Information Security Engineer
Job Description
LCS is hiring an Information Security Engineer to oversee user access and identity operations and to plan and execute security measures that protect LCS networks and systems.
Responsibilities
- Administer and manage IT security technologies including Microsoft Entra, Okta identity management, vulnerability management, spam email technology, simulated phishing technology, and generative AI solutions
- Own the user access lifecycle for corporate associates, community associates, contractors, consultants, and third-party vendors including provisioning, modifications, transfers, and terminations
- Ensure access to business and clinical applications aligns with job responsibilities, least-privilege principles, and established security standards
- Run periodic user access reviews and certification campaigns for critical senior living systems covering financial, resident management, healthcare, and human resources
- Monitor security alerts, suspicious activity, and system-generated events to identify threats impacting LCS communities, corporate operations, or resident information
- Administer and support enterprise security solutions such as endpoint protection, email security, vulnerability management, identity protection, device management, and security monitoring platforms
- Partner with Infrastructure and Application teams to remediate vulnerabilities, implement security hardening recommendations, and maintain secure configurations
- Participate in investigations related to suspected incidents including unauthorized access attempts, phishing attacks, malware infections, or policy violations
- Conduct security risk assessments for new technologies, business initiatives, acquisitions, community transitions, and third-party vendor solutions
- Support due diligence and integration activities for community acquisitions, management changes, and new community openings
- Develop and maintain information security policies, standards, procedures, and access governance practices
- Assist with business continuity and disaster recovery planning to support operations across LCS-managed communities
- Support internal audits, external audits, and regulatory assessments by documenting controls, collecting evidence, and responding to audit requests
- Educate associates and business partners on cybersecurity risks, security policies, and best practices to protect resident and organizational information
- Research emerging cybersecurity threats and recommend enhancements to strengthen organizational controls
- Maintain documentation for security systems, access management processes, operational procedures, and technical standards
- Perform other duties and responsibilities as assigned
Requirements
- Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent year of experience
- 6+ years of related experience
- In-depth knowledge of security best practices, data protection, and regulatory compliance
- Excellent problem-solving skills and ability to troubleshoot complex issues
- Strong communication and interpersonal skills to collaborate with diverse teams and stakeholders
Technologies
- Microsoft Entra
- Okta identity management
- Vulnerability management
- Spam email technology
- Simulated phishing technology
- Generative AI solutions
- Endpoint protection
- Email security
- Identity protection
- Device management
- Security monitoring platforms
Preferred Qualifications
- Relevant industry certifications such as CISSP, CISM, CompTIA Security+, or vendor-specific identity certifications
Travel
- 0-10%
Compensation
- Estimated salary: $98,000 - $122,000 per year
Benefits
- Competitive pay
- Great benefits and vacation time
- Medical
- Dental
- Life insurance
- Disability
- 401(K) with company match
- Paid parental leave