OverviewAbout the Role:The Senior Security Engineer is HealthDrive's in-house owner of day-to-day security operations and security configuration. This role handles the security work that arrives every day - reported phishing, email and data loss prevention alerts, endpoint detections, and escalations from our managed security providers - and drives each to closure. It also owns the configuration and hardening of our Microsoft cloud estate and holds accountability for ensuring identified vulnerabilities are actually remediated.
HealthDrive uses managed security providers for around-the-clock monitoring and for network security engineering. This role sits above those providers: it directs their work, evaluates their performance, and remains the decision-maker for HealthDrive when a genuine security incident occurs. This is a hands-on engineering role, not a governance or audit role, and not a role that supervises staff.
Work Environment:Based at HealthDrive's Framingham, MA office (off Route 9, near Routes 90 and 495) on a hybrid schedule.
Compensation Range:$85,000 to $115,000 / experience dependent
#INDHDCORPREC
ResponsibilitiesDay-to-Day Security Operations- Triage, investigate and resolve reported phishing and email-borne threats, including user communication and follow-up.
- Monitor, tune and maintain email security and data loss prevention policy and alerting; investigate and disposition DLP events involving protected health information.
- Own escalations from HealthDrive's managed detection provider from receipt through containment and closure, including endpoint detection and response alerts.
- Investigate user-reported security concerns and suspicious activity, and maintain records of findings and actions taken.
Vulnerability Management- Own the vulnerability management cycle end to end: scanning, risk-based prioritization, and accountability for remediation reaching completion.
- Work with Infrastructure and Software Development to schedule and validate remediation, including where patching conflicts with clinical or operational workflows.
- Report remediation status, aging and exceptions to IT leadership on a defined cadence.
Cloud and Endpoint Security Configuration- Own security configuration and hardening of Microsoft Entra ID, including Conditional Access policy design, review and change control.
- Own Microsoft 365 security configuration and data protection settings across mail, collaboration and file storage.
- Maintain endpoint security policy and configuration, and verify coverage across the managed device estate.
- Review and improve identity, access and privilege configuration, including administrative access and multi-factor authentication enforcement.
Managed Provider Oversight- Serve as HealthDrive's technical owner of the managed security provider relationships, covering monitoring, response and network security engineering services.
- Direct provider work, submit and validate detection tuning requests, and reduce recurring false positives.
- Run periodic service reviews, hold providers to contracted response commitments, and escalate performance shortfalls to IT leadership.
- Maintain documented escalation paths and ensure HealthDrive retains the knowledge required to change providers without loss of continuity.
Incident Response- Recommend and implement containment and recovery actions for affected systems when a provider escalates a confirmed incident.
- Maintain and exercise incident response procedures, and lead post-incident review and corrective action.
- Support breach assessment and notification analysis in coordination with Compliance and Legal.
Security Program Support- Contribute to security awareness and phishing simulation programs.
- Support security review of vendors and third parties, and of new applications and integrations, in partnership with Compliance.
- Maintain security documentation, configuration baselines and operational runbooks.
QualificationsMust have:- Approximately seven or more years of hands-on experience in security engineering or security operations, with demonstrated personal ownership of the work rather than coordination of it.
- Demonstrated hands-on ownership of email security and data loss prevention. Proofpoint strongly preferred; comparable enterprise platforms considered.
- Demonstrated hands-on experience configuring and securing Microsoft Entra ID and Microsoft 365, including Conditional Access policy design in a production environment.
- Demonstrated ownership of a vulnerability management program, including driving remediation to closure across teams that do not report to this role.
- Practical experience with endpoint detection and response platforms and with security monitoring or SIEM output. SentinelOne, Microsoft Sentinel or Secureworks Taegis are directly relevant.
- Demonstrated incident response experience with sound judgment on containment decisions.
- Experience working with or overseeing managed security service providers.
- Working knowledge of enterprise network and firewall security sufficient to review provider work and partner effectively with Infrastructure. Fortinet experience is relevant.
- Scripting or automation capability, such as PowerShell or Python.
- Ability to communicate risk clearly to non-technical stakeholders, including clinical and operational leaders.
Nice to have:- Healthcare provider-side experience and working familiarity with HIPAA and HITECH.
- Experience with Qualys, Fortinet, SentinelOne, Microsoft Sentinel or Secureworks.
- Third-party and vendor risk assessment experience.
- Experience in a small or lean IT organization where breadth and self-direction are required.
Education & Qualifications:- Bachelor's degree in Information Technology, Computer Science, Cybersecurity or a related field, or equivalent demonstrated professional experience.
Certifications & Licenses:- CISSP preferred.
- In the absence of CISSP, at least one of the following: AZ-500, SC-200, Security+, CySA+, CISM, CCSP or HCISPP
Core Competencies:- Cooperation and Team working
- Expertise and Professionalism
- Problem Solving / Analysis