, event triage, vulnerability analysis, and documented resolution or escalation of applicable security matters.
Incident-response documentation capturing findings, response actions, and remediation steps for applicable security events.
Vulnerability-management reviews and documented remediation recommendations or verification results aligned with applicable policy SLAs.
Threat-intelligence analyses and approved proactive defense measures addressing identified threats and vulnerabilities.
Security administration outputs for agreed-upon endpoint protection, firewall, access-control, and related security systems.
Audit and compliance support materials, including requested logs, reports, control evidence, and documentation for applicable HIPAA, PCI DSS, SOC 1, and SOC 2 activities.
Security awareness and testing support, including agreed-upon phishing simulations or other security testing activities.
Current technical procedures and other documentation for security tools, troubleshooting, controls, and agreed-upon security processes.
Automation or process-improvement solutions, where agreed upon, that improve the efficiency or reliability of security operations.
Contractor Qualifications
Demonstrated professional experience in Information Technology, Cybersecurity or a similar discipline, including six or more (6+) years of hands-on experience with information, data, system and application security.
Strong knowledge of cybersecurity principles, common threat vectors, security controls, and defense strategies.
Hands-on experience with security monitoring, vulnerability management, incident response, endpoint or network security, and related security technologies.
Experience with network and host security policy management and monitoring, including firewalls, web application firewalls (WAF), and group policies.
Working knowledge of risk-management practices, cybersecurity frameworks, security controls, and industry best practices.
Demonstrated ability to independently manage priorities, exercise sound judgment, and complete security projects and agreed-upon deliverables within established timelines.
Strong analytical and problem-solving skills with attention to detail and the ability to investigate and resolve complex security matters.
Strong written and verbal communication skills, with the ability to collaborate effectively with technical and non-technical stakeholders.
Additional Experience Preferred
Relevant information security certifications, such as Security+, GSEC, SSCP, CASP+, CISSP, or comparable credentials.
Experience with Microsoft 365, Entra ID, Active Directory, Windows and Linux operating systems, networking and system logs, and scripting or programming languages such as Bash, PowerShell, or Python.
Experience designing secure networks, systems, or application architectures.
Understanding of the HIPAA Security Rule, HITECH Act, PCI DSS, and general data privacy principles.
Experience identifying and implementing security process improvements or automation opportunities.
Engagement Details
Services will be performed pursuant to a written Independent Contractor Agreement and applicable Statement(s) of Work.
Deliverables, priorities, timelines, and other engagement-specific terms will be established by mutual agreement before the applicable services begin.
Initial Term: The initial engagement is anticipated to continue for up to twelve (12) months. Prior to the conclusion of the initial term, EMS|MC and the contractor may mutually evaluate whether to extend the independent contractor engagement or pursue an employment opportunity, if there is mutual interest.• Any employment relationship would be subject to a separate offer of employment, successful completion of the Company's hiring process, and execution of all required employment documentation. Nothing in this posting or any resulting agreement guarantees future employment, continued engagement, or an extension of the initial term.
Independent Contractor Engagement
This opportunity is for the provision of professional services by an independent contractor. Nothing in this posting or any resulting agreement is intended to create an employer-employee relationship.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.