Senior Platform & Security Engineer

Highlight Health

Philadelphia (Philadelphia County)

On-site

USD 140,000 - 180,000

Full time

46 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Highlight Health is seeking a Senior Platform and Security Engineer to own the Azure infrastructure, IT operations, and security controls that underpin our PHI-handling Claims Intelligence Platform. This hands‑on role collaborates with engineering and leadership on SOC 2 Type 2 and HIPAA audit readiness.

You will manage Azure resources, DevOps pipelines, and security tooling across development, UAT, and production, driving reliability and compliance for a fast‑growing, mission‑driven company.

Qualifications

  • 7–10 years of experience in cloud platform engineering, DevOps, or infrastructure security.
  • Hands‑on Azure production experience across the full service lifecycle.
  • Practical experience implementing technical controls for HIPAA and SOC 2 Type 2.
  • Fluent in Entra ID: conditional access, MFA, role assignments, and identity governance.
  • Applies appropriate safeguards for PHI, including PHI‑safe logging and least‑privilege access controls.
  • Comfortable owning IT operations end‑to‑end: M365, SaaS administration, and employee access management.

Responsibilities

  • Own infrastructure for all Azure resources across development, UAT, and production environments.
  • Manage and evolve Azure DevOps pipelines for build, test, and deployment.
  • Operate Azure Container Apps, App Service, Service Bus, PostgreSQL Flexible Server, Blob Storage, and supporting services.
  • Maintain Azure Key Vault including secrets rotation and least‑privilege access.
  • Configure and tune Application Insights and Log Analytics with PHI‑safe logging pipelines.
  • Administer Microsoft Fabric, including governance, capacity management, access controls, and data integration oversight.
  • Implement and maintain technical controls in support of SOC 2 Type 2 and HIPAA.
  • Administer Entra ID including conditional access policies, MFA enforcement, and identity governance.
  • Audit preparation, evidence collection, and control documentation with leadership.
  • Incident response readiness, tabletop exercises and runbooks.
  • Manage logging and alerting with Microsoft Purview and Microsoft Sentinel.
  • Maintain security posture through vulnerability management and access reviews.
  • Own Office 365 administration, SharePoint, and SaaS tool management.
  • Serve as internal technical authority on endpoint security and device management.
  • Evaluate and onboard new tooling with a bias toward security and simplicity.

Skills

Azure
DevOps
Security engineering
PHI data handling
Entra ID

Tools

Azure DevOps
Azure Container Apps
App Service
Service Bus
PostgreSQL Flexible Server
Key Vault
Application Insights
Log Analytics
Microsoft Defender
Microsoft Sentinel
Purview
M365

Job description

Highlight Health is a mission-driven company that protects consumer rights and controls healthcare costs exclusively for self-funded employers and their stop loss carriers. We are a profitable, fast-growing company without private equity investors.

We are currently building a sophisticated, proprietary Claims Intelligence Platform — a system of record handling protected health information (PHI) and generating financial recommendations with real-world legal and economic weight. Security, compliance, and platform reliability are not afterthoughts here; they are first-class engineering concerns.

We are looking for a Senior Platform and Security Engineer to own the Azure infrastructure, IT operations, and technical implementation of security controls that underpin this platform. This is a hands‑on individual contributor role with a potential path toward team leadership as the company grows. You will work closely with the engineering team on platform changes and directly with leadership on SOC 2 Type 2 and HIPAA audit preparation.

If you want technical ownership of a platform where the stakes are real and the work is consequential, we would love to hear from you.

