Security Engineer

Birdi

Plymouth (MI)

Remote

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A Healthcare Technology Company is looking for a Security Engineer to lead their cybersecurity program. This role focuses on software supply chain security, IAM, and ensuring compliance with SOC 2 Type II and HIPAA regulations. Key responsibilities include designing security policies, conducting risk assessments, and managing security awareness training. Candidates should have experience in cybersecurity, knowledge of compliance frameworks, and a relevant degree. This is a full-time remote position that offers opportunities for significant impact in the healthcare sector.

Qualifications

  • Minimum 3-5 years of relevant cybersecurity experience.
  • Experience with SOC 2 and HIPAA compliance.
  • Knowledge of IAM principles and security auditing.

Responsibilities

  • Design and implement cybersecurity policies for SOC 2 Type II.
  • Conduct risk assessments and develop mitigation strategies.
  • Manage Identity and Access Management strategies.

Skills

Information Security experience
Cybersecurity Engineering
Compliance frameworks knowledge
Identity and Access Management
Incident response skills

Education

Bachelor's degree in Information Security or related field

Tools

IAM platforms
Endpoint protection solutions
AWS security tools

Job description

Position Summary

The Security Engineer is responsible for designing, implementing, and operating the organization’s cybersecurity program from the ground up, with a primary focus on software supply chain security, identity and access management (IAM), permissions architecture, and compliance readiness for SOC 2 Type II and HIPAA within a healthcare environment. This role leads the research, planning, and execution of security policies, technical controls, and operational processes that protect endpoints, cloud infrastructure, applications, and data throughout the full software development lifecycle (SDLC). The Security Engineer builds and maintains security monitoring, threat detection, and alerting systems, while establishing and managing a company-wide Security Awareness Training Program.

Essential Duties/Responsibilities
  • Research, develop, and implement comprehensive cybersecurity policies and procedures from the ground up to achieve and maintain SOC 2 Type II certification, including defining controls, gathering evidence, and coordinating with external auditors.
  • Conduct regular risk assessments and vulnerability analyses to identify potential security threats and develop mitigation strategies aligned with HIPAA requirements and industry best practices.
  • Design, implement, and manage Identity and Access Management (IAM) strategies, including role-based access control (RBAC), least privilege principles, multi-factor authentication (MFA), and single sign-on (SSO) solutions.
  • Establish and enforce software supply chain security practices, including Software Bill of Materials (SBOM) management, dependency scanning, vulnerability assessment, container security, and secure CI/CD pipeline integration.
  • Develop and maintain permissions governance frameworks, conducting regular access reviews and ensuring appropriate authorization levels across all systems handling PHI and sensitive data.
  • Maintain incident response procedures, including breach notification processes compliant with HIPAA requirements, and lead security incident investigations and remediation efforts.
  • Design, implement, and manage a comprehensive Security Awareness Training program for all workforce members, covering HIPAA requirements, phishing awareness, social engineering defense, and secure data handling practices.
  • Track and document training completion for all employees, maintaining records for audit purposes and ensuring ongoing education as cyberthreats evolve.
  • Collaborate with Development and DevOps teams to integrate security practices into the software development lifecycle (SDLC), including secure coding standards, code review processes, and automated security testing.
  • Evaluate and manage third-party vendor security risks, conducting security assessments and ensuring business associates comply with HIPAA and organizational security requirements.
  • Participate in an on-call rotation schedule for critical security incidents and support incident management processes for security-related events.
Required Skills/Abilities
  • Proven experience in Information Security, Cybersecurity Engineering, or a similar role with hands‑on experience implementing security programs and compliance frameworks.
  • Strong knowledge of compliance frameworks including SOC 2, HIPAA Security Rule, NIST Cybersecurity Framework, and CIS Controls, with experience preparing for and supporting audits.
  • Deep expertise in Identity and Access Management (IAM), including experience with IAM platforms, RBAC implementation, MFA, SSO, and privileged access management.
  • Experience with software supply chain security tools and practices, including SBOM generation, dependency scanning (e.g., Dependabot, Snyk), and secure CI/CD pipeline configuration.
  • Proficiency with endpoint protection solutions including EDR platforms, firewalls, and network security tools.
  • Strong understanding of cloud security principles and experience securing AWS
  • Excellent written and verbal communication skills, with the ability to translate complex security concepts for technical and non‑technical audiences.
  • Strong analytical, problem‑solving, and incident response skills with attention to detail.
  • Self‑directed individual capable of working independently to build programs from the ground up with minimal supervision.
Education/Experience
  • Bachelor's degree in information security, Computer Science, or related field; or equivalent combination of education and experience with at least 3‑5 years of relevant cybersecurity experience.
  • Demonstrated experience implementing security compliance programs (SOC 2, HIPAA, ISO 27001, or similar).
  • Experience conducting risk assessments and developing security policies and procedures.
Preferred Skill/Abilitie
  • Experience working within the Healthcare industry with direct knowledge of HIPAA compliance requirements and ePHI protection.
  • Industry certifications such as CISSP, CISM, Security+, CCSP, AWS Security Specialty, or HCISPP (Healthcare Information Security and Privacy Practitioner).
  • Experience with zero trust architecture design and implementation.
  • Familiarity with healthcare data standards (HL7, FHIR) and healthcare IT systems including EHR platforms.
  • Experience with policy-as-code tools (e.g., OPA, Checkov) and infrastructure-as-code security scanning.
  • Scripting and automation skills in Python, PowerShell, or Bash for security automation.
  • Experience with container security, Kubernetes security, and DevSecOps practices.
  • Experience with Security Awareness Training platforms (e.g., KnowBe4, Proofpoint) and phishing simulation tools.
Work Environment/Physical Requirements
  • This is a full‑time remote position.
  • Ability to sit for prolonged periods of time.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

U.S. Renal Care • Northern (KY)

Hybrid
USD 192,864,000 - 206,640,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Cyber Security Engineer – Full Time
Senior Cyber Security Engineer – Full Time

Jobtailor • Covina (CA)

On-site
USD 140,000 - 180,000
Security Engineer
Security Engineer

Healthmark Group • United States

Remote
USD 100,000 - 130,000
Cybersecurity Engineering Manager (JR229586)
Cybersecurity Engineering Manager (JR229586)

ViziRecruiter,LLC. • Village of Elmsford (NY)

On-site
USD 120,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Sr Security Engineer
Sr Security Engineer

The Timberline Group • St. Louis (MO)

On-site
USD 110,000 - 160,000
Cyber Security Consultant at The Planet Group Washington DC
Cyber Security Consultant at The Planet Group Washington DC

CDL Labor Logistics • Washington

Hybrid
USD 130,000 - 140,000
Hybrid work schedule
Onsite facility access
"Security Consultant"
"Security Consultant"

krg technology inc • Dearborn (MI)

On-site
USD 90,000 - 130,000