OneOncology

Security Engineer

OneOncology$90K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in security engineering or related IT security role
  • Solid understanding of network, endpoint, and cloud security
  • Experience with SIEM, vulnerability scanners, and EDR solutions
  • Familiarity with HIPAA and healthcare data privacy regulations
  • Knowledge of encryption, IAM, and secure network design
  • Experience in incident response and investigation
  • Strong communication skills to convey risks to diverse audiences

Responsibilities

  • Design, implement, and maintain security controls across various technology environments
  • Conduct vulnerability assessments and implement remediation strategies
  • Monitor security systems and respond to alerts and incidents
  • Lead or support incident response efforts
  • Ensure compliance with HIPAA and healthcare regulatory requirements
  • Manage IAM practices and perform least-privilege access reviews
  • Evaluate and implement security tools to enhance the security posture

Benefits

  • Health insurance starting Day 1
  • Dental, vision, and life insurance
  • Short and long-term disability coverage
  • Generous paid time off (PTO)
Full Job Description
Job Description:

Security Engineer

Location: Port Jefferson, NY
Hours/Days: Monday-Friday 8:30am-5pm
Organization: New York Cancer & Blood Specialists (NYCBS)


NY Cancer & Blood is seeking a talented Security Engineer to help design, implement, and maintain and security infrastructure that protects our IT systems, networks, medical devices, and patient data. In this role, you'll work cross-functionally with IT, clinical, and compliance teams to identify vulnerabilities, respond to incidents, and build security into every layer of our environment, from network infrastructure to clinical and administrative systems. This role is well-suited to someone who enjoys both hands-on technical work and the challenge of operating in a highly regulated environment where security failures can have real consequences for patient care and safety.

What You'll Do:
  • Design, implement, and maintain security controls across on-premises networks, cloud infrastructure, endpoints, and clinical/administrative applications (EMR, lab, and medical devices, etc.)
  • Conduct vulnerability assessments and remediate vulnerabilities
  • Monitor security systems (SOC, EDR, etc.) and respond to alerts and incidents
  • Lead or support incident response efforts, including investigation, containment, and remediation of security incidents
  • Ensure systems and processes align with HIPAA and other relevant healthcare regulatory requirements
  • Support audits and risk assessments (HITRUST, internal/external audits, regulatory inspections)
  • Manage identity and access management (IAM) practices, including least-privilege access reviews for all applications
  • Evaluate and implement security tools and technologies to strengthen our security posture
  • Develop and maintain security documentation and policies
  • Provide security awareness training and guidance to clinical staff, administrative staff, and IT teams
  • Stay current on emerging threats and healthcare-specific attack trends (e.g., ransomware targeting hospital systems, PHI breaches, medical device vulnerabilities)


What We're Looking For:
  • 3+ years of experience in a security engineering, infrastructure security, or related IT security role
  • Solid understanding of network security, endpoint security, and cloud security fundamentals
  • Experience with security tools such as SIEM platforms, vulnerability scanners, and EDR solutions
  • Familiarity with HIPAA and other healthcare data privacy/security regulations
  • Working knowledge of encryption, IAM, and secure network design
  • Experience responding to and investigating security incidents
  • Strong communication skills, ability to explain risk to both clinical/administrative staff and technical stakeholders


Nice to Have:
  • Additional years of IT experience considered a plus
  • Experience securing healthcare-specific systems (EMR platforms, HL7/FHIR interfaces, medical devices, biomedical/IoT equipment)
  • Relevant certifications
  • Experience with compliance frameworks such as HIPAA, HITRUST, or NIST 800-53
  • Experience working in a hospital, health system, or clinical environment


Compensation & Benefits:
  • Salary: Starting at $90,000/yr
  • Benefits Include:
    • Health Insurance starting Day 1
    • Dental, Vision, Life Insurance
    • Short & Long-Term Disability
    • Generous PTO

About OneOncology

OneOncology is a technology-enabled community of independent, community oncology practices working together to improve the lives of everyone living with cancer through a patient-centric, physician-driven, and technology-powered model.
Learn more about OneOncology
Size
500 employees
Industry
Founded
2018

Similar Jobs

More Jobs at OneOncology

More Healthcare Jobs

Find similar Security Engineer jobs: