Highmark Health Information Security Engineer in Camp Hill, Pennsylvania


The Information Security and Risk Management organization is seeking an Information Security Engineer. This person will support the IAM engineering security services, and in addition will be responsible for building and supporting security tools and automation processes for the IAM team. The ideal candidate should have previous experience in Web Application Security, computer programming (Java and VB) experience and experience with the following: Windows PowerShell, Perl, CGI, mod_perl, and Linux Shell Scripting.


This job works with others to plan, research, evaluate, design and develop Information Security and Risk Management (ISRM) systems by applying engineering, hardware and software design theories and principles to develop a compatible system infrastructure in line with organizational strategies. Assists with the design, development, and implementation of ISRM components such as operating systems, software tools, and utilities. Supports studies of ISRM Infrastructure performance and traffic analysis. Determines systems design requirements and ensures that system improvements are successfully implemented and monitored to increase efficiency. Assists with the development of ISRM Infrastructure engineering policies, standards and procedures. In addition the following:

  • Serve on or may lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.

  • Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.

  • Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.

  • Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.

  • Implement, monitor, configure, and maintain security systems.

  • Assure compliance to required standards, procedures, guidelines and processes.

  • Other duties as assigned or requested.


  • Bachelor’s Degree - Computer Science, Information Systems, or related field


  • 5 years' of information security engineering


  • 3 - 5 years' experience with information security and systems analysis

  • 3 - 5 years' with information security and/or information risk management and/or information technology

  • 3 - 5 years' with operating systems and software administration

  • 3 - 5 years' developing, communicating and presenting information security and risk management concepts to varying audiences

  • 3 - 5 years' with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms


  • Experience as an administrator for Identity Federation using SAML 2.0 is strongly preferred. This experience can be in various vendor federation products such as Microsoft ADFS, Oracle Access Manager, Ping Federation or other similar products

  • 5 - 7 years of experience in Web Application Security

  • Java and Visual Basic programming experience along with the following: Windows PowerShell, Perl, CGI, mod_perl, and Linux Shell Scripting experience

  • 5 - 7 years' experience with information security and systems analysis

  • 3 - 5 years' IT/information security risk advisory experience

  • 3 - 5 years' In-depth understanding of network security architecture, network and networking protocols

  • 3 - 5 years' database management, system administration and software development lifecycle

  • 1 - 3 years' experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework


  • Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3

  • Familiarity with secure SDLC best practices

  • Knowledge of Microsoft Apps and Suites, Windows Server, SharePoint, etc.

  • Strong teamwork and inter-personal skills


  • Certified Information Systems Security Professional (CISSP) - Center for Cyber Security Safety and Education, Security TRAVEL REQUIREMENT

0% - 25%

Referral Payout Level: 4


Equal Opportunity Employer Minorities/Women/ProtectedVeterans/Disabled/Sexual Orientation/Gender Identity