Essential Duties and Responsibilities
  • Own infrastructure for all Azure resources across development, UAT, and production environments
  • Manage and evolve Azure DevOps pipelines for build, test, and deployment
  • Operate Azure Container Apps, App Service, Service Bus, Azure Database for PostgreSQL Flexible Server, Blob Storage, and supporting services
  • Maintain Azure Key Vault including secrets rotation and enforcement of least‑privilege access
  • Configure and tune Application Insights and Log Analytics, including PHI‑safe logging pipelines that prevent sensitive data from appearing in telemetry
  • Administer Microsoft Fabric, including workspace governance, capacity management, access controls, data integration oversight, and alignment with security and compliance requirements
Security Controls and Compliance
  • Implement and maintain technical controls in support of SOC 2 Type 2 and HIPAA compliance programs
  • Administer Entra ID including conditional access policies, MFA enforcement, group lifecycle management, and identity governance
  • Partner with leadership on audit preparation, evidence collection, and control documentation
  • Contribute to incident response readiness, including tabletop exercises and runbook development
  • Manage logging and alerting functions through Microsoft Purview and Microsoft Sentinel, including alert tuning, analytics rules, and data connector configuration
  • Maintain and improve the organization’s security posture through vulnerability management, access reviews, and security monitoring
IT Operations
  • Own Office 365 administration, SharePoint configuration, and SaaS tool management for the organization
  • Serve as the internal technical authority on endpoint security, device management, and employee access provisioning
  • Evaluate and onboard new tooling as the company scales, with a bias toward security and operational simplicity
The Technical Environment
  • Security and Identity: Azure Key Vault, Microsoft Entra ID, Microsoft Defender, Azure Policy
  • Observability and Security Operations: Application Insights, Log Analytics Workspaces, Microsoft Sentinel, Microsoft Purview
  • Productivity: Microsoft 365, SharePoint, Teams
  • Compliance targets: SOC 2 Type 2, HIPAA
Experience and Qualifications
  • 7-10 years in cloud platform engineering, DevOps, or infrastructure security
  • Hands‑on production Azure experience across the full service lifecycle, not just resource provisioning
  • Practical experience implementing technical controls for HIPAA and SOC 2 Type 2
  • Fluent in Entra ID: conditional access, MFA, role assignments, and identity governance
  • Applies appropriate safeguards for protected health information, including PHI‑safe logging pipelines, data isolation, and least‑privilege access controls
  • Comfortable owning IT operations end‑to‑end: M365, SaaS administration, and employee access management included
  • Brings a point of view. This role requires someone who assesses the environment, identifies gaps, and recommends a path forward
  • Energized by doing the work. This is a hands‑on role with full ownership of the platform and security posture
  • Healthcare or regulated industry background is a genuine advantage
  • Comfortable incorporating AI‑assisted tools and workflows into day‑to‑day work to improve speed and quality
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Azure Platform & Security Engineer — SOC 2 & HIPAA Ready
Azure Platform & Security Engineer — SOC 2 & HIPAA Ready

Highlight Health • Philadelphia

On-site
USD 140,000 - 180,000
Azure System Engineer
Azure System Engineer

FTS, Inc. • Marietta (GA)

Hybrid
USD 85,000 - 125,000
Security Engineer
Security Engineer

Healthmark Group • United States

On-site
USD 100,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Entegrata • Indianapolis (IN)

Hybrid
USD 120,000 - 180,000
Medical insurance
401k plan with match
Unlimited paid time off
+1
Platform Engineer - Security Focus
Platform Engineer - Security Focus

Arena Technical Resources, LLC (ATR) • Springfield (VA)

On-site
USD 70,000 - 85,000
Benefits
Paid Time Off
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Heath • Houston (TX)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Benefits
401k
PTO
+1
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Socket.dev • Ankeny (IA)

On-site
USD 170,000 - 210,000
PTO and holidays
401(k) match
Life insurance
+5
Senior Infrastructure & Security Engineer
Senior Infrastructure & Security Engineer

OnMed • City of White Plains (NY)

On-site
USD 150,000 - 160,000
Senior Infrastructure & Security Engineer
Senior Infrastructure & Security Engineer

OnMed LLC • City of White Plains (NY), Northern (KY)

Hybrid
USD 150,000 - 160,000
Unlimited PTO
Paid holidays
Senior Healthcare Infrastructure, Cloud & Security Engineer
Senior Healthcare Infrastructure, Cloud & Security Engineer

United Theranostics • United States

On-site
USD 160,000 - 210,000