Senior Security Engineer
Senior
Azure
Cloud
Cloud Platform
Cloud Platforms
Cloud Security Posture Management
Cybersecurity Tools
Data Security
Endpoint Security
Engineer
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Network Security
Risk Management
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Job Description
HealthDrive is seeking a hands-on Senior Security Engineer to safeguard patient data across on-premises and Azure environments, build and operate security controls, lead incident detection and response, and manage third-party risk in partnership with a Managed Security Service Provider.
Responsibilities
- Architect and operate HealthDrive's security infrastructure across on premises and cloud, covering firewalls (Fortinet preferred), MDM, identity platforms, email security, and cloud controls; hands-on experience with comparable firewalls such as Palo Alto is transferable.
- Implement and manage Azure cloud security controls, with a focus on identity and access management, network security, and data protection.
- Collaborate with infrastructure teams to design and harden secure network and server configurations, including firewall, VPN, and access controls.
- Own and maintain policy configurations for Proofpoint platforms (Email Security, Email DLP, Endpoint DLP) and DSPM tuning, triage alerts, and controls to prevent phishing, malware, and data exfiltration.
- Conduct regular vulnerability assessments using tools such as SecureWorks or Qualys and coordinate remediation with IT teams.
- Lead incident detection, investigation, containment, and recovery in coordination with internal teams and external partners; operationalize threat intelligence to guide detection and response priorities.
- Develop scripts in PowerShell, Python, or Bash to automate routine security tasks and enhance operational efficiency.
- Own and drive HealthDrive's Third-Party Risk Management program end to end, including inbound and outbound security questionnaires, vendor risk scoring, responding to partner and payer assessments, and managing ongoing third-party risk in line with HIPAA and data protection obligations.
- Ensure HIPAA and other regulatory compliance through policy enforcement and risk-mitigation strategies.
- Maintain detailed documentation of security configurations and procedures; provide guidance on security best practices to business and IT staff.
- Oversee the security awareness training program, building campaigns and phishing simulations, tracking completion and results, and reporting workforce risk to IT leadership.
- Collaborate with HealthDrive's Managed Security Service Provider to ensure effective threat monitoring and response.
Requirements
- Infrastructure-focused security engineering background with the ability to set strategy and execute hands-on.
- Strong understanding of network security fundamentals including TCP/IP, DNS, routing, and firewalls.
- Hands-on experience with enterprise-grade firewalls and network security tools.
- Proficiency with Microsoft Active Directory and Azure Active Directory (Microsoft Entra ID).
- Solid knowledge of Azure cloud security best practices.
- Experience with endpoint protection and data loss prevention technologies, preferably Proofpoint.
- Experience leading or conducting third-party risk management and vendor security assessments.
- Excellent problem-solving, communication, and collaboration skills; able to work independently and across cross-functional teams.
- Education: Bachelor's degree in Cybersecurity, Computer Science, or a related field.
- Experience requirement: minimum 10 years in security engineering or a closely related role.
Technologies
- Fortinet
- Palo Alto
- Microsoft Active Directory
- Microsoft 365
- Azure
- Microsoft Entra ID
- Proofpoint
- Email Security
- Email DLP
- Endpoint DLP
- DSPM
- SecureWorks
- Qualys
- PowerShell
- Python
- Bash
- Microsoft Intune
- Microsoft Sentinel
- Okta
Compensation
Salary range: $85,000 - $115,000 per year, experience dependent. Location: Framingham, MA, hybrid work arrangement.