Senior Security Engineer

HealthMark Group

• $120K — $145K *
US-AnywhereRemote in United States
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field
  • 5+ years of senior engineering experience, education may be substituted
  • Experience with AWS, Azure, or GCP
  • Proficient in Microsoft Entra, Active Directory, and AWS IAM
  • Familiar with HIPAA, NIST, SOC2, and HITrust security controls
  • Current information security certification (CISSP, CSSLP, CCFP, CISM)
  • Strong knowledge of Windows operating systems and network protocols

Responsibilities

  • Ensure HIPAA compliance by implementing necessary safeguards for Protected Health Information
  • Design and maintain cybersecurity architecture using HIPAA Security Rule and NIST frameworks
  • Analyze and improve cloud and corporate security posture
  • Configure and maintain security infrastructure software and services
  • Collaborate with SecOps, Legal, and Compliance teams to develop security policies
  • Establish Identity and Access guidelines and manage authorization systems
  • Lead security audits and client security assessments
  • Monitor systems for threats and triage incidents with Managed Service Provider
  • Work with Development and CloudOps to manage and remediate vulnerabilities
  • Provide Cyber Security training and mentorship to staff
  • Develop documentation for security practices and incident response
  • Report metrics on security threats using cloud and third-party tools
  • Communicate critical information to leadership effectively
  • Stay updated on industry trends and attack remediations

Benefits

  • Remote work flexibility
  • Opportunities for professional development and training
  • Collaborative team environment
  • Access to cutting-edge security tools and technologies
  • Engagement with industry-leading security frameworks
Full Job Description
LOCATION: Remote

POSITION: Sr. Security Engineer

The Sr. Security Engineer is a member of the Security and IT Operations team focused on ensuring the confidentiality, integrity, and availability of sensitive health information. Given the regulatory landscape (e.g., HIPAA) and the importance of protecting patient data, this position requires deep technical expertise and strong security leadership.

PRIMARY ROLE AND RESPONSIBILITIES:

  • Ensure HIPAA compliance by implementing necessary safeguards to protect Protected Health Information entrusted to us by our clients.
  • Design, implement, and maintain cybersecurity architecture leveraging security framework including HIPAA Security Rule, NIST Cybersecurity Framework, and NIST 800-53
  • Analyze current cloud and corporate security posture and recommend improvements, build and develop secure systems/infrastructure
  • Configure, troubleshoot, and maintain security infrastructure software, tooling, and services
  • Work with SecOps leadership, Legal, and Compliance teams to develop, review, and revise Security Policies and Procedures
  • Establish Identity and Access guidelines, design and manage authorization and authentication systems, review access requests for approval, perform periodic audits of existing access
  • Lead security components of audits such as SOC 2 Type 2, HITrust, and PCI
  • Lead response to client security assessments
  • Work with our Managed Service Provider to effectively monitor our systems for threats, and triage incidents using best practices methodology
  • Work with Development and CloudOps to identify, manage and remediate vulnerabilities
  • Provide Cyber Security training and mentorship to staff
  • Develop and maintain documentation around security practices, incident response, and security protocols
  • Provide metrics-based reporting utilizing cloud and third-party tools to identify and respond to security threats
  • Great communicator with the ability to relay critical information to leadership promptly
  • Stay up to date with industry trends and advancements in current attacks and remediations
  • Ability to solve intricate problems with key source systems (Directory, Database, etc...)


REQUIRED EXPERIENCE AND QUALIFICATIONS:

  • Bachelor's degree in Computer Science, Engineering, or related field
  • Relevant experience at a senior engineering level for at least 5 years - may substitute for education.
  • Experience with Cloud Service Providers such as AWS, Azure or GCP
  • Experience with Microsoft Entra, Active Directory, and AWS IAM administration
  • Experience with HIPAA, NIST, SOC2, and HITrust security controls
  • Current information security certification (CISSP, CSSLP, CCFP, CISM)
  • Experience using Agile methodologies including Scrum or Kanban
  • Strong knowledge of operating systems (Windows) and network protocols.
  • Familiarity with cloud security (e.g., AWS, Azure) and DevSecOps practices.


ADDITIONAL PREFERRED EXPERIENCE:

  • Assist in planning and developing an information security strategy
  • Understanding of trending attack vectors, remediations, and mitigating controls
  • Proficiency with scanning and vulnerability tools
  • Networking and Cryptography Experience in Practice
  • Authentication Mechanisms and controls within IAM/PAM space
  • Pentest / Adversarial testing of critical systems, components, or services

Similar Jobs

More Jobs at HealthMark Group

  • Credential Manager
    $80K — $95K *
    Remote
    Healthcare
    Remote in United States
  • Security Engineer
    $110K — $130K *
    Remote
    Information Technology
    Remote in United States

More Healthcare Jobs

Find similar Senior Security Engineer jobs: