Cyber Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
- Own configuration, tuning, and operational health of Mimecast and Zscaler. Monitor platform health, review alert fidelity, and identify gaps in coverage
- Analyze email and web security events. Investigate suspicious activity, triage alerts, and escalate confirmed incidents through established IR procedures
- Identify opportunities to improve detection logic and policy configuration. Collaborate with security operations peers to implement, test, and validate changes
- Produce metrics and reporting on the state of email and web security controls. Communicate findings clearly to management and peer teams
Threat Hunting
- Conduct proactive, hypothesis-driven hunts for adversary activity across the enterprise environment, with particular depth in email and web traffic
- Develop hunting hypotheses from threat intelligence, industry reporting, and observed anomalies. Document methodology, findings, and outcomes for each hunt
- Identify indicators of compromise and behavioral patterns that automated detection has not flagged. Escalate confirmed findings through IR procedures
- Contribute hunting findings back to detection engineering - hunts that prove out should become automated detections where feasible
- Stay current on threat actor tactics, techniques, and procedures relevant to the healthcare sector. Apply that knowledge to prioritize hunting activity
General
- Support Tier 2 and Tier 3 escalations when email, web security, or hunting context is relevant
- Contribute to policy, standards, and procedure updates that affect email and web security controls
- Participate in on-call rotation for after-hours security support, approximately one week per month
What Weāre Looking For Passion for Information Security
- You follow the threat landscape because you find it genuinely interesting, not because itās in your job description. You read security blogs, track CVEs, or participate in CTFs on your own time
- You care about getting it right - not just closing tickets, but understanding what actually happened and why
- You bring energy to your work even when itās routine. Tool tuning and alert review arenāt glamorous, but you treat them as opportunities to improve coverage rather than tasks to get through
Critical Thinking
- You question assumptions. When an alert fires, you ask whether the detection logic is sound before assuming the activity is malicious
- You can hold competing hypotheses at the same time and work methodically to rule them out. Threat hunting without that discipline produces noise, not findings
- You know when youāve found something and when you havenāt. Intellectual honesty about inconclusive results is as important as identifying real threats
- You look for root causes, not just symptoms. A misconfigured policy is worth fixing even if it hasnāt been exploited yet
Collaboration and Communication
- You work well across a team of engineers who each own different tools and disciplines. You ask for help when you need it and offer it when you can
- You can explain technical findings to someone who isnāt technical
- You document your work. Hunt methodology, investigation notes, and configuration changes need to be reproducible by someone else
Requirements
- Bachelorās degree in a related field, or equivalent demonstrated experience
- 3 to 5 years of experience in a security engineering or security operations role
- Working knowledge of email security concepts including SPF, DKIM, and DMARC
- Familiarity with secure web gateway or zero trust network access technologies
- Experience using a SIEM for log analysis and investigation - writing queries, correlating events, and building timelines
- Working knowledge of MITRE ATT&CK and how it applies to structured threat hunting
- Experience supporting incident detection and response in an enterprise environment
- Familiarity with HIPAA and HITRUST compliance requirements as they apply to security operations, * GCIA (GIAC Certified Intrusion Analyst)
- GCIH (GIAC Certified Incident Handler)
- CompTIA Security+
About the company
TeamHealth is proud to be the leading physician practice in the U.S. providing exceptional patient care, together. TeamHealth has been recognized as one of the ā165 Top Places to Work in Healthcareā for 2026 by Beckerās Hospital Review. TeamHealth has also been recognized by Newsweek as one of Americaās Greatest Workplaces in Health Care for 2025. We continue to grow across the U.S. from our Clinicians to Corporate Employees. Join Us!
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Understanding and Mitigating Common Web Vulnerabilities
Top-Paying Tech Jobs (with Salaries)
Best Paying Jobs in Technology