We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Cloud Security Engineer Principal

Children's Hospital of Philadelphia
$129,700.00 - $171,900.00 Annually
United States, Pennsylvania, Philadelphia
Oct 01, 2026

SHIFT:

Day (United States of America)

Seeking Breakthrough Makers

Children's Hospital of Philadelphia (CHOP) offers countless ways to change lives. Our diverse community of more than 20,000 Breakthrough Makers will inspire you to pursue passions, develop expertise, and drive innovation.

At CHOP, your experience is valued; your voice is heard; and your contributions make a difference for patients and families. Join us as we build on our promise to advance pediatric care-and your career.

CHOP does not discriminate on the basis of race, color, sex, national origin, religion, or any other legally protected categories in any employment, training, or vendor decisions or programs. CHOP recognizes the critical importance of a workforce rich in varied backgrounds and experiences and engages in ongoing efforts to achieve that through equally varied and non-discriminatory means.

A Brief Overview

As CHOP continues to transform pediatric healthcare, we strive to evolve our security program to protect organizational assets and support our world class health system strategy. The Information Security Principal is a senior technical leadership role that provides expert level knowledge and serves as a critical thought leader in one or more information security domains, with enterprise wide influence and responsibility within those domains.

This department works approximately 80% remotely, 20% on site in our Philadelphia offices on an as-needed basis.

What you will do

  • The Information Security Principal is a senior technical leadership role distinguished from Specialist III by its expertlevel domain knowledge and responsibility for enterprisewide leadership and influence within one or more information security domains. This role operates with a high degree of independence, driving solution and service development through critical thinking, evaluating and socializing options with stakeholders, and guiding decisions that align with enterprise strategy.

Essential functions of the Information Security Principal are:

  • Leads complex, enterprise-scale security initiatives from concept through implementation, coordinating colleagues, vendors, stakeholders, risks, timelines, and outcomes to deliver solutions aligned with enterprise priorities.
  • Serves as the subject matter expert for assigned security domains, applying deep knowledge of CHOP's business, clinical, research, and operational environments to guide information protection and compliance decisions.
  • Leads advanced analysis and resolution of complex security issues, identifying root causes and driving sustainable improvements across teams.
  • Partners with architects, engineers, and service owners to define secure architecture patterns and standards across systems, applications, cloud, identity, data, and infrastructure
  • Advances security service maturity by strengthening controls, promoting best practices, improving reliability and resiliency and considering lifecycle, financial, and sustainability impacts
  • Articulates the business impact of security and technology, incorporating stakeholder feedback and using meaningful technical and non-technical metrics to guide service effectiveness. Communicates complex security concepts clearly to a variety of audiences to support informed decision-making
  • Supports and leads Information Security strategy, policies, standards, and program initiatives, including roadshows, working sessions, and critical security forums.
  • Leads security-related business continuity, disaster recovery, and cyber resiliency activities, including tabletop exercises, continuity planning, recovery readiness, and control validation
  • Produces clear technical, architectural, risk, operational, and executive-level documentation, including standards, design artifacts, guidance, and decision materials
  • Promotes continuous learning, mentoring, and technical excellence by coaching others, sharing knowledge, and staying current on emerging technologies, threats, and regulatory changes
  • Ensures security solutions are designed with lifecycle and financial considerations in mind, contributing input to budget planning, service sustainability, and enterprise technology standards.

Licenses and Certifications

Senior level technical security certification Senior level technical security certification upon hire Required

  • Certified Information Systems Security Professional (CISSP) International Information System Security Certification Consortium (ISC2) upon hire Preferred or
  • HealthCare Information Security and Privacy Practitioner (HCISPP) International Information System Security Certification Consortium (ISC2) upon hire Preferred or
  • Systems Security Certified Practitioner (SSCP) International Information System Security Certification Consortium (ISC2) upon hire Preferred or
  • Certified Information Security Manager (CISM) Information Systems Audit and Control Association (ISACA) upon hire Preferred or
  • Certified Information Systems Auditor (CISA) Information Systems Audit and Control Association (ISACA) upon hire Preferred or
  • Certified in the Governance of Enterprise IT (CGEIT) Information Systems Audit and Control Association (ISACA) upon hire Preferred or
  • Certified in Risk and Information Systems Control (CRISC) Information Systems Audit and Control Association (ISACA) upon hire Preferred or
  • GIAC Security Essentials (GSEC) GIAC Certifications upon hire Preferred or
  • Certified Ethical Hacker (CEH) EC-Council upon hire Preferred or
  • Certificate of Cloud Security Knowledge (CCSK) Cloud Security Alliance (CSA) upon hire Preferred or
  • Certificate of Cloud Auditing Knowledge (CCAK) Cloud Security Alliance (CSA) upon hire Preferred or
  • Cloud security: CCSP, AWS Certified Security - Specialty, Azure Security Engineer upon hire Preferred or
  • Penetration testing: OSCP, PNPT, GPEN upon hire Preferred

Education Qualifications

  • Bachelor's Degree - Required
  • Bachelor's Degree Computer Science, Information Systems, or related field - Preferred

Experience Qualifications

  • At least twelve (12) years industry related experience, including experience in one to two IT disciplines (such as technical architecture, network management, application development, middleware, information analysis, database management or operations) in a multitier environment. Required and
  • At least six (6) years experience with information security, regulatory compliance and risk management concepts. Required and
  • At least three (3) years experience with Identity and Access Management, user provisioning, Role Based Access Control, or control self-assessment methodologies and security awareness training. Required and
  • Experience with Cloud and/or Virtualization technologies. Required
  • At least three (3) years in working with matrixed high performance teams. Preferred

Skills and Abilities

  • Demonstrates comprehensive knowledge and understanding of Information security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.
  • Exhibits knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, ISO 27000 series).
  • Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.
  • Good knowledge of basic database query techniques & data mining to analyze data or other related database functionality.
  • Knowledge of Microsoft Active Directory, UNIX, and Clinical Applications a plus.
  • Experience implementing application level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience a plus.
  • General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.
  • Microsoft, UNIX, Lawson, and Clinical Applications,
  • Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, Project).
  • Experience with risk management frameworks.
  • Information Security Requirements
  • Understand and comply with all enterprise and IS departmental information security policies, procedures and standards.
  • Support the integration of information security in the development, design, and implementation of Hospital Technology Resources that process, transmit, or store CHOP information.
  • Support all compliance activities related to state, federal regulatory requirements, healthcare accreditation standards, and all other applicable regulations that govern the use and disclosure of patient, financial, or other confidential information.

To carry out its mission, CHOP is committed to supporting the health of our patients, families, workforce, and global community. As a condition of employment, CHOP employees who work in patient care buildings or who have patient facing responsibilities must receive an annual influenza vaccine. Learn more. EEO / VEVRAA Federal Contractor | Tobacco Statement

SALARY RANGE:

$129,700.00 - $171,900.00 Annually

Salary ranges are shown for full-time jobs. If you're working part-time, your pay will be adjusted accordingly.

-------------------

At CHOP, we are committed to fair and transparent pay practices. Factors such as skills and experience could result in an offer above the salary range noted in this job posting. Click here for more information regarding CHOP's Compensation and Benefits.

Applied = 0

(web-9db6c7984-gr7xl)