Cybersecurity Specialist
Reports to Director of Infrastructure
Background: Cahaba Medical Care Foundation is a community health center providing medical, pharmacy, dental, and behavioral health services to diverse underserved communities in Alabama. We are a Level 3 Patient-Centered Medical Home and Joint Commission accredited organization, committed to increasing integration and coordination of behavioral health and primary care. This is an exciting, fast paced practice with a strong mission and commitment to providing high quality care.Â
Position Summary:Â The Cybersecurity Specialist will be the dedicated champion for the security posture of our Federally Qualified Health Center (FQHC). Reporting directly to the IT Director/Director of Infrastructure, this role will transition our security from a shared team responsibility to a focused, proactive program. You will be responsible for safeguarding patient data (PHI), ensuring HIPAA compliance, managing security vendor relationships, implementing further endpoint controls, and leading our internal vulnerability assessments.
Responsibilities and Duties:
Vulnerability & Threat Management: Lead annual security risk assessments and ongoing internal penetration testing. Analyze results, prioritize remediation, and work with the IT team to patch vulnerabilities.
MDR/SIEM Oversight: Serve as the primary point of contact and administrator for our 24/7 security monitoring partner. Monitor alerts, investigate incidents, and lead response efforts.
Endpoint & Identity Security: Take ownership of securing our mixed-OS environment. Maintain Google Workspace Enterprise policies for Chromebooks, and spearhead the selection, implementation, and management of a Mobile Device Management and directory solution for our Windows and Mac endpoints.
Network & Access Control: Maintain and optimize our RADIUS-based network authentication and access controls to ensure secure connectivity across all clinic sites.
Compliance & Governance: Ensure all IT systems and workflows align with HIPAA, HITECH, and other healthcare regulatory frameworks. Maintain documentation for audits.
Security Awareness: Develop and run ongoing security awareness training and phishing simulations for FQHC staff.
Qualifications:
Experience: 3–5 years of dedicated experience in cybersecurity or information security, preferably within a healthcare (FQHC/hospital) or highly regulated environment.
Technical Stack Familiarity:
Strong knowledge of Google Workspace Enterprise administration and ChromeOS security.
Proven experience implementing MDM solutions from scratch.
Familiarity with Network Access Control (NAC) and RADIUS protocols.
Experience working with co-managed SIEM/MDR providers.
Certifications (Preferred but not required): CompTIA Security+, CEH (Certified Ethical Hacker), GSEC, or HCISPP (Healthcare Information Security and Privacy Practitioner).
Soft Skills: A collaborative mindset. You will be embedding security into the workflows of a busy IT team and medical staff, so empathy and clear communication are key.
Learn more about this Employer on their Career Site
