Gainwell Technologies is an innovative healthcare technology company dedicated to improving the health and well-being of vulnerable communities. As an Advisor Information Security Engineer, you will provide technical expertise and manage the delivery of Data Security services, including designing and implementing Database Activity Monitoring infrastructure and supporting incident response efforts.
Responsibilities:
- Design, implement, and administer Database Activity Monitoring (DAM) infrastructure
- Support Database Activity Monitoring software (e.g., agent) deployments, troubleshooting, and lifecycle management
- Provides incident support, including on-call, to investigations and/or Database Activity Monitoring related outages
- Performs Database Activity Monitoring software patching, upgrades, and vulnerability remediation
- Creates, tests, and tunes policy rules to align with industry and internal monitoring criteria including NIST, HIPAA, CCPA, etc
- Performs thorough product evaluations, recommends, and implements products/services for new or replacement data security technologies
- Develops, maintains, and reviews operating procedures, solution topology diagrams, and reporting metrics
- Performs regular service reporting including completed actions, upcoming activities, and recommendations to stakeholders
- Influences and contributes to the data security program development and roadmap planning
- Provides support and guidance to other security resources including business partners and suppliers
- Trains and educates staff to use software solutions safely and efficiently
Requirements:
- Two or more years of experience in database administration supporting relational database technologies such as Oracle, MS SQL, MySQL, PostgreSQL, IBM DB2, etc
- Experience with cloud hosted database Platform as a Service (PaaS) or Database as a Service (DBaaS) from AWS and/or Azure
- Three or more years of experience administering, managing, and tuning, IBM Guardium, Imperva, or equivalent solutions
- Experience working with networking concepts such as TCP/IP, firewalls, ACLs, and encryption
- Experience working with server operating systems such as Windows, Linux, etc
- Experience working with federal regulations related to information security (FISMA, HIPAA, CPRA, etc.)
- Experience working with NIST Special Publications or other industry frameworks
- Strong documentation, communication, and workflow design skills
- Possesses relevant vendor and industry security and technical certifications (CISSP, CCSP, etc.) is a plus
- Experience with Microsoft Purview or other Data Protection products is a plus