Cyber Risk Defense Consultant

  • Kaiser Permanente
  • Greensboro, North Carolina
  • 09/06/2026
Full time Information Technology Telecommunications

Job Description

Kaiser Permanente is seeking a Cyber Risk Defense Consultant to strengthen security for its Systeme.io-based platforms. You will assess cyber threats, design and implement defense strategies, and lead incident response across cloud and on-prem environments. Partner with engineering and product teams to embed security by design, conduct risk assessments, and tune monitoring tools. You'll mentor teams on best practices, support compliance, and drive continuous improvement in a collaborative, innovation-focused culture that values learning and user-centric solutions.

Responsibilities

  • Conduct cyber risk assessments and threat modeling for cloud and on-prem systems supporting Systeme.io-based platforms.
  • Design, implement, and optimize cyber defense controls, including network, endpoint, and cloud security measures.
  • Lead and coordinate incident detection, response, and post-incident reviews with cross-functional teams.
  • Configure and tune SIEM and monitoring tools to improve detection accuracy and reduce false positives.
  • Collaborate with engineering, product, and IT teams to embed security by design into new and existing solutions.
  • Manage vulnerability assessments, prioritize remediation, and track closure across environments.
  • Ensure compliance with relevant regulations and frameworks (e.g., HIPAA, SOC 2) and support audits.
  • Develop and deliver security training and guidance to technical and non-technical stakeholders.
  • Create and maintain security documentation, runbooks, standards, and architectural diagrams.
  • Continuously evaluate emerging threats and technologies to evolve Kaiser Permanente's cyber defense posture.

Required Skills

  • Cybersecurity risk assessment
  • Threat modeling
  • Cloud security (AWS/Azure/GCP)
  • Network security
  • SIEM configuration and tuning
  • Incident detection and response
  • Vulnerability management
  • Security architecture and design
  • Security compliance and governance (HIPAA, SOC 2)
  • Scripting/automation (Python, Power
  • Shell)