About the job Clinical Engineering Cyber Specialist
Job Function: Engineering
Industry: Hospital & Healthcare
Experience Level: Mid-Senior Level (3+ Years)
Education Level: Bachelor's Degree
Total Positions: 1
Compensation: To be discussed
Relocation Assistance: No
Visa Sponsorship Eligibility: No
Role Overview
We are seeking a Clinical Engineering Cyber Specialist to oversee and execute critical technical components of the healthcare cybersecurity program at a major healthcare facility in Far Rockaway, NY.
In this role, you will lead the implementation of medical device cybersecurity strategies and controls, perform comprehensive risk assessments, and collaborate closely with hospital IT and InfoSec teams to ensure the security, integrity, and availability of connected medical equipment. The ideal candidate brings strong technical leadership, a proactive approach to threat mitigation, and a deep understanding of healthcare regulatory compliance.
Essential Responsibilities
Technical Support & Threat Mitigation (80%)
- Lead the collection and maintenance of Critical Cybersecurity Data Elements (CDEs) and manufacturer documentation in the Computerized Maintenance Management System (CMMS).
- Conduct thorough risk assessments of medical assets based on collected CDEs and vendor technical documentation.
- Oversee out-of-the-box configuration and baseline hardening of medical devices to align with established cybersecurity standards and manufacturer guidelines.
- Manage planned and unplanned vulnerability remediation efforts, including routine software patching, hardware upgrades, and rapid responses to zero-day threats.
- Coordinate technical cybersecurity activities, remediation workflows, and vendor patch validations with medical device manufacturers.
- Lead the testing and validation of network segmentation rules in direct coordination with hospital IT network teams.
- Support cross-functional IT projects involving connected medical devices operating on the hospital network.
Program Support & Incident Handling (10%)
- Investigate cybersecurity alerts and anomalous activity across connected medical devices within the hospital and affiliated clinics.
- Analyze high and critical vulnerabilities to develop actionable incident response recommendations.
- Track and report on vulnerability remediation progress, identifying ongoing opportunities to strengthen HTM and IT cybersecurity practices.
- Maintain quality control and integrity for all cybersecurity data and inventory records within the CMMS.
Training & Mentorship (5%)
- Support Healthcare Technology Management (HTM) cybersecurity education and awareness initiatives across operational teams.
- Coach Biomedical Equipment Technicians (BMETs) on fundamental cybersecurity hygiene, standard controls, and risk mitigation.
- Represent the organization in industry cybersecurity workgroups, forums, and knowledge-sharing panels.
- Complete all assigned mandatory technical and non-technical training requirements.
Regulatory & Compliance (5%)
- Advise on hospital audits involving medical device cybersecurity, including HIPAA, Joint Commission, and relevant regulatory bodies.
- Provide technical guidance for enterprise cybersecurity audits in alignment with organizational leadership priorities.
Qualifications & Requirements
Minimum Qualifications
- Education: Bachelor's degree in Clinical Engineering, Cybersecurity, Information Technology, Biomedical Engineering, or a related field (or equivalent practical experience).
- Experience: Minimum of 3 years of functional experience in medical device cybersecurity, Healthcare Technology Management (HTM), or a related clinical network infrastructure environment.
- Licensure: Valid driver's license with an acceptable driving record.
Key Skills & Competencies
- Deep understanding of medical device architecture, clinical workflows, and network protocols.
- Technical knowledge of CMMS platforms and vulnerability management toolsets.
- Practical familiarity with cybersecurity frameworks (e.g., NIST CSF, ISO/IEC 27001) and regulatory/compliance standards (FDA guidance, Joint Commission, HIPAA).
- Proven track record leading technical projects and driving cross-functional alignment across IT, InfoSec, and clinical staff.
- Relevant industry certifications (e.g., CISSP, HCISPP, CEH, or CompTIA Security+) are strongly preferred.
Benefits & What We Offer
We offer a competitive and equitable compensation structure, with salary offers determined based on a candidate's specific skills, education, and relevant experience.
Full-time employees gain access to a comprehensive benefits package, including:
- Comprehensive Medical, Dental, and Vision Care Insurance
- Wellness Programs and Employee Support Resources
- 401(k) Retirement Plan with Matching Contributions
- Paid Time Off (PTO) and Paid Company Holidays
- Continuous Career Growth Opportunities and Tuition Reimbursement