Senior Information Security Engineer
Posted 34ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Information Security Engineer safeguarding cloud-based healthcare SaaS platforms and customer data. Responsible for designing, implementing, and managing enterprise-grade security solutions.
Responsibilities:
- Design and maintain secure architectures across AWS, Azure, and GCP environments.
- Implement guardrails and controls using services such as AWS Security Hub, GuardDuty, Config, and IAM.
- Conduct regular vulnerability scans, configuration reviews, and remediation tracking for infrastructure and workloads.
- Develop and enforce network segmentation, encryption, and key management policies.
- Collaborate with DevOps and Engineering to integrate security into CI/CD pipelines (Snyk, StackHawk, etc.).
- Perform threat modeling, code reviews, and secure design reviews for microservices and APIs.
- Support penetration testing and application security validation efforts.
- Manage and enhance EDR/XDR solutions (e.g., Cortex, Defender for Endpoint).
- Implement and monitor identity security controls through Microsoft Entra ID (Azure AD), Conditional Access, and PIM.
- Monitor alerts, investigate incidents, and coordinate responses with the SOC.
- Support audits and evidence collection for HIPAA, HITRUST, SOC 2, and customer security assessments.
Requirements:
- Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
- 5+ years of experience in security engineering or related technical security roles.
- Strong knowledge of cloud-native security (AWS, Azure) and modern SaaS architectures.
- Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation.
- Familiarity with HIPAA, HITRUST, and SOC 2 requirements.
- Experience securing containerized and serverless workloads (e.g., EKS, Lambda).




















