Information Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
This is a hands-on role for an experienced professional who can make an impact from day one. You’ll partner closely with Infrastructure, Engineering, Product, Privacy, Compliance, Legal, and senior leadership in a fast-paced, collaborative environment.
What You’ll Do
- Develop, tune, and maintain threat detections across cloud, endpoint, network, application, and container environments.
- Investigate, prioritize, and resolve security alerts, and initiate and coordinate incident response when appropriate.
- Scope, contain, eradicate, and document security incidents, including root-cause analysis, forensics, postmortems, and lessons learned.
- Deploy and support security telemetry and response platforms, including SIEM, EDR, NDR, MDR, threat intelligence, and SOAR tools.
- Design and implement security controls across cloud, network, and application layers.
- Improve vulnerability management, vulnerability scanning, secrets management, patching, and security-control maintenance.
- Apply an AI-first mindset to security automation and threat detection.
- Partner with Privacy and Compliance to document and monitor security practices in support of HITRUST, SOC 2, and other compliance initiatives.
Requirements
- Senior-level security experience. You can jump in immediately and work independently with minimal ramp-up.
- 3+ years of hands-on cloud security experience. AWS is required.
- Experience with SIEM, EDR, MDR, vulnerability scanning, secrets management, and security-automation tools.
- Strong knowledge of vulnerabilities, exploits, threat detection, and incident-response techniques.
- Understanding of authentication protocols and frameworks such as OAuth, SSO/SAML, and OpenID Connect.
- Experience with Zero Trust architectures.
- Knowledge of cybersecurity frameworks, including HITRUST, NIST, and ISO.
- Strong communication skills and the ability to influence cross-functional teams.
- Ability to manage multiple priorities and see work through to completion.
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
Nice to Have
- Experience with CrowdStrike, Okta, KnowBe4, Datadog, GuardDuty, CloudWatch/CloudTrail, Trusted Advisor, WAF and firewall configuration, Jamf, and Island.io enterprise browser.
- Certifications such as CISSP, AWS Security Specialty, AWS Cloud Practitioner, CompTIA Network+, SC-900, or AZ-900, or equivalent experience.
Success in This RoleSuccess means improving our client’s ability to prevent, detect, investigate, and respond to threats, while making secure development practices easier for engineering teams to adopt.
About the company
About the RoleOur client, a growing healthcare technology company, is seeking a senior Information Security Engineer for a short-term contract engagement. The company operates in a highly regulated environment: it is HIPAA compliant, is pursuing HITRUST certification, has SOC 2 in progress, and may pursue FedRAMP/GovRAMP. A strong security foundation is already in place. This role will maintain and evolve that posture by strengthening detection, operations, incident response, cloud security, and secure development practices.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Fully Remote Software Engineer Jobs
Understanding and Mitigating Common Web Vulnerabilities
Is Software Engineering Over-Saturated?