HCA Healthcare is hiring a Senior Network Security Engineer in Nashville, TN (onsite) to lead and improve enterprise network security controls and risk reduction initiatives.
Responsibilities
- Lead implementation, modernization, standardization, and enhancement of network security controls to protect a Fortune 100 enterprise infrastructure, patients, and data from evolving risk and threats.
- Perform and oversee reviews and assessments of security policies to identify risk, vulnerabilities, and hardening opportunities; provide remediation recommendations, designs, and solutions.
- Implement configuration changes supporting continuous security control maturity and ongoing risk reduction.
- Partner with other IT teams to apply risk management practices, optimize technology solutions, monitor infrastructure, and align with current and future needs.
- Ensure compliance with regulatory requirements and support long-term security posture and control maturity planning.
- Evaluate, recommend, and implement security measures including next-generation firewall capabilities, IDS/IPS, VPN, network segmentation and zero trust, and multifactor access control mechanisms.
- Conduct firewall rule reviews, security audits, baseline and best-practice compliance checks, and forensic network investigations to support data transmission adherence.
- Support and manage network security solutions aligned to regulatory and industry requirements such as PCI DSS, SOX, NIST, ISO 27000, and HIPAA.
- Assess vulnerability findings, penetration test results, security metrics, and audit outcomes to identify hardening needs and provide remediation recommendations.
- Recommend and implement complex solutions and enterprise-wide configuration changes to improve continuous security control maturity.
- Participate in incident response activities and disaster recovery planning and testing.
- Collaborate across IT teams to ensure network security controls integrate with other systems and applications and meet security standards.
- Routinely run audits and control tests on deployed technologies; collect and consolidate performance indicators, risks, and trends; provide recommendations and baseline/regulatory compliance ratings.
- Manage relationships with vendors and contractors to ensure timely delivery of security services in alignment with security policies.
- Contribute to development and documentation of security policies and procedures; support training and awareness efforts.
- Provide guidance and training to peers on compliance requirements and best practices.
- Research security design enhancements and identify automated solutions or best-of-breed technologies; support vendor integration tests.
- Stay current on threats, vulnerabilities, regulations, and industry best practices; implement recommendations to strengthen security posture and control maturity.
Requirements
- Bachelor’s degree preferred
- 5+ years of experience required
- Extensive experience with security technologies including next-generation firewalls, intrusion detection/prevention systems, VPN, network segmentation, access control mechanisms, and network security design, management, best practices, and policy standards in large 1000+ firewall environments
- Expertise with Checkpoint Firewall and related platforms: CMA, Provider-1, Maestro, VSX/VSLS, CloudGuard
- Cisco Network Security products and technologies such as Firepower, ASA, VPN, WSA, ISE, Stealthwatch
- Strong understanding of network protocols, topologies, tools, subnetting, and architectures
- Experience with network security policy management tools (Algosec, Tufin) and/or conducting risk assessments, firewall rule review, and security audits
- Strong knowledge of enterprise security technologies and processes including Zscaler, advanced threat detection tools, Antibot, antimalware, threat emulation, SIEM, IDS/IPS, network packet analysis, Netflow
- Experience designing solutions for security standards and frameworks including HIPAA, SOX, PCI DSS, HITECH, ISO/IEC 27001, and the NIST Cybersecurity Framework
- Network security management tools/technologies such as Splunk, Trustsec, segmentation, and syslog
- Excellent verbal and written communication, interpersonal, analytical, and problem-solving skills
- Demonstrated leadership and mentorship skills, including ability to guide and train junior engineers
- Ability to work independently and as part of a team
- Relevant certifications from ISC2 (CISSP), GIAC (GISP), ISACA (CISA), Cisco Security, or CompTIA are a plus
Technologies
- Next-generation firewalls
- Intrusion detection/prevention systems (IDS/IPS)
- VPN
- Network segmentation/zero trust
- Multifactor and access control mechanisms
- PCI DSS, SOX, NIST, ISO 27000, HIPAA
- Checkpoint Firewall, CMA, Provider-1, Maestro, VSX/VSLS, CloudGuard
- Cisco security technologies: Firepower, ASA, WSA, ISE, Stealthwatch
- Algosec, Tufin
- Zscaler
- Advanced Threat Detection Tools, Antibot, Antimalware, Threat Emulation
- SIEM
- Network Packet Analysis, Netflow
- HITECH, ISO/IEC 27001, NIST Cybersecurity Framework
- Splunk, Trustsec, segmentation, syslog
- Incident response and disaster recovery planning and testing
Benefits
- Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health, and telemedicine services
- Wellbeing support including free counseling and referral services
- Time away from work programs: paid time off, paid family leave, long- and short-term disability coverage, and leaves of absence
- 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support, and financial wellbeing counseling
- Education support including tuition assistance, student loan assistance, certification support, dependent scholarships, and a partnership with Galen College of Nursing
- Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection, and consumer discounts
Physical Demands / Working Conditions
- Minimal supervision required based on design, service, and support knowledge/skills
- May require periodic after-hours work and light travel at times with little notice
- Sitting for extended periods is required
Senior Network Security Engineer in nashville at Unknown Company
This position is listed as contract and onsite.