Network Security Engineer

MDVIP

Boca Raton (FL)

Hybrid

USD 110,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Great Place to Work since 2018
Competitive compensation
Comprehensive benefits
Professional development
Fostering collaboration

Job summary

MDVIP is seeking a Network Security Engineer in Boca Raton, FL, to own remediation, patch cycles, and hardening for on-prem and hybrid environments. You will oversee PKI, IAM/PAM tooling, and cloud security tooling while coordinating with security, DevOps, and audit teams.

The role supports 24/7 reliability and periodic travel to ATL; a strong background in enterprise security and governance is required.

Qualifications

  • Bachelors degree in CS/Info Security or related field; 5+ years in network security or infrastructure.
  • Experience with on-prem and cloud infrastructure, including vulnerability management and OS hardening.
  • Experience with PKI/SSL lifecycle management and IAM/PAM tools (BeyondTrust or equivalent).
  • Experience with security operations/SIEM and onboarding log sources; reliable syslog delivery.
  • Working knowledge of hybrid AD/Microsoft Entra ID and network segmentation tools (Illumio).
  • Experience supporting audit/remediation cycles (HIPAA, SRAs, pen tests).
  • Proficiency with firewalls and security appliances (Palo Alto, Fortinet, Cisco Meraki); SD-WAN.

Responsibilities

  • Execute remediation for findings from pen tests, SRAs, and HIPAA assessments with defined SLAs.
  • Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid servers.
  • Manage PKI/SSL lifecycle and key vault rotations for cloud-hosted apps.
  • Utilize automation to deploy machine certificates and manage syslog forwarding.
  • Administer network micro-segmentation using Illumio and enforce zero trust networks.
  • Review and harden edge security, including NGFW, SD-WAN, and NAC (ClearPass).
  • Manage Azure RBAC and AD hardening; coordinate with security/SIEM teams.
  • Support audit/compliance remediation and risk-reduction initiatives.

Skills

Analytical
Collaboration
Communication
Initiative
Problem solving
Troubleshooting
Travel

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

BeyondTrust
Illumio
Palo Alto
Fortinet
Cisco Meraki
Cisco switches
VMware
Azure
Microsoft Entra ID
CLEARPass

Job description

MDVIP: Transforming Primary Care, One Patient at a Time

MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work since 2018, MDVIP is committed to excellence in patient care and employee satisfaction.

Position Summary

The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers.

This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization’s on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations - including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score - while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule.

Security Remediation & Compliance
  • Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third-party resources to ensure timely delivery.
  • Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments.
  • Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere).
  • Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements.
  • Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score.
Core Platform & Infrastructure Ownership
  • Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders.
  • Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non-compliant certificates, and manage key vault rotations for critical cloud-hosted applications.
  • Utilize automation tools to deploy required machine certificates across the organization.
  • Manage syslog retention and forwarding across on-premises and cloud infrastructure, supporting the Security team’s SIEM ingestion, correlation, and compliance reporting needs.
  • Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning.
  • Review and administer security tools to harden network edge security, including next generation firewalls, SD-WAN, and switching, striving for zero trust networks.
  • Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass.
  • Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls.
  • Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices.
  • Review and secure SDLC servers and hosted applications, both on-premises and in Azure, applying measures to keep all public endpoints secure.
Operational Reliability & Risk Reduction
  • Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables.
  • Identify and reduce single-point-of-failure risk by documenting procedures and cross-training across PKI, AD, cloud access, segmentation, and patching functions.
  • Partner with the Azure DevOps and Security teams to align on-prem/hybrid remediation with broader cloud governance and security initiatives.
  • Escalate emerging risks, audit exceptions, and outage-driving conflicts between operational and remediation priorities to leadership.
Key Competencies
  • Analytical: synthesizes complex or diverse technical information, using intuition and experience to complement data.
  • Collaboration: openly partners with security operations, DevOps, and business stakeholders, valuing diverse perspectives and building productive relationships.
  • Communication: listens and responds effectively to stakeholder needs; writes and speaks clearly and persuasively.
  • Initiative and personal accountability: identifies and creates solutions independently, sets and meets deadlines, and reports timely and prepared.
  • Problem solving/decision making: thinks strategically, drawing on diverse sources to identify issues, risks, and trends and determine optimal, timely solutions.
  • Strong troubleshooting skills and the ability to manage competing priorities between reactive operational work and scheduled remediation projects.
  • Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours.
  • Ability to travel periodically between the Boca Raton, FL and Atlanta (ATL) data centers as needed.
Required Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or a related field; at least five (5) years of related business experience in network security, systems engineering, or infrastructure operations in an enterprise environment, or an equivalent combination of education and professional experience.
  • Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments.
  • Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent).
  • Experience partnering with security operations/SIEM teams to onboard new log sources and ensure reliable syslog delivery from network infrastructure.
  • Working knowledge of hybrid Active Directory/Microsoft Entra ID environments and familiarity with network segmentation concepts and tools (e.g., Illumio or comparable micro-segmentation platforms).
  • Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, and penetration test findings.
  • Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass).
  • This is a hybrid role based in Boca Raton, FL, with periodic on-site support required at the Boca Raton and Atlanta (ATL) data centers. At no time may work be performed, or computer systems accessed, from outside of the U.S.
Preferred Qualifications
  • Vendor-specific certifications, Microsoft Azure, Security+, CISSP, GIAC, or an equivalent security certification.
  • Scripting/automation experience (e.g., PowerShell) for remediation and hardening tasks.
Why Join MDVIP?
  • Be part of a mission-driven organization leading innovation in personalized healthcare.
  • Drive transformation and growth in a dynamic, fast-paced environment.
  • Competitive Compensation: Attractive base salary complemented by performance-based incentives.
  • Comprehensive Benefits: Health, dental, vision insurance, and retirement plans.
  • Professional Development: Access to ongoing training and leadership development programs.
  • Positive Work Environment: Consistently recognized as a Great Place to Work, fostering a culture of collaboration and excellence.

