Patient First is seeking a Security Engineer II to strengthen operational security and advance cloud-native security across Azure and Microsoft 365. The position combines security operations responsibilities with design-time governance, incident response support, and compliance-focused reporting in a hybrid environment.
Role Location
Glen Allen, VA (hybrid)
Salary
USD 125,000 - 150,000 per year, depending on experience.
Responsibilities
- Implement and maintain Microsoft Defender for Cloud, Azure Policy, security baseline controls, and cloud posture recommendations.
- Configure and support RBAC, Conditional Access, privileged access, and identity governance models for Azure and Microsoft 365.
- Maintain centralized logging, alerting, and monitoring pipelines for cloud workloads to support security investigations.
- Support security gates in deployment workflows, including policy validation, access review, and exception management.
- Provide security input during architecture reviews, workload intake, and production go-live readiness.
- Move security activities from after-the-fact validation into design-time and pipeline-integrated governance.
- Standardize cloud security baselines and reduce reliance on manual security validation.
- Translate existing security policies into Azure Policy, RBAC standards, and operational control requirements.
- Improve auditability by aligning monitoring, logging, access review, and compliance reporting with cloud workloads.
- Support security operations including firewall management, IDS/IPS, EDR, security monitoring, auditing, vulnerability management, and patch-related security coordination.
- Investigate alerts, participate in incident response, and support threat hunting, log review, and risk analysis.
- Assist with security reviews for applications, systems, third-party vendors, and hybrid cloud implementations.
- Support compliance activities related to HIPAA, PCI, access control, vulnerability remediation, and audit evidence.
- Communicate security risks and remediation recommendations to technical teams and business stakeholders.
Requirements
- Employee must be 18 years of age or older.
- High school diploma or equivalent.
- At least 3 years of experience in cybersecurity, security operations, cloud security, or hybrid infrastructure security roles.
- Experience with Azure security services, Microsoft Defender for Cloud, Sentinel or other SIEM tools, and identity concepts including RBAC and access control.
- Understanding of vulnerability management, logging, alerting, incident response, and expectations for compliance evidence.
- Working knowledge of hybrid environments including Windows/Linux systems, networking, firewalls, and SaaS/PaaS/IaaS security, plus Microsoft 365.
- Ability to communicate risk, remediation options, and control requirements across technical and non-technical audiences.
- Experience in regulated or compliance-driven environments; healthcare experience preferred.
- Knowledge of NIST, HIPAA, PCI, CIS, COBIT, or similar security frameworks.
- Azure Security Engineer Associate, CISSP, or comparable security certification.
- Experience with SIEM/SOAR, DLP, EDR, vulnerability scanning, and cloud security posture management tools.
Technologies
- Microsoft Defender for Cloud
- Azure Policy
- RBAC
- Conditional Access
- Microsoft 365
- Sentinel
- SIEM tools
- IDS/IPS
- EDR
- Windows
- Linux
- SaaS, PaaS, IaaS
- NIST, HIPAA, PCI, CIS, COBIT
- SIEM/SOAR
- DLP
- Vulnerability scanning
- Cloud security posture management tools
- Azure Security Engineer Associate
- CISSP
Benefits
- Health, Dental and Vision insurance for employees and dependents
- Disability, Life and Long Term care insurance
- Employee Assistance Program, Flexible Spending accounts, 401(k) Retirement Plan (with employer match)
- Paid Annual Leave, Volunteer Time Off Pay, Bereavement Leave, Emergency Leave Bank
- Overtime Pay, Holiday Pay, Double time compensation for all holidays worked
- Discounted medical treatment at any Patient First location for employees and immediate family
- Recruitment bonus
Minimum Education
High school diploma or equivalent