Назад
Company hidden
4 дня назад

Sr Information Security Engineer (Healthcare)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr Information Security Engineer (Healthcare): Designing, implementing, and operating security controls for systems, networks, endpoints, and cloud environments protecting patient genomic and health information with an accent on MDR/SIEM, vulnerability management, privileged access management, and Zero Trust. Focus on leading end-to-end incident response, advancing identity and cloud security, and implementing PHI/PII data protection controls.

Location: Remote, based in the United States

Company

hirify.global is a clinical genetic testing laboratory that protects patient genomic and health information.

What you will do

  • Lead and operate detection and response capabilities, including SIEM/MDR, EDR/XDR, and SOAR.
  • Establish a centralized, risk-based vulnerability management program with patch service-level agreements, secure configuration baselines, and penetration test remediation.
  • Design and implement identity and access controls, including PAM, JIT access, MFA, SSO, Conditional Access, and least privilege.
  • Advance the Zero Trust roadmap across identity, endpoints, networks, cloud, and data.
  • Detect, contain, investigate, and recover from security incidents; lead post-incident reviews and provide periodic on-call support.
  • Implement PHI/PII data protection controls, including classification and DLP across endpoints and cloud services, while collaborating with IT, Privacy, Compliance, and application teams.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or an equivalent combination of education and experience.
  • 6–8 years of experience in information security engineering, security operations, or a related discipline.
  • Hands-on experience with SIEM/MDR and EDR platforms, security event monitoring, triage, and detection tuning.
  • Knowledge of network security, firewalls, IDS/IPS, cryptography, authentication, authorization, vulnerability management, incident response, and endpoint hardening.
  • Working knowledge of Azure and/or AWS security and identity platforms such as SSO, MFA, and Conditional Access.
  • Understanding of healthcare data compliance frameworks and regulations, including HIPAA, HITRUST, NIST, and GDPR, plus strong written and verbal communication skills.

Nice to have

  • Advanced certifications such as CISSP, CISM, GCIA, GCIH, or an Azure/AWS security specialty.
  • Experience with PAM, SOAR, Zero Trust architectures, DLP, Microsoft Purview, and data classification programs.
  • Experience in healthcare, clinical laboratory, or another regulated HIPAA/PHI environment.

Culture & Benefits

  • Remote work with occasional travel for meetings, conferences, or audits.
  • Periodic on-call availability may be required for security incident response.
  • Cross-functional collaboration with IT, Privacy, Compliance, and application teams.
  • Opportunity to mentor other security engineers and influence security practices across the organization.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →