Sr Information Security Engineer

Baylor Genetics
United States
12 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software System Penetration Testing User Authentication Microsoft Azure Cloud Computing Security Cyber Security Information Leak Prevention Identity and Access Management Intrusion Detection Systems Network Security Performance Tuning Systems Development Life Cycle
+10 more
Cloud Services Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Cloud Platform System Data Classification In-Plane Switching (IPS) Firewalls (Computer Science) Information Technology Microsoft Sentinel

Job description

Baylor Genetics is seeking a Senior Information Security Engineer to serve as a senior technical leader within our Information Security team. As one of the nation’s leading clinical genetic testing laboratories, we safeguard some of the most sensitive data that exists - patient genomic and health information - and this role is critical to protecting it.

Reporting to the Director of Information Security, the Senior Information Security Engineer designs, implements, and operates the security controls that protect Baylor Genetics’ systems, networks, endpoints, and cloud environments. This role leads key operational security initiatives - including managed detection and response (MDR/SIEM), privileged access management, vulnerability management, and Zero Trust - and provides technical mentorship to other engineers. Scope may evolve as organizational needs change.

KEY RESPONSIBILITIES

Lead and operate the organizational detection and response capabilities, including SIEM/MDR and EDR/XDR, and SOAR (e.g., CrowdStrike or Microsoft Sentinel), tuning detections with organization specific policies and response actions.

Establish and mature a centralized, risk-based vulnerability management program with enforced patch SLAs, secure configuration baselines, and remediation of penetration test findings.

Design and implement identity and access security controls, including Privileged Access Management (PAM), Just-in-Time (JIT) access, MFA, SSO, Conditional Access, and least-privilege .

Advance the Zero Trust roadmap across identity, endpoints, networks, cloud, and data.

Respond to and investigate security incidents end to end - detection, containment, investigation, and recovery - in line with the incident response playbook, and lead post-incident reviews.

Implement and manage data protection controls for PHI/PII, including auto-classification and DLP (e.g., Microsoft Purview) across endpoints and cloud services.

Collaborate with IT, Privacy, Compliance, and application teams to embed security best practices into system designs, cloud deployments, and the SDLC.

Requirements

Required

Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field - or an equivalent combination of education and experience.

Minimum of 6-8 years of experience in information security engineering, security operations, or a related discipline.

Hands-on expertise with SIEM/MDR and EDR platforms (e.g., CrowdStrike, Microsoft Sentinel) and security event monitoring, triage, and tuning.

Strong knowledge of network security, firewalls, IDS/IPS, cryptography, authentication, and authorization principles.

Experience with vulnerability management, penetration test remediation, incident response, and endpoint/OS hardening.

Working knowledge of cloud security (Azure and/or AWS) and identity platforms (SSO, MFA, conditional access).

Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, HITRUST, NIST, and GDPR.

Excellent written and verbal communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.

Preferred

Advanced certifications such as CISSP, CISM, GCIA, GCIH, or a cloud security specialty (e.g., Azure/AWS Security).

Experience with privileged access management (PAM), SOAR, and Zero Trust architectures.

Familiarity with data loss prevention (e.g., Microsoft Purview) and data classification programs.

Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment.

COMPETENCIES

Strong analytical and problem-solving skills with a risk-based, outcome-driven mindset.

Sound judgment and composure when responding to security incidents under pressure.

Collaborative, cross-functional approach with the ability to influence peers and mentor others.

Self-directed, detail-oriented, and able to prioritize competing demands in a fast-moving environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · World Congress 2026 Europe

Videos

See all

Related articles

See all