About the RoleAs a Security Engineer at K Health, you will serve as a foundational force in securing our healthcare technology ecosystem. Reporting directly to the Director of Security, this is a deeply hands-on individual contributor role focused primarily on Security Operations (SecOps) and IT Security projects. You will be responsible for building, automating, and maintaining our security controls while acting as a key responder to security incidents. If you thrive in a fast-paced environment where you are empowered to own your domain, automate repetitive tasks, and directly safeguard patient and organizational data, this role is for you.
What You Will Do- Design, implement, and maintain hands-on SecOps workflows, threat detection, and incident response procedures across our corporate and cloud infrastructure.
- Build low-code and custom automations (using tools like Torq) to streamline security alerts, routine IT security tasks, and incident triage.
- Administer, optimize, and manage key security and endpoint management tools, including Sumo Logic, Jamf, Intune, Slack Enterprise, CrowdStrike, and related platforms.
- Maintain and support continuous compliance with SOC2 and HIPAA security controls, actively participating in audit preparation, evidence gathering, and control enforcement.
- Partner with cross-functional IT and engineering teams to harden systems, enforce zero-trust endpoint policies, and secure employee workflows.
- Conduct root-cause analysis on security incidents and proactively implement preventative security measures to eliminate recurring risks.
What We Are Looking For- Experience: 3-5 years of dedicated hands-on experience in Security Operations, IT Security, or System Administration with a strong security focus.
- Incident Response: Proven background in actively detecting, investigating, and remediating security incidents in a modern cloud/hybrid environment.
- Technical Depth: Deep foundational IT background spanning endpoint administration (macOS/Windows), identity management, and network security.
- Compliance Standards: Demonstrated experience maintaining controls for SOC2 and/or HIPAA frameworks in an operational setting.
- Automation Mindset: Hands-on experience automating security operations or IT tasks using SOAR platforms, scripting (Python, PowerShell, Bash), or API integrations.
Bonus- Direct experience implementing SOC2 or HIPAA controls from scratch or directly interfacing with external auditors.
- Hands-on familiarity with our specific technology stack: Sumo Logic, Jamf, Intune, Slack Enterprise, CrowdStrike, and Torq.
- Relevant industry certifications (e.g., Security+, Network+, GIAC, or vendor-specific platform certifications).
Benefits & Perks: #LI-Hybrid
- Hybrid work schedule with weekly lunches and stocked fridges
- Monthly social committees for company events
- 18 vacation days, 9 company holidays, 5 sick days, and 2 personal days
- Stock options for every full-time employee
- Paid parental leave
- 401k benefit
- Commuter Benefits
- Competitive health, dental, and vision insurance options
Compensation:
$125,000-$150,000 USD