What are the responsibilities and job description for the CYBER SECURITY SPECIALIST - ONSITE position at MT?
Our Mission
We Are Caring People Committed To Improving Community Health.
Expectations at MGRMC
- Excellence is about commitment. At MGRMC, we will:
- Make every patient and visitor's satisfaction a top priority.
- Go beyond the minimum required.
- Do all that is required to ensure a safe and secure environment within our hospital.
- Demand 100% effort from ourselves in everything we do while accepting nothing less from those we work with.
- Attitude - Our Attitude defines who we are. At MGRMC, we will:
- Recognize that our attitude is an expression to others of our character and integrity.
- Recognize that our attitude we carry as we approach our day to day tasks will inevitably drive our behavior.
- Have a pleasant attitude that underscores our principles of caring and compassion towards those we serve.
- Perform with an understanding that our organization, and each person who makes up our organization, will succeed as far as our attitude takes us.
- Compassion - A Compassionate gesture to a patient, a visitor or a fellow co-worker can be the difference between a positive or a negative experience. At MGRMC, we will:
- Approach our duties with a sense of Compassion.
- Show empathy to those who are struggling.
- Provide comfort when comfort is needed.
- Recognize that every person, whether patient, visitor or co-worker, deserves the same treatment that we would want for ourselves.
- Communication is the life blood of any organization. At MGRMC, we will:
- Strive to have full transparency, when possible, between Administration, Management and Staff.
- Expect everyone to take responsibility for receiving information that has been communicated.
- Provide clear, concise and timely information to our patients.
- Exhibit positive body language when communicating. We will listen with our eyes and our ears.
- Provide any instruction, feedback or criticism with tact.
- Professionalism is the standard by which every organization is judged. At MGRMC, we will:
- Be current in all educational aspects of our professions.
- Remain courteous at all times, especially in situations where discourteousness may seem the natural reaction.
- Exhibit the appearance, demeanor and grooming of one who belongs to a professional organization.
- Recognize the effect of our actions in front of non-staff members. What may be acceptable to an audience of co-workers, may not be acceptable to an audience of patients or visitors.
- Respect is a staple of any successful relationship. At MGRMC, we will:
- Recognize we are all one team in search of a common goal that will elude us if sought separately.
- Treat everyone (patients, visitors and co-workers) equally.
- Respect the privacy of others that we value for ourselves.
- Make time to praise and not just find time to criticize.
- Use hospital funds with prudence.
- Accountability - Holding people Accountable for their actions is the only way to guarantee our organization is living up to its Mission, Vision, and Value. At MGRMC, we will:
- Take responsibility and ownership for assignments that are given.
- Respect and established organizational chain of command.
- Be reliable in all our duties and expectations.
- Accept feedback and implement it.
- Always adhere to our 4A process for Service Recovery. (Anticipate, Acknowledge, Apologize and Amend)
- Expect to be held accountable to these Performance Standards.
Position Summary
Under the general supervision of the Director of Information Technology, the Information Security Specialist is responsible for developing and implementing security measures to protect sensitive data and ensure compliance with applicable regulatory requirements. This role manages cybersecurity systems, oversees security protocols, and responds to emerging threats. The specialist works closely with IT staff to ensure system integrity and user safety.
Required Qualifications
- Must be at least18 years of age.
- Proof of the highest level of education completed, but not less than associate’s degree in related field or equivalent years of experience
- Minimum 3–5 years of experience in cybersecurity or related IT field.
- Demonstrated experience with security tools such as Darktrace AI Threat Visualizer, CISCO Firepower Threat Defense Firewalls, antivirus systems, Security Operations Center, Endpoint Security, and SIEM platforms.
- Strong understanding of security frameworks, including HIPAA and NIST standards.
- Proficiency in scripting and automation tools (e.g., Python, PowerShell) and familiarity with Azure AD and Microsoft Office 365.
- Must have a well-groomed, professional appearance.
- Must have the mental and physical ability to perform, with or without reasonable accommodation, the essential functions of the job.
- Ability to lift, carry, pull, & push 50 pounds.
- Language proficiency in English, with excellent written and verbal fluency.
Preferred Qualifications
- Experience with network security protocols and tools, including IDS/IPS systems.
- Certifications such as Darktrace Threat Visualizer Essentials, CompTIA Network , CISSP, Security , or CISM are highly preferred.
- Hands-on experience with vulnerability assessment tools such as Tenable or Darktrace Proactive Exposure Management
- Familiarity with endpoint security solutions like CISCO Secure Endpoint and SOPHOS.
- Background in disaster recovery and business continuity planning
- Strong analytical and problem-solving abilities
Principle Clinical/Technical Duties
- Category: Cybersecurity Management
- Develop, implement, and enforce information security policies and procedures.
- Configure, monitor, and manage cybersecurity tools, including firewalls and Darktrace.
- Conduct regular security audits and vulnerability assessments.
- Lead incident response efforts and develop mitigation strategies.
- Oversee data governance initiatives to ensure the integrity, security, and proper handling of sensitive data.
- Develop and maintain hardened workstation and server images, ensuring adherence to industry standards and best practices for minimizing vulnerabilities.
- Category: System Administration
- Oversee security protocols for servers, workstations, and networks.
- Implement and maintain secure baseline configurations for all workstation and server images, regularly reviewing and updating settings to mitigate emerging threats.
- Ensure proper data backup and restoration procedures are in place and tested.
- Maintain antivirus protection and endpoint security for all network devices.
- Category: Training and Compliance
- Provide security awareness training for staff.
- Ensure compliance with HIPAA, PCI-DSS, and other regulatory requirements.
- Assist in creating documentation and reports for audits and compliance checks.
- Category: Collaboration and Support
- Work with IT staff to develop and implement secure system designs.
- Provide Level 2 and escalated support for security-related issues.
- Stay updated on the latest cybersecurity threats and industry trends.
- Category: Other Duties
- Participate in after-hours maintenance and emergency response as required
- Other duties as assigned
This is a general description of the kinds of duties and responsibilities that are performed by employees who have this title. It shall not be construed as an all-inclusive determination of the specific duties and responsibilities of any particular position. It is not intended in anyway to limit the right of any supervisor to assign, direct and control the work of employees under his/her supervision.
Working Conditions
- Normal working routine includes working in air-conditioned areas, with frequent interruptions, and ability to adapt to changing patient load frequently during the workday. Complies with on-call responsibilities. Interactions involve patients, family, and health care professionals.
Adherence to Policies & Procedures
- Consistently applies knowledge of policies/procedures in departmental performance. Recognizes and appropriately responds to deviations from departmental policy/procedure.
Age-Appropriate Interventions
- Demonstrates knowledge and appropriate measures with consideration of cognitive/physical/emotional/ biological maturation level, in meeting needs of population served, as it relates to age-appropriate intervention.
Safety
- Demonstrates knowledge of MGRMC safety policies/procedures contributes to a safe/secure work environment for everyone and initiates effective actions in response to potential and actual safety hazards.
Acknowledgement
I acknowledge that I have received and reviewed this job description and I understand the contents and will abide accordingly.
_________________________ ________________
Employee Signature Date