Senior Information Security Engineer

Posted 34ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Information Security Engineer safeguarding cloud-based healthcare SaaS platforms and customer data. Responsible for designing, implementing, and managing enterprise-grade security solutions.

Responsibilities:

  • Design and maintain secure architectures across AWS, Azure, and GCP environments.
  • Implement guardrails and controls using services such as AWS Security Hub, GuardDuty, Config, and IAM.
  • Conduct regular vulnerability scans, configuration reviews, and remediation tracking for infrastructure and workloads.
  • Develop and enforce network segmentation, encryption, and key management policies.
  • Collaborate with DevOps and Engineering to integrate security into CI/CD pipelines (Snyk, StackHawk, etc.).
  • Perform threat modeling, code reviews, and secure design reviews for microservices and APIs.
  • Support penetration testing and application security validation efforts.
  • Manage and enhance EDR/XDR solutions (e.g., Cortex, Defender for Endpoint).
  • Implement and monitor identity security controls through Microsoft Entra ID (Azure AD), Conditional Access, and PIM.
  • Monitor alerts, investigate incidents, and coordinate responses with the SOC.
  • Support audits and evidence collection for HIPAA, HITRUST, SOC 2, and customer security assessments.

Requirements:

  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
  • 5+ years of experience in security engineering or related technical security roles.
  • Strong knowledge of cloud-native security (AWS, Azure) and modern SaaS architectures.
  • Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation.
  • Familiarity with HIPAA, HITRUST, and SOC 2 requirements.
  • Experience securing containerized and serverless workloads (e.g., EKS, Lambda).