EngineerJobs.io
← Back to all jobs

Job Description

Senior Security Engineer role in Framingham, MA (hybrid) focused on protecting HealthDrive patient data across on premises and Azure, building and operating security controls, and coordinating incident detection and response with MSSP collaboration.

Responsibilities

  • Security infrastructure management: design, configure, deploy, and maintain security infrastructure including firewalls, MDM, identity platforms, email security, and cloud controls, primarily using Fortinet; experience with Palo Alto is transferable.
  • Cloud security: implement and manage Azure security controls with emphasis on identity and access management, network security, and data protection.
  • Secure network and server design: collaborate with infrastructure teams to design and harden secure network and server configurations, including firewall, VPN, and access controls.
  • Endpoint and data protection: own policy configuration for Proofpoint platforms (Email Security, Email DLP, Endpoint DLP) and DSPM; tune detection and prevention rules, triage alerts, and refine controls to prevent phishing, malware, and data exfiltration.
  • Vulnerability management: conduct regular vulnerability assessments using tools such as SecureWorks or Qualys, and coordinate remediation with IT teams.
  • Incident response: lead detection, investigation, containment, and recovery in collaboration with internal teams and external partners; operationalize threat intelligence to shape detection and response priorities.
  • Security automation: develop scripts in PowerShell, Python, or Bash to automate routine security tasks and improve operational efficiency.
  • Third-party risk management: own and drive HealthDrive’s Third-Party Risk Management program end to end, including inbound and outbound security questionnaires, assessing vendor security posture, maintaining the vendor risk-scoring framework, responding to security assessments from partners and payers, and managing ongoing third-party risk in line with HIPAA requirements.
  • Compliance and risk management: ensure HIPAA and other regulatory compliance through policy enforcement and risk mitigation strategies.
  • Documentation and training: maintain detailed security configurations and procedures; provide guidance to business and IT staff on security best practices.
  • Security awareness training: manage the security awareness program, building campaigns and phishing simulations, tracking completion and results, and reporting workforce risk to IT leadership.
  • Collaboration with MSSP: act as liaison with HealthDrive’s Managed Security Service Provider to ensure effective threat monitoring and response.

Requirements

  • Infrastructure focused security engineering background with the ability to set strategy and execute hands-on.
  • Strong understanding of network security fundamentals including TCP/IP, DNS, routing, and firewalls.
  • Hands-on experience with enterprise-grade firewalls and network security tools.
  • Proficiency in Microsoft Active Directory and Azure Active Directory (Microsoft Entra ID).
  • Solid knowledge of Azure cloud security best practices.
  • Experience with endpoint protection and data loss prevention technologies, preferably Proofpoint.
  • Experience leading or running third-party risk and vendor security assessment processes.
  • Excellent problem solving, communication, and collaboration skills; ability to work independently and across cross-functional teams.
  • Educational and experience requirements: Bachelor’s degree in Cybersecurity, Computer Science, or related field; minimum 10 years of security engineering experience.

Technologies

  • Fortinet, Palo Alto
  • Microsoft Active Directory, Microsoft Entra ID
  • Microsoft 365, Azure
  • Proofpoint, Email Security, Email DLP, Endpoint DLP, DSPM
  • SecureWorks, Qualys
  • PowerShell, Python, Bash
  • Microsoft Intune, Microsoft Sentinel, Okta

Compensation

  • USD 85,000 - 115,000 per year, experience dependent

Similar Jobs