Senior IT Security Engineer - Full Time, Days (Remote)

NOR HEALTHCARE SYSTEMS CORP
Bellflower, CA, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$145,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Layers Cyber Security Intrusion Detection and Prevention Intrusion Detection Systems Network Security Log Analysis Microsoft Security Essentials Network Monitoring Azure Active Directory Kusto Query Language Information Technology Security Auditing EndPointSecurity
+8 more
Azure Automation Microsoft Power Automate Mitre Att&ck Firewalls (Computer Science) Build Management Cybercrime Microsoft Sentinel SentinelOne Expertise

Job description

Assists in spearheading the development and enforcement of robust cybersecurity strategies, ensuring the highest level of security across all technological platforms. Leads threat prevention, detection, and remediation efforts for the organization., * Design and build robust security infrastructure that includes firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and secure network architectures. Ensure these measures are scalable and integrated seamlessly with existing systems.

  • Perform regular threat assessments to identify vulnerabilities within the network and application layers. Develop and implement strategies to mitigate identified risks, including the deployment of patches, updates, and security enhancements.
  • Lead the incident response team. Respond to security breaches and incidents with urgency, conduct thorough investigations to determine the root cause, and implement corrective actions to prevent future occurrences.
  • Administer security tools and technologies, ensuring they are optimized to detect and prevent malicious activities. Evaluate and recommend new security solutions to enhance defense capabilities.
  • Continuously monitor network traffic for unusual or suspicious activity. Use advanced network security tools to detect and block threats before they can infiltrate or damage the system.
  • Work closely with the IT department and other relevant teams to ensure security measures are aligned with organizational needs. Report on security posture, incidents, and ongoing risk assessments to senior management.

Requirements

Do you have experience in Threat hunting activities?, * 7+ years of progressive information security experience, with 4+ years in a SOC, threat detection, or incident response role

  • Deep expertise in Microsoft Security stack: Defender XDR, Defender for Endpoint (P2/E5), Defender for Identity, Microsoft Sentinel, and Log Analytics
  • Strong KQL proficiency for custom analytics, threat hunting, and workbook development
  • Hands-on experience with Entra ID / Azure AD, hybrid AD environments, and M365 security administration
  • Demonstrated experience leading incident response engagements from detection through post-incident reporting
  • Working knowledge of MITRE ATT&CK and its practical application to detection engineering
  • Familiarity with HIPAA Security Rule requirements and healthcare security operations context
  • Strong written communication skills; ability to produce clear incident reports and executive summaries, * Experience in a multi-org, multi-domain M365 tenant environment
  • Hands-on experience with Logic Apps / Azure Automation for SOAR playbooks
  • Familiarity with SentinelOne, Mimecast, Netwrix Auditor, or similar tooling in the NOR stack
  • Experience working alongside DFIR retainer providers (e.g., Kroll, Mandiant) during major incidents
  • Relevant certifications: MS-500, SC-200, SC-300, GCIH, GCFA, GDAT, CISSP, or equivalent
  • Healthcare vertical experience (hospitals, health systems, or covered entities under HIPAA)
  • Experience with BloodHound CE, Impacket, or similar AD security audit tooling

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all