Overview
The Engineer I, Security is an entry level supporting role that will assist with day-to-day security engineering and operations work, helping maintain and improve security processes across systems and applications while learning from and collaborating with senior engineers and cross-functional partners.
Responsibilities
- Assist with day-to-day security engineering and operations work, helping maintain and improve security processes across systems and applications while learning from and collaborating with senior engineers and cross-functional partners.
- Assist in developing and maintaining security tools, documentation, and standards under senior engineer guidance.
- Support threat monitoring, triage, and analysis activities; escalation of potential security incidents following established procedures.
- Partner with application, infrastructure, and DevOps teams to track and remediate vulnerabilities across cloud and on-prem systems.
- Create and maintain operational runbooks; assist with SOC documentation and process updates.
- Configure and monitor alerts and dashboards in the SIEM platform with oversight; help validate tuning changes and document outcomes.
- Assist in supporting email, endpoint, and identity protections (configuration, monitoring, and basic troubleshooting).
- Help automate recurring tasks using Python, PowerShell, or other scripting languages; contribute to small automation improvements.
- Participate in incident response activities alongside the production IR team during security events; follow runbooks and contribute notes and evidence as needed.
- Contribute to knowledge sharing and cross-team learning through documentation, demos, or training sessions.
- Perform other duties that support the overall objective of the position.
Education and Experience Requirements
- Bachelor’s degree in Information Systems, Computer Science, or related discipline.
- Or combination of education and experience providing required qualifications.
- 1–3 years of experience (or relevant internships/co‑ops) in security operations, IT operations, systems administration, or related technical area.
Licensing and Certifications
- Security+ or similar foundational security certification preferred.
- CEH, SANS, ISC2, or cloud certifications (AWS, Azure, GCP) are a plus.
Knowledge, Skills & Abilities
- Foundational knowledge of security concepts and tools (e.g., SOC operations, SIEM, EDR, email threat protection, vulnerability management, cloud security).
- Basic scripting familiarity (Python or PowerShell) and willingness to learn automation practices.
- Awareness of MITRE ATT&CK, common attack techniques, and basic log analysis concepts.
- Strong analytical and troubleshooting skills.
- Clear communication and collaboration in team environments.
- Strong willingness to learn and ability to work as part of a team.
NextGen Healthcare is an equal opportunity employer.