Security Risk Engineer
Remote - Minnesota, United States
Full Time Mid-level / Intermediate USD 106K - 129K
Solventum
Solventum is a healthcare company built from a legacy of innovation and dedicated to enabling better, smarter, safer healthcare to improve lives. Learn more.Job Description:
Security Risk Engineer (Solventum)
3M Health Care is now Solventum
At Solventum, we enable better, smarter, safer healthcare to improve lives. As a new company with a long legacy of creating breakthrough solutions for our customers’ toughest challenges, we pioneer game-changing innovations at the intersection of health, material and data science that change patients' lives for the better while enabling healthcare professionals to perform at their best. Because people, and their wellbeing, are at the heart of every scientific advancement we pursue.
We partner closely with the brightest minds in healthcare to ensure that every solution we create melds the latest technology with compassion and empathy. Because at Solventum, we never stop solving for you.
The Impact You’ll Make in this Role
The Cybersecurity Risk Engineer will play a key role in securing Solventum’s digital products and information technology (IT) infrastructure, ensuring resilience against cyber threats, and enhancing our overall security posture. Working closely with both engineering and IT teams, this role will focus on risk assessment, controls assessment, and risk management, while also automating security tools and processes.
In this role, the Cybersecurity Risk Engineer will undertake a variety of key responsibilities. They will conduct regular risk assessments, audits, and vulnerability analyses on IT assets, networks, and processes. By developing and maintaining a risk-based approach, they will work to protect IT assets by mitigating identified threats and vulnerabilities. This position involves analyzing and tracking cybersecurity risks to ensure they are documented and managed effectively.
Automation of security tools and processes to improve efficiency and effectiveness is another critical aspect of the role. The engineer will use technical skills to implement reporting and evidence collection for security tools like Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) as needed.
The Cybersecurity Risk Engineer will review security controls for software and products to ensure they meet required standards and will develop and maintain a controls heat map to visualize the effectiveness and coverage of security controls across the organization. They will support the Authority to Operate (ATO) program, ensuring that risk management and control validation processes are followed. By contributing "leading practices" in terms of findings, checklists, templates, testing methods, and techniques, the engineer will support and advance the internal Security Assessment program.
The engineer will develop and maintain documentation of security processes, policies, and controls, enabling a transparent audit trail and compliance verification. They will affirm and advance various stakeholders' understanding of, and their responsibilities with respect to, the Security Frameworks and regulatory compliance.
Collaboration is a key component of this role. The engineer will act as a liaison between engineering, IT, and security teams to ensure alignment on cybersecurity initiatives. They will stay current with cybersecurity trends and best practices. Building an extensive network of positive relationships throughout Solventum and its technology organizations will be crucial to accomplish the broad requirements of this position.
Your Skills and Expertise:
To set you up for success in this role from day one, Solventum requires (at a minimum unless otherwise specified) the following qualifications:
- High School Diploma/GED AND 3+ years in software development or automation
AND
- Technical Knowledge: knowledge of cybersecurity principles, including network segmentation, firewall management, and IT systems.
Additional qualifications that could help you succeed even further in this role include:
- Programming Skills: Proficiency in Python or common scripting languages, and experience working with APIs.
- Standards & Regulations (Nice to Have): Familiarity with industry regulations and standards like NIST CSF, NIST 800-53, and other IT security frameworks.
- Soft Skills: Excellent communication skills, project management experience, and the ability to work effectively with cross-functional teams.
- Problem-Solving: Proven ability to identify security challenges and develop practical solutions in complex IT environments.
- Independence: Ability to work independently, with limited required direction and guidance.
Work location: Remote.
- Travel: May include up to [20% domestic]
- Relocation Assistance: May be authorized
Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).
Supporting Your Well-being. Solventum offers many programs to help you live your best life – both physically and financially. To ensure competitive pay and benefits, Solventum regularly benchmarks with other companies that are comparable in size and scope.
Applicable to US Applicants Only:The expected compensation range for this position is $106,331 - $129,960, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate’s relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: https://www.solventum.com/en-us/home/our-company/careers/#Total-RewardsResponsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties.Solventum is committed to maintaining the highest standards of integrity and professionalism in our recruitment process. Applicants must remain alert to fraudulent job postings and recruitment schemes that falsely claim to represent Solventum and seek to exploit job seekers.
Please note that all email communications from Solventum regarding job opportunities with the company will be from an email with a domain of @solventum.com. Be wary of unsolicited emails or messages regarding Solventum job opportunities from emails with other email domains.
Please note, Solventum does not expect candidates in this position to perform work in the unincorporated areas of Los Angeles County.Solventum is an equal opportunity employer. Solventum will not discriminate against any applicant for employment on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status.Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.
Solventum Global Terms of Use and Privacy Statement
Carefully read these Terms of Use before using this website. Your access to and use of this website and application for a job at Solventum are conditioned on your acceptance and compliance with these terms.
Please access the linked document by clicking here, select the country where you are applying for employment, and review. Before submitting your application you will be asked to confirm your agreement with the
terms.
Tags: APIs Engineering Privacy Python Security Testing
Perks/benefits: Career development Competitive pay Flex hours Health care Insurance Relocation support
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.