> Markdown version of [/jobs/ext/3037440-it-security-manager](https://www.wearedevelopers.com/jobs/ext/3037440-it-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Manager - **Company:** Platinum Dermatology Partners - **Location:** Dallas, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Information Leak Prevention, Identity and Access Management, Phishing, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Cloud Platform System, Mitre Att&ck, Mttr, Microsoft Sentinel, Firewall Services Module, Splunk, Qualys, Vulnerability Analysis - **Published:** September 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ace855c44d38f5da ## About the Role * Bachelor's degree in Information Security, Cybersecurity, Information Systems, or related field, * 5-10 years of hands-on cybersecurity experience * 3+ years in healthcare or highly regulated industry required * Direct experience operating SIEM platforms (e.g., Splunk, Microsoft Sentinel) * Hands-on experience with XDR/MDR platforms (e.g., CrowdStrike, Sentinel One, Microsoft Defender) * Experience managing SOC workflows and alert triage * Experience securing cloud environments (Azure, AWS, Microsoft 365) * Strong understanding of HIPAA compliance requirements Technical Skills & Certifications: * SIEM configuration and log ingestion management * XDR / MDR implementation and optimization * SOC ticketing workflows and escalation procedures * Vulnerability management tools (Tenable, Rapid7, Qualys) * Email security and phishing detection * IAM, SSO, MFA, and privileged access management * Endpoint hardening and patch governance * AI risk monitoring and governance controls * Certifications: CISSP, CISM, CISA, CCSP, Security+, CRISC, CPHIMS, CHPS Soft Skills: * Excellent customer service and communication skills, with a patient, professional, and empathetic approach. * Ability to prioritize tasks and manage time effectively in a busy environment. * Strong problem-solving abilities and keen attention to detail., Physical Requirements: Must possess manual dexterity to operate office machines including computer and calculator; stooping and bending to handle files and supplies; and mobility to complete errands or deliveries. Includes handling of sharps and chemicals. ## Description In the performance of their respective tasks and duties, all employees are expected to conform to the following: * Perform quality work within deadlines with or without direct supervision. * Interact professionally with other employees, customers, and suppliers. * Work effectively as a team contributor on all assignments. * Work independently while understanding the necessity for communicating and coordinating work efforts with other employees and organizations., The IT Security Manager is a working leader responsible for directly operating, configuring, and securing the organization's cybersecurity infrastructure across a multi-site healthcare environment. This role is hands-on and execution focused, owning day to day security operations while building a scalable security program. The ideal candidate has strong technical depth in XDR, MDR, SOC operations, SIEM administration, endpoint security, cloud security, and AI-enabled security tools. This individual will actively configure systems, investigate alerts, respond to incidents, and drive remediation efforts, not simply oversee them., * Act as primary owner of SIEM, XDR, and MDR platforms * Monitor and tune alerting thresholds to reduce noise and improve detection accuracy * Investigate security alerts, perform root cause analysis, and lead incident responses * Conduct threat hunting using MITRE ATT&CK framework methodologies * Manage endpoint detection and response (EDR) tools across all locations * Maintain vulnerability scanning programs and coordinate patch remediation Incident Response & Risk Mitigation: * Lead real-time incident triage and containment activities * Develop and maintain incident response playbooks * Coordinate forensic investigations and external cybersecurity partners when required * Document all incidents and produce executive summaries AI & Emerging Technology Security: * Evaluate and secure AI tools used in clinical, revenue cycle, and operational workflows * Assess data leakage risks associated with generative AI platforms * Implement monitoring controls for AI-driven automation systems * Participate in AI governance initiatives and enforce approved AI usage policies Identity, Network & Cloud Security: * Manage identity and access management (IAM), MFA enforcement, and privileged access controls * Implement and maintain Zero Trust architecture principles * Oversee firewall rules, email security, and endpoint hardening * Secure Microsoft 365, Azure, AWS, or other cloud environments * Conduct periodic access reviews and audit log monitoring Compliance & Healthcare Security: * Maintain HIPAA Security Rule safeguards (Administrative, Physical, Technical) * Support internal and external audits * Conduct periodic security risk assessments * Manage Business Associate Agreement (BAA) security reviews Security Engineering & Continuous Improvement: * Implement security automation workflows * Improve mean time to detect (MTTD) and mean time to respond (MTTR) * Run phishing simulations and security awareness campaigns * Develop metrics dashboards for executive reporting ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)