MDVIP is an Equal Opportunity Employer and is committed to fostering an inclusive and diverse workplace. We welcome applicants of all backgrounds and do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected status. We believe that diversity and inclusion drive innovation and strengthen our company culture.

If you require accommodations during the application or interview process, please let us know, and we will be happy to assist.

Pay Transparency: Our compensation reflects the cost of labor across appropriate US geographic markets. Pay is based on several factors including but not limited to market location and may vary depending on job-related knowledge, skills, and education/training and a candidate's work experience. Hired applicants are offered annual incentive compensation programs, subject to applicable eligibility requirements. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance. The company offers the following benefits for this position, subject to applicable eligibility requirements. Medical/prescription drug coverage, Dental coverage, Vision coverage, Flexible Spending Account, Health Savings Account, Dependent Care Flexible Spending Account, Basic and Supplemental Life Insurance & Accidental Death and Dismemberment, Disability Income Protection Plan, Employee Assistance Program, 401(k) retirement program, Vacation, Paid Holidays and Personal time, Paid Sick and Family and Medical Leave time as required by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Engineer
Network Security Engineer

MDVIP LLC • Boca Raton (FL)

Hybrid
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+3
Hybrid Network Security Engineer: On-Prem & Cloud
Hybrid Network Security Engineer: On-Prem & Cloud

MDVIP • Boca Raton (FL)

Hybrid
USD 110,000 - 160,000
Great Place to Work since 2018
Competitive compensation
Comprehensive benefits
+2
Manager, Marketing Operations
Manager, Marketing Operations

MDVIP LLC • Boca Raton (FL)

On-site
USD 110,000 - 150,000
Competitive base salary
Health, dental, vision insurance
401(k) retirement plan
+1
Network Engineer – VDI Security / Network Infrastructure
Network Engineer – VDI Security / Network Infrastructure

Staffed4U • Chantilly (VA)

On-site
USD 90,000 - 120,000
5 weeks PTO plus birthday leave
11 floating holidays
401(k) with 10% employer contribution
+3
16269 - Senior Cybersecurity Specialist - AZ - On Site
16269 - Senior Cybersecurity Specialist - AZ - On Site

Vensure Employer Solutions • Chandler (AZ)

On-site
USD 110,000 - 165,000
Health Insurance
401(k) with company match
Paid Time Off
+2
Clinical Program Manager
Clinical Program Manager

MDVIP • Boca Raton (FL)

Hybrid
USD 85,000 - 115,000
Health insurance
Dental insurance
Vision insurance
+2
Senior Technical Product Owner - Analytics
Senior Technical Product Owner - Analytics

MDVIP • Boca Raton (FL)

On-site
USD 140,000 - 190,000
Great Place to Work recognition
Health, dental, vision insurance
Professional development programs
Senior Cybersecurity Specialist - GA - On Site
Senior Cybersecurity Specialist - GA - On Site

Socket.dev • Duluth (GA)

On-site
USD 120,000 - 180,000
Health Insurance
401(k) Plan
Paid Time Off
Clinical Program Manager
Clinical Program Manager

MDVIP LLC • Boca Raton (FL)

On-site
USD 90,000 - 120,000
Health, dental, vision insurance
Retirement plans
Professional development
+1
Network Security Engineer
Network Security Engineer

Flybridge Staffing • Boca Raton (FL)

Hybrid
USD 100,000 - 140,000