Description
Location: Chicago, Illinois
Business Unit: Rush Medical Center
Hospital: Rush University Medical Center
Department: Cybersecurity Engineering
Work Type: Full Time (Total FTE between 0.9 and 1.0)
Shift: Shift 1
Work Schedule: 8 Hr (8:00:00 AM - 4:00:00 PM)
Rush offers exceptional rewards and benefits learn more at our Rush benefits page (https://www.rush.edu/rush-careers/employee-benefits).
Pay Range: $46.07 - $68.64 per hour
Rush salaries are determined by many factors including, but not limited to, education, job-related experience and skills, as well as internal equity and industry specific market data.
The pay range for each role reflects Rush’s anticipated wage or salary reasonably expected to be offered for the position.
Offers may vary depending on the circumstances of each case.
Summary
Rush University Medical Center is seeking a SaaS Security Engineer to strengthen and mature our vulnerability and threat management program.
In this role, you'll identify and mitigate SaaS security risks, assess vulnerabilities across enterprise platforms, partner with application owners and technical teams, and help drive innovative cybersecurity strategies that protect critical systems and data.
If you're passionate about SaaS security, vulnerability management, identity-centric security, and leveraging emerging technologies—including AI—to improve security at scale, we'd love to hear from you
Responsibilities
Conduct continuous identification and assessment of SaaS exposures, to include misconfigurations, permission sprawl, insecure integrations, and identity centric risks across enterprise SaaS platforms.Analyze security findings and provider advisories to identify and prioritize corrective action(s) based on exposure, exploitability, and business criticality.Document and track SaaS security risks, remediation actions, and posture trends using automated risk registers, POA&Ms, and exception requests.
Generate and brief technical and executive level reports aligned to applicable regulatory and audit requirements.Develop, implement, and sustain security configuration baselines and hardening standards, mapped to organizationally mandated frameworks ( CIS, NIST CSF, etc.).Partner with SaaS application owners and identity, GRC, and enterprise teams to coordinate remediation of customer controlled SaaS risks.Plan and execute SaaS security posture assessments to measure connected application compliance and alignment across the SaaS portfolio.Participate in cross-functional risk and threat modeling activities and provide actionable recommendations for reduction or transference of risk.Develop, implement, and update vulnerability management policies, standards, and TTPs supporting SaaS vulnerability and exposure management processes.Utilize autonomous skills to leverage organizational Artificial Intelligence (AI) tools to effectively and efficiently assess exposure and risk at scale.Liaison with applications teams, business stakeholders, and vendor representatives to review security posture, remediation ownership, compensating controls, and contractual and regulatory compliance.Support and mature proactive cybersecurity strategies to include CTEM, SaaS Attack Surface Management, Identity Threat Detection and Response (ITDR), and zero trust access models.Maintain up-to-date knowledge of emerging threats, vulnerabilities, and cybersecurity best practices.Assist with cybersecurity tool evaluation and implementation, and operation.Participate in organizational and third-party training and workshops to enhance professional knowledge and team performance.
Required Job Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).Professional certification as Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+), GIAC Security Leadership Certification (GSLC), or equivalent.Minimum 5 years of experience in cybersecurity, with at least 3 years focused on vulnerability management, compliance validation, or threat analysis.Experience with multiple operating systems to include Windows, MacOS, Linux, Cisco iOS, etc.Hands-on experience with SSPM, CASB, IAM, or equivalent SaaS vulnerability management tools (e.g., Wiz, Microsoft Defender, Netskope, Entra ID, Okta).Familiarity with prompt engineering and leveraging of AI tools to automate manual processes and supplement data analysis.A strong understanding of networking, infrastructure, application, and information concepts and associated security principles.Experience in risk assessment and mitigation processes, practices, and strategies.Strong analytical, documentation, and communication skills.Ability to lead cybersecurity engineering projects and effectively communicate with business partners.Excellent interpersonal and communications skills, with the ability to work collaboratively in a team environment.Ability to work under pressure and effectively handle multiple responsibilities in a fast-paced and critical heath care environment.
Preferred Job Qualifications
Experience with business efficiency/intelligence tools (e.g., Power BI, Power Automate, Generative AI).Experience with industry cybersecurity frameworks (e.g., CIS, NIST, PCI DSS).Experience with Business Efficiency, Business Intelligence, or Generative AI products.Exposure to incident response and disaster recovery procedures.Exposure to virtualization and cloud platform security (e.g., Azure, AWS).Familiarity with DevSecOps practices and secure software development methodologies.
Rush is an equal opportunity employer.
We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.