Senior Security Engineer
Senior
Azure
Cloud
Cloud Platform
Cloud Platforms
Cloud Security Posture Management
Cybersecurity Tools
Data Security
Endpoint Security
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Network Security
Risk Management
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Windows Powershell
Job Description
Hands-on Senior Security Engineer safeguarding HealthDrive patient data and leading security controls across on-prem and Azure, incident response, and end-to-end third-party risk management with an MSSP.
Responsibilities
- Architect, configure, deploy, and operate security infrastructure including firewalls, mobile device management, identity platforms, email security, and cloud controls using Fortinet as the preferred platform with Microsoft Active Directory, Microsoft 365, and Azure; transferable experience with Palo Alto or other enterprise firewalls is acceptable.
- Deploy and maintain Azure cloud security controls with emphasis on identity and access management, network security, and data protection.
- Collaborate with infrastructure teams to design and harden secure network and server configurations, covering firewall rules, VPNs, and access controls.
- Manage policy configurations for Proofpoint Email Security, Email DLP, Endpoint DLP, and DSPM; tune detection and prevention rules, triage alerts, and refine controls to defend against phishing, malware, and data exfiltration.
- Perform regular vulnerability assessments with tools like SecureWorks or Qualys and coordinate remediation with IT teams.
- Lead incident detection, investigation, containment, and recovery in collaboration with internal teams and external partners; operationalize threat intelligence to guide detection and response priorities.
- Develop automation scripts in PowerShell, Python, or Bash to streamline routine security tasks and enhance efficiency.
- Lead HealthDrive's Third-Party Risk Management program end to end, including inbound and outbound security questionnaires, assessing vendor posture, maintaining the vendor risk-scoring framework, and handling security assessments from partners and payers in line with HIPAA and data protection obligations.
- Ensure HIPAA and other regulatory compliance through policy enforcement and risk mitigation strategies.
- Maintain comprehensive security configuration and procedure documentation and provide guidance to business and IT staff on security best practices.
- Oversee the security awareness training program, including campaigns and phishing simulations, tracking completion and results, and reporting workforce risk to IT leadership.
- Coordinate with HealthDrive's Managed Security Service Provider to ensure effective threat monitoring and response.
Requirements
- Infrastructure-focused security engineering background with both strategic planning and hands-on execution capabilities.
- Solid understanding of network security fundamentals including TCP/IP, DNS, routing, and firewall technologies.
- Hands-on experience with enterprise-grade firewalls and network security tools.
- Strong proficiency in Microsoft Active Directory and Azure Active Directory (Microsoft Entra ID).
- Strong working knowledge of Azure cloud security best practices.
- Experience with endpoint protection and data loss prevention technologies, preferably Proofpoint.
- Experience leading third-party risk or vendor security assessments.
- Excellent problem-solving, communication, and collaboration skills, with the ability to work independently and across cross-functional teams.
Technologies
- Fortinet (preferred); transferable experience with Palo Alto
- Microsoft Active Directory
- Microsoft Entra ID
- Microsoft 365
- Azure
- Proofpoint
- DSPM
- Email Security
- Email DLP
- Endpoint DLP
- SecureWorks
- Qualys
- PowerShell
- Python
- Bash
- Microsoft Intune
- Okta MFA
- Microsoft Sentinel
Work Environment
Based at HealthDrive’s Framingham, MA office (off Route 9, near Routes 90 and 495) on a hybrid schedule.
Compensation
Salary range: $85,000 to $115,000 per year, experience dependent.
Certifications & Licenses
Preferred: CISSP; or at least one relevant security certification such as Microsoft Certified: Azure Security Engineer Associate (AZ-500), CompTIA Security+, CISM, CCSP, or HCISPP.
Core Competencies
- Communication
- Cooperation and Team Working
- Adaptability
- Expertise and Professionalism
- Problem Solving / Analysis