We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Sr IT Security Engineer

American Medical Association
United States, Illinois, Chicago
330 North Wabash Avenue (Show on map)
Sep 24, 2026

Sr IT Security Engineer

Remote - Chicago IL, California, Florida, Illinois, Indiana, Maryland, Massachusetts, New Jersey, New York, Ohio, South Carolina, Virginia, Wisconsin, Washington D.C.

The American Medical Association (AMA) is the nation's largest professional Association of physicians and a non-profit organization. We are a unifying voice and powerful ally for America's physicians, the patients they care for, and the promise of a healthier nation. To be part of the AMA is to be part of our Mission to promote the art and science of medicine and the betterment of public health.

At AMA, our mission to improve the health of the nation starts with our people. We foster an inclusive, people-first culture where every employee is empowered to perform at their best. Together, we advance meaningful change in health care and the communities we serve.

We encourage and support professional development for our employees, and we are dedicated to social responsibility. We invite you to learn more about us and we look forward to getting to know you.

We have an opportunity for a remote Sr IT Security Engineer on our Infrastructure Ops team. As a Sr IT Security Engineer, you will be responsible for
security and cyber threat intelligence, industry best practices research, threat
detection/prevention, threat triage, and response. This role is responsible for
designing, implementing and maintaining security platforms and operational
solutions to secure cloud-based technology and on-premise applications. This
role is responsible for the day-to-day security technologies (e.g., firewalls, SIEM,
data loss prevention, web application firewalls, application security testing,
VPN etc.) and supporting processes. Collects and generates reports and metrics
for security trends and audit compliance purposes. Also designs security use cases based on
business requirements and lead security tool administration and configuration; works
closely with IT Engineering and Infrastructure teams to achieve security
objectives and goals.

RESPONSIBILITIES:


IT Security Policy

  • Research, design and advocate new technologies, architectures, and security products that will support security requirements for the enterprise and its customers, business partners, and vendors
  • Plan, document, and execute enterprise-wide security programs, including vulnerability identification and testing, network scanning framework for public and private networks and other technologies
  • Configure and troubleshoot vulnerability assessment tools and endpoint solutions; perform scans, and identify and research threats; summarize results and corrective actions where appropriate
  • Consult with IT, compliance, audit, and others to ensure development, implementation, and administration of applications and infrastructure meets standards for IT security and regulatory audit compliance
  • Communicate IT Security policies and procedures to management and end users across businesses
  • Collect and analyze defined metrics to report to leadership, including security dashboards and results of trainings
  • Develop and/or deliver information security awareness training, including phishing simulations and risk-based training content for high-risk users
  • Identify, collect, and organize credible, new intelligence and subject matter relative to current and emerging threats using all the tools, applications and open-source information
  • Define and document, application security standards for developers; ensure compliance with applicable security controls when writing such standards
  • Design, lead, and project manage the development and configuration of security tools and automation based on use cases.

Incident Detection and Response

  • Proactively monitor, analyze, block, and respond to malware and other emerging threats; serve as technical point of contact during and after security incidents including digital forensics procedures
  • Conduct operational threat hunting exercises to proactively find incidents in the AMA environment
  • Perform threat modeling and risk assessments using standard security frameworks for cloud services
  • Monitor and audit networks, on-premise and cloud systems and service changes
  • Document incident response procedures; support management communication during incidents
  • Assist in management of security services providers

Security Operations (including processes, monitoring, configuration, and maintenance)

  • Responsible for researching new threats, attacks, and risks to infrastructure and software
  • Define and document operating procedures for incident identification, investigation, and response
  • Work with businesses to identify and address data security risks in business processes
  • Analyze and make recommendations to enhance our security posture within cloud and hybrid environments and associated services and configurations
  • Improve security reporting, including coordinating vulnerability management, penetration testing, and infrastructure compliance
  • Create or update of detailed operational processes and procedures related to security operations, incident management & code development

May include other responsibilities as assigned


REQUIREMENTS:

  1. Bachelor's degree required in Information Security, Engineering, Computer Science, or related field
  2. Demonstrated progression towards one or more security of the following certifications; GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), CISSP/CISA certification, CISM
  3. 5+ years of Security Operations experience is required, including cyber incident investigations
  4. Strong understanding of various network and host-based security applications and host-based security applications and tools
  5. Exposure to enterprise web application programming and Application Security (AppSec).
  6. Knowledge of browser security controls, web application security frameworks, and authentication infrastructures (SAML, OAUTH), technical infrastructure, end points, networks, databases, and systems in relation to IT Security and IT Risk
  7. Understanding of cloud networking concepts and architecture to promote and develop new designs and security strategies across all types of cloud-based applications (including infrastructure, platform, and software as a service)
  8. Excellent written and verbal communication skills; able to communicate technical concepts to business leaders and users clearly, with appropriate emphasis on urgency and priority of potential threats and possible security incidents in progress
  9. Ability to respond to security incidents promptly and independently, addressing incidents under time pressure
  10. Excellent analytical, organizational and communication skills; demonstrated ability to facilitate cross-functional teams
  11. Experience in continuous improvements and agile methodology


The pay range for this position in Chicago IL,
California, Florida, Illinois, Indiana, Maryland, Massachusetts, New Jersey,
New York, Ohio, South Carolina, Virginia, Wisconsin, or Washington
D.C. is $115,523-$150,972.
This is the lowest to highest salary we in good faith believe we would pay for
this role at the time of this posting. An employee's pay within the salary
range will be based on numerous factors including, but not limited to, relevant
education, qualifications, experience, skills, geographical location and
business or organizational needs.

We are an equal opportunity employer, committed to diversity
in our workforce. All qualified applicants will receive consideration for
employment. As an EOE/AA employer, the American Medical Association will
not discriminate in its employment practices due to an applicant's race, color,
religion, sex, age, national origin, sexual orientation, gender identity and
veteran or disability status.

THE AMA IS COMMITTED TO IMPROVING
THE HEALTH OF THE NATION

Applied = 0

(web-9db6c7984-ddcg9)