Summa Health
Full-Time / Benefit Eligible
Remote Opportunity
Summa Health System is recognized as one of the region’s top employers by a number of third party organizations, including NorthCoast 99. Exceptional candidates gravitate to Summa because of its culture, passion for delivering excellent service to our patients and families commitment to our philosophy of servant leadership, collegial working relationships at every level of the organization and competitive pay and benefits.
Summary :
Supports the implementation, operation, and maintenance of the organization’s identity and access management capabilities to ensure secure and reliable access to systems, services, and critical resources.
Supports the organization’s access security capabilities including Identity and Access Management platforms, integrations, and supporting controls. Working under the direction of senior engineers and architects, the Engineer installs, configures, tests, maintains, and troubleshoots IAM capabilities; integrates IAM services into the enterprise architecture and supported systems; supports automation of identity lifecycle and access provisioning/deprovisioning; and supports secure access patterns such as least privilege, strong authentication, and Conditional Access. Works in close partnership with peers and other subject matter experts across the organization to achieve desired outcomes.
Minimum Qualifications:
1. Formal Education Required :
a. Bachelor’s Degree or equivalent in Computer Science, Cybersecurity, IT, or Engineering or equivalent combination of education and/or experience.
2. Experience & Training Required:
a. Three (3) years of IT related experience
b. Preferred experience in a healthcare environment with exposure to HIPAA, PCI DSS, or other relevant regulations.
c. Certifications required:
i. (CompTIA Security+ or CompTIA Healthcare IT Tech or SSCP or CCNA-Security or Microsoft Technology Associate - Security Fundamentals) (or equivalent)
d. Certifications preferred:
i. ITIL Foundation (or equivalent)
ii. ISC2 CCSP, SSCP (or equivalent)
iii. GIAC Certifications
iv. CompTIA CASP
3. Other Skills, Competencies and Qualifications:
Intermediate knowledge of information assurance (IA) principles and organizational requirements to protect confidentiality, integrity, availability, authenticity, and non-repudiation of information and data.
Intermediate knowledge of the systems engineering process; user authentication methods and factors; secure configuration management techniques.
Intermediate knowledge of directory services and identity platforms and how identity and access requests traverse enterprise systems (e.g., authentication flows, token/assertion use, authorization decision points, and access enforcement paths).
Intermediate knowledge of identity security architecture principles, including identity-centric and Zero Trust approaches (e.g., strong authentication, conditional access, least privilege, separation of duties, and continuous evaluation).
Intermediate knowledge of modern authentication capabilities and practices, including phishing-resistant MFA, passwordless authentication, credential lifecycle management, and identity proofing concepts.
Intermediate knowledge of identity governance and entitlement risk concepts, including access creep, excessive privilege, orphaned accounts, toxic access combinations, and the engineering controls that support access reviews, access certification, and identity attestation.
Intermediate knowledge of IAM platform operations and resilience engineering, including high availability design considerations, patching/upgrade practices, backup and recovery, and performance tuning for identity services and integrations.
Intermediate knowledge of identity governance and administration (IGA) integration patterns, including connector-based provisioning, attribute mapping, reconciliation, and troubleshooting for identity management platforms and source systems.
Intermediate knowledge of Conditional Access and privileged access control enforcement, including policy design considerations, rollout strategies, and exception handling.
Intermediate knowledge of host and network access control mechanisms; systems testing and evaluation methods; fault tolerance; system and application security threats and vulnerabilities; data backup, types of backups and recovery concepts and tools; systems management principles, models, methods and tools; and network traffic analysis methods as they relate to identity services and access pathways.
Intermediate knowledge of identity automation methods and patterns, including automated provisioning and deprovisioning workflows, integration patterns (e.g., APIs/connectors), and policy-driven access enforcement.
Intermediate knowledge of identity-related logging, monitoring, and telemetry (e.g., authentication events, privileged access events, lifecycle events, and access decision signals) and how to integrate identity signals into detection and response workflows.
Intermediate knowledge of IAM-specific alerting and escalation design, including detection thresholds for credential, lifecycle, and access events, and coordination of log ingestion and correlation with SIEM and security monitoring workflows.
Basic knowledge of risk management processes; incident response and handling methodologies; cyber defense policies, procedures, and regulations.
Basic knowledge of information technology (IT) supply chain security/risk management; laws, regulations, policies, and ethics as they relate to cybersecurity (e.g., Personally Identifiable Information (PII) and Personal Health Information (PHI)).
Intermediate analysis and critical thinking skills.
Intermediate interpersonal communication skill, both written and oral, with the ability to communicate effectively to technical and non-technical audiences.
Intermediate technical writing skill; MS Office suite of tools and SharePoint.
Ability to optimize identity and access management systems to meet organizational cybersecurity requirements.
Ability to think strategically and creatively to solve complex access security problems.
Ability to stay up to date on emerging identity-related threats and access security technologies.
Ability to communicate effectively with technical and non-technical audiences.
Ability to take direction and operate independently in moderately ambiguous situations.
Ability to effectively interact with populations of patients/customers with an understanding of their needs for self-respect and dignity.
4. Level of Physical Demands:
a. Sedentary: Exerts up to ten pounds of force occasionally and/or a negligible amount of force frequently.
b. Minimal, may occasionally move computer equipment (desktop, laptop, monitor, printer, and peripherals) when necessary.
Equal Opportunity Employer/Veterans/Disabled
$49.78/hr - $74.68/hr