4 дня назад
Sr Information Security Engineer (Healthcare)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr Information Security Engineer (Healthcare): Designing, implementing, and operating security controls for systems, networks, endpoints, and cloud environments protecting patient genomic and health information with an accent on MDR/SIEM, vulnerability management, privileged access management, and Zero Trust. Focus on leading end-to-end incident response, advancing identity and cloud security, and implementing PHI/PII data protection controls.
Location: Remote, based in the United States
Company
is a clinical genetic testing laboratory that protects patient genomic and health information.
What you will do
- Lead and operate detection and response capabilities, including SIEM/MDR, EDR/XDR, and SOAR.
- Establish a centralized, risk-based vulnerability management program with patch service-level agreements, secure configuration baselines, and penetration test remediation.
- Design and implement identity and access controls, including PAM, JIT access, MFA, SSO, Conditional Access, and least privilege.
- Advance the Zero Trust roadmap across identity, endpoints, networks, cloud, and data.
- Detect, contain, investigate, and recover from security incidents; lead post-incident reviews and provide periodic on-call support.
- Implement PHI/PII data protection controls, including classification and DLP across endpoints and cloud services, while collaborating with IT, Privacy, Compliance, and application teams.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or an equivalent combination of education and experience.
- 6–8 years of experience in information security engineering, security operations, or a related discipline.
- Hands-on experience with SIEM/MDR and EDR platforms, security event monitoring, triage, and detection tuning.
- Knowledge of network security, firewalls, IDS/IPS, cryptography, authentication, authorization, vulnerability management, incident response, and endpoint hardening.
- Working knowledge of Azure and/or AWS security and identity platforms such as SSO, MFA, and Conditional Access.
- Understanding of healthcare data compliance frameworks and regulations, including HIPAA, HITRUST, NIST, and GDPR, plus strong written and verbal communication skills.
Nice to have
- Advanced certifications such as CISSP, CISM, GCIA, GCIH, or an Azure/AWS security specialty.
- Experience with PAM, SOAR, Zero Trust architectures, DLP, Microsoft Purview, and data classification programs.
- Experience in healthcare, clinical laboratory, or another regulated HIPAA/PHI environment.
Culture & Benefits
- Remote work with occasional travel for meetings, conferences, or audits.
- Periodic on-call availability may be required for security incident response.
- Cross-functional collaboration with IT, Privacy, Compliance, and application teams.
- Opportunity to mentor other security engineers and influence security practices across the organization.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Information Security Engineer (Corporate Technology)
100 000 - 150 000$
4 дня назад
Cybersecurity Engineer - CBO (Cybersecurity)
90 000 - 107 000$
8 дней назад
Security Engineer (Expert Seniority Level)
9 дней назад
Security Operations Engineer (Healthcare)
125 000 - 150 000$
4 дня назад
Senior Network Engineer (Cisco)
115 000 - 142 000$
9 дней назад
Director, IT Security (Cybersecurity)
141 300 - 223 200$