> Markdown version of [/jobs/ext/543509-senior-it-security-engineer-full-time-days-remote](https://www.wearedevelopers.com/jobs/ext/543509-senior-it-security-engineer-full-time-days-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IT Security Engineer - Full Time, Days (Remote) - **Company:** NOR HEALTHCARE SYSTEMS CORP - **Location:** Bellflower, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $145,000.0 - **Contract:** Permanent contract - **Skills:** Application Layers, Cyber Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Log Analysis, Microsoft Security Essentials, Network Monitoring, Azure Active Directory, Kusto Query Language, Information Technology Security Auditing, EndPointSecurity, Azure Automation, Microsoft Power Automate, Mitre Att&ck, Firewalls (Computer Science), Build Management, Cybercrime, Microsoft Sentinel, SentinelOne Expertise - **Published:** June 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2651ee8b27333cfd ## About the Role Do you have experience in Threat hunting activities?, * 7+ years of progressive information security experience, with 4+ years in a SOC, threat detection, or incident response role * Deep expertise in Microsoft Security stack: Defender XDR, Defender for Endpoint (P2/E5), Defender for Identity, Microsoft Sentinel, and Log Analytics * Strong KQL proficiency for custom analytics, threat hunting, and workbook development * Hands-on experience with Entra ID / Azure AD, hybrid AD environments, and M365 security administration * Demonstrated experience leading incident response engagements from detection through post-incident reporting * Working knowledge of MITRE ATT&CK and its practical application to detection engineering * Familiarity with HIPAA Security Rule requirements and healthcare security operations context * Strong written communication skills; ability to produce clear incident reports and executive summaries, * Experience in a multi-org, multi-domain M365 tenant environment * Hands-on experience with Logic Apps / Azure Automation for SOAR playbooks * Familiarity with SentinelOne, Mimecast, Netwrix Auditor, or similar tooling in the NOR stack * Experience working alongside DFIR retainer providers (e.g., Kroll, Mandiant) during major incidents * Relevant certifications: MS-500, SC-200, SC-300, GCIH, GCFA, GDAT, CISSP, or equivalent * Healthcare vertical experience (hospitals, health systems, or covered entities under HIPAA) * Experience with BloodHound CE, Impacket, or similar AD security audit tooling ## Description Assists in spearheading the development and enforcement of robust cybersecurity strategies, ensuring the highest level of security across all technological platforms. Leads threat prevention, detection, and remediation efforts for the organization., * Design and build robust security infrastructure that includes firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and secure network architectures. Ensure these measures are scalable and integrated seamlessly with existing systems. * Perform regular threat assessments to identify vulnerabilities within the network and application layers. Develop and implement strategies to mitigate identified risks, including the deployment of patches, updates, and security enhancements. * Lead the incident response team. Respond to security breaches and incidents with urgency, conduct thorough investigations to determine the root cause, and implement corrective actions to prevent future occurrences. * Administer security tools and technologies, ensuring they are optimized to detect and prevent malicious activities. Evaluate and recommend new security solutions to enhance defense capabilities. * Continuously monitor network traffic for unusual or suspicious activity. Use advanced network security tools to detect and block threats before they can infiltrate or damage the system. * Work closely with the IT department and other relevant teams to ensure security measures are aligned with organizational needs. Report on security posture, incidents, and ongoing risk assessments to senior management. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)