Security Engineer

Infopeople Corporation
United States
10 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Firewall Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security System Configuration Information Leak Prevention Data Security
+34 more
Domain Name System (DNS) Email Management Identity and Access Management Information Security Management IT Management Internet Security Virtual Private Networks (VPN) Python (Programming Language) Network Security Network Configuration and Change Management Network Planning and Design Routing Windows PowerShell Azure Active Directory Phishing Security Information and Event Management TCP/IP Transmission Control Protocol (TCP) Technical Data Management Systems Software Vulnerability Management Network Routing Scripting Okta Malware Firewalls (Computer Science) Microsoft InTune Information Technology Microsoft Sentinel Data Management Fortinet Cisco Qualys Security Orchestration, Automation & Response Vulnerability Analysis

Job description

The Senior Security Engineer is a hands-on, implementation-focused role responsible for protecting the Client’s sensitive data and strengthening security across on-premises and Microsoft Azure environments. This engineer builds, configures, and operates security controls, including firewalls, endpoint and email protection, cloud security, and vulnerability management, while leading incident detection, investigation, and response. Working closely with IT leadership and the Client’s Managed Security Service Provider (MSSP), the engineer also manages the third-party risk process from end to end. This is primarily a technical build-and-operate role, not a policy or oversight position. SPECIFIC DUTIES & RESPONSIBILITIES:

  • Security infrastructure management: Build, configure, deploy, and maintain security infrastructure firewalls, MDM, identity platforms, email security, and cloud using Fortinet (preferred), Microsoft Active Directory, Microsoft 365, and Azure; hands-on experience with comparable firewalls such as Palo Alto is transferable.
  • Cloud security: Implement and manage cloud security controls in Microsoft Azure, focusing on identity and access management, network security, and data protection.
  • Secure network & server design: Partner hands-on with infrastructure teams to design and harden secure network and server configurations, including firewall, VPN, and access controls.
  • Endpoint & data protection: Own and maintain policy configurations for Proofpoint platforms Email Security, Email DLP, Endpoint DLP, and Data Security Posture Management (DSPM) tuning detection and prevention rules, triaging alerts, and refining controls to protect against phishing, malware, and data exfiltration.
  • Vulnerability management: Conduct regular vulnerability assessments using tools such as SecureWorks or Qualys, and coordinate remediation efforts with IT teams.
  • Incident response: Lead incident detection, investigation, containment, and recovery in collaboration with internal teams and external partners and operationalize threat intelligence to inform detection and response priorities.
  • Security automation: Develop scripts in PowerShell, Python, or Bash to automate routine security tasks and improve operational efficiency.
  • Third-party risk management: Own and drive the Client’s Third-Party Risk Management (TPRM) program end to end, including inbound and outbound security-questionnaire processes assessing vendor and partner security posture, maintaining the vendor risk-scoring framework, responding to security assessments received from partners and payers, and managing ongoing third-party risk in line with HIPAA and data-protection obligations.
  • Compliance & risk management: Ensure adherence to HIPAA and other regulatory requirements through policy enforcement and risk-mitigation strategies.
  • Documentation & training: Maintain detailed documentation of security configurations and procedures and provide guidance to business and IT staff on security best practices.
  • Security awareness training: Manage the Client’s security awareness training program building and scheduling campaigns and phishing simulations, tracking completion and results, and reporting on workforce risk to IT leadership.
  • Collaboration with MSSP: Serve as liaison with the Client’s Managed Security Service Provider to ensure effective threat monitoring and response.

Requirements

  • Infrastructure-focused security engineering background, able to both set strategy and execute hands-on.
  • Deep understanding of network security fundamentals, including TCP/IP, DNS, routing, and firewalls.
  • Hands-on experience with enterprise-grade firewalls and network security tools.
  • Proficiency in Microsoft Active Directory and Azure Active Directory (Microsoft Entra ID).
  • Strong knowledge of Azure cloud security best practices.
  • Experience with endpoint protection and data loss prevention (DLP) technologies, preferably Proofpoint tools.
  • Experience leading or running third-party risk / vendor security assessment processes.
  • Excellent problem-solving, communication, and collaboration skills, with the ability to work independently and across cross-functional teams.

Nice to Have

  • Microsoft Intune (MDM).
  • Scripting with PowerShell, Python, or Bash.
  • SIEM / XDR platforms such as Microsoft Sentinel or SecureWorks; experience with comparable platforms is transferable.
  • Experience working with MSSPs and vulnerability detection and response platforms.
  • Knowledge of healthcare compliance standards, including HIPAA and HITECH.
  • Experience managing security awareness training.
  • Experience with Okta MFA configuration., * Bachelor’s degree in Cybersecurity, Computer Science, or a related field.
  • Approximately 10+ years of security engineering experience, with demonstrated depth in infrastructure and cloud security.

CERTIFICATIONS AND LICENSES:

  • Preferred: CISSP; or at least one relevant security certification, such as Microsoft Certified: Azure Security Engineer Associate (AZ-500), CompTIA Security+, CISM, CCSP, or HCISPP.

Skills: Access Control, Bash Scripting, Best Practices, CCSP - Cisco Certified Security Professional, CISM - Certified Information Security Manager, Campaigns, Channel Strategies, Cloud Computing, CompTIA Security+, Computer Science, Computer Security, Cross-Functional, Customer Relations, DNS (Domain Name System), Email Management/Administration, Email Security, Endpoint Security, Firewall Administration, Firewalls, HIPAA (Health Insurance Portability and Accountability Act), Healthcare, Identity Data Management, Incident Response, Information/Data Security (InfoSec), Internet Security, Leadership, Loss Prevention, Maintain Compliance, Malware, Manufacturing Data Management, Microsoft Active Directory, Microsoft Windows Azure, Network Configuration Management, Network Design, Network Routing, Network Security, Operational Improvement, Operational Strategy, Phishing, Problem Solving Skills, Process Analysis, Protective Services, Python Programming/Scripting Language, Regulatory Compliance, Regulatory Requirements, Risk, Risk Analysis, Risk Management, Sales Management, Scorecarding, Scripting (Scripting Languages), Security Analysis, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Strategic Planning, Systems Administration/Management, TCP/IP (Transmission Control Protocol/Internet Protocol), Team Player, Technical Leadership, Training Program, VPN (Virtual Private Network), Vendor/Supplier Evaluation, Windows PowerShell

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all