IT Security Engineer II

MedImpact Healthcare Systems Inc.

San Diego (CA)

On-site

USD 110,982 - 199,769

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision, and Wellness
401K with Company match
PTO and Holidays
Incentive Compensation
Life and Disability Insurance
Tuition Reimbursement
Employee Referral Bonus

Job summary

MedImpact Healthcare Systems Inc. in San Diego seeks an Information Security Engineer II to develop, execute, and monitor enterprise security across SECOPS, DEVSECOPS, and Threat Analytics.

This hands-on role acts as process owner for security activities, enforcing policies, improving tooling, and coordinating with IT and business units to protect data. On-site work at the San Diego headquarters; requires BS/BA and 8+ years of experience with Windows/Linux security, IAM, EDR, and vulnerability

Qualifications

  • BS/BA and 8+ years of experience in information security, including 4+ years in subject areas.

Responsibilities

  • Develop, execute, and monitor enterprise-wide information security across SECOPS, DEVSECOPS, and Threat Analytics.
  • Enforce policy and support security procedures, and document resolutions for cases.
  • Lead security tooling automation and coordinate with IT and business units.

Skills

Analytical skills
Communication
Team collaboration
Regulatory awareness

Education

BS/BA

Tools

EDR
IAM
Vulnerability management
Windows security
Linux security

Job description

Job Description

The Information Security Engineer II develops, executes, and monitors enterprise-wide information security from policy through implementation across all Security departments including SECOPS, DEVSECOPS, and Threat Analytics. This "hands‑on" position serves as the process owner for all ongoing security activities and is responsible for protecting the confidentiality and integrity of client, employee, and proprietary business information in accordance with federal/state laws and regulations.

Essential Duties and Responsibilities
  • Enforces policy and supports security procedures, applications, and systems through the documentation of the resolution of assigned cases that range from simple to complex.
  • Recommends changes to existing security process and procedures.
  • Utilizes Endpoint Threat Detection, Response, and Hunting toolsets.
  • Creates requirements for product evaluations and/or procedures to enhance productivity and effectiveness.
  • Provides direct support to the business and IT staff for security‑related issues.
  • Drives the delivery of new and upgraded security applications, systems, and workflows.
  • Tests new systems for effective operations.
  • Leads efforts to proactively maintain and improve the automation, reliability, consistency, and quality of existing IT security tools and environments.
  • Assists in the design, deployment, integration, and configuration of security solutions or enhancements to ensure functionality.
  • Ensures the confidentiality, integrity, and availability of data residing on or transmitted to, from, or through the enterprise workstations, servers, application systems, and data repositories.
  • Initiates, facilitates, and promotes activities to create information security awareness.
  • Disseminates and educates users on security policies and practices.
  • Participates in regular security awareness training and updates to ensure consistent compliance with IT Security Policies.
  • Works cross‑functionally and interacts with internal business units and stakeholders to support the business’s needs.
  • Tracks and documents security service requests and completed cases using an automated customer case request system.
  • Participates in daily activities and reporting required for regulatory and contractual information security obligations.
  • Coordinates tasks performed within the infrastructure (system administration, network administration, application support, etc.) for security updates and initiatives.
  • Performs analysis, design, and development of security features for system architecture.
  • Participates in security incident investigations and provides ongoing communication to security management.
  • Identifies root causes of security events and proposes solutions; closes out and documents investigations.
  • Maintains up‑to‑date industry knowledge through formal/informal training, industry associations, and research of latest technologies critical to the success of the company’s information security program.
  • Continuously works to identify and improve security solutions to defend the company against data security threats.
  • Applies appropriate mitigation strategies and communicates security issues to management.
  • Provides guidance/training to less experienced staff.
  • Provides IT Security consultative support to internal and external clients.
  • Manages IT Security related projects and assignments as assigned.
  • Applies appropriate security architecture frameworks and standards.
Client Responsibilities
  • Internal and external client facing position that requires excellent customer service skills and interpersonal communication skills.
  • Manages difficult or emotional client situations, responds promptly to client needs, solicits client feedback, and meets commitments to clients.
Qualifications
  • BS/BA and 8+ years of experience (or equivalent combination of education and experience), including 4 years of subject‑matter expertise in respective areas.
Computer Skills
  • Microsoft Office Suite.
  • Endpoint Management (BigFix, WSUS/SCCM, Symantec, Trend Micro, etc.).
  • Identity and Access Management.
  • Certificate Management.
  • Patch Management (Windows and Unix).
  • Intrusion Detection and Prevention.
  • Security Awareness Training.
  • Mobile Device Management.
  • Endpoint Detection and Response (EDR).
  • Web Content Filtering.
  • Device Encryption.
  • Vulnerability Assessment Tools.
  • Firewall and VPN.
  • Secure E‑mail, Anti‑SPAM.
  • Web Server applications.
  • Web API Service Security.
  • Business Continuity (Disaster Recovery).
  • Compliance and Audit (HIPAA, HITRUST, SOC, GovRAMP, PCI – a plus).
  • OS Administration (Windows, Linux, Unix).
  • Authentication and SSO.
  • Container Security.
  • Certificates, Licenses, Registrations.
  • Security Certification preferred (OWASP, ISSA, ISACA membership – a plus).
Other Skills and Abilities
  • Excellent analytical, problem‑solving, and communication skills.
  • Familiarity with SSAE SOC 1 and SOC 2, HITRUST, federal/state security and privacy frameworks, HIPAA, PCI and regulatory requirements for information security.
  • Ability to work on a team and build good working relationships with team members and internal clients.
  • Good understanding of standard policies and procedures for information security.
  • Reasoning Ability – ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists.
  • Ability to define problems, collect data, establish facts, and draw valid conclusions.
  • Mathematical Skills – ability to apply concepts such as fractions, percentages, ratios, and proportions to practical situations; add, subtract, multiply, and divide in all units of measure; compute rate, ratio, and percent; draw and interpret bar graphs.
  • Language Skills – ability to respond to common inquiries or complaints from customers, regulatory agencies, or members of the business community; respond effectively to the most sensitive inquiries or complaints.
Competencies
  • Composure
  • Decision Quality
  • Organizational Agility
  • Problem Solving
  • Customer Focus
  • Drive for Results
  • Peer Relations
  • Time Management
  • Dealing with Ambiguity
  • Learning on the Fly
  • Political Savvy
Physical Demands

Regularly required to sit, talk or hear, stand, walk, use hands to handle and reach, and occasionally lift up to 25 pounds.

Work Environment

Common office setting with computers and printers; moderate noise level; exposure to moving mechanical parts, chemicals, outdoor weather conditions, and risk of electrical shock or vibration.

Work Location

On‑site at the San Diego Headquarters for direct support to internal clients; no remote work.

Working Hours

Exempt; flexible hours to meet deadlines, including nights, weekends, or holidays when required. Core business hours Monday‑Friday 8:00am‑5:00pm.

Travel

Domestic travel up to 10% of time.

Perks
  • Medical, Dental, Vision, and Wellness Programs.
  • Paid Time Off and Company Paid Holidays.
  • Incentive Compensation.
  • 401K with Company match.
  • Life and Disability Insurance.
  • Tuition Reimbursement.
  • Employee Referral Bonus.
Equal Opportunity Employer

Equal Opportunity Employer, Male/Female/Disabilities/Veterans. OSHA/ADA: Reasonable accommodations may be provided to enable individuals with disabilities to perform essential functions.

Salary

US$110,982 – $155,376 – $199,769 (based on experience).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer II
IT Security Engineer II

MedImpact Healthcare Systems, Inc. • San Diego (CA)

On-site
USD 110,000 - 200,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
IT Security Engineer II
IT Security Engineer II

Medimpact • San Diego (CA)

On-site
USD 110,000 - 200,000
Medical / Dental / Vision / Wellness
Paid Time Off
401K with Company match
+3
Information Security Analyst 1
Information Security Analyst 1

Reliance, Inc. • Cypress (CA), Northern (KY)

Hybrid
USD 80,000 - 85,000
Systems Engineer - Security
Systems Engineer - Security

PAE Government Services Inc. • Columbia (MD)

On-site
USD 155,000 - 175,000
Health, dental, and vision insurance
Paid time off
Retirement benefits (401(k) matching)
+1
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Manager, Cyber Security - US
Senior Manager, Cyber Security - US

Pace Industries, LLC • San Antonio (TX)

Hybrid
USD 148,011 - 217,082
Incentive compensation
Employee Stock Purchase Plan (ESPP)
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Security Consultant - Endpoint
Security Consultant - Endpoint

SHI • Columbus (OH)

On-site
USD 110,000 - 145,000
Diversity & inclusion
Growth opportunities
Health benefits
+1
Security Engineer II (Only USC/GC)/ Onsite-Hybrid
Security Engineer II (Only USC/GC)/ Onsite-Hybrid

TalentBridge • Skokie (IL)

Hybrid
USD 90,000 - 130,000
Retirement plan with company match
Tuition reimbursement
Medical, dental, vision, and pet-insur
+2
Cybersecurity/Info Security Engineer (Remote- 130K)
Cybersecurity/Info Security Engineer (Remote- 130K)

Merit Personnel & Consulting • New York (NY)

Remote
USD 117,000 - 143,000