SENIOR SECURITY ENGINEER

NORTH EAST MEDICAL SERVICES

Daly City (CA)

On-site

USD 103,030 - 119,024

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

North East Medical Services is seeking a Senior Security Engineer to design and govern enterprise security architecture. The role involves hands-on leadership across clinic sites and cloud infrastructure, ensuring compliance with HIPAA and NIST standards.

The ideal candidate has a Bachelor's degree in a relevant field and CISSP certification, with a strong background in incident response and identity management. Join our team to enhance security across our health services.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Certified Information Systems Security Professional (CISSP) certification required.
  • Minimum 5 years in enterprise security engineering including comprehensive architecture design.

Responsibilities

  • Design and maintain enterprise security architecture aligned with Zero-Trust principles.
  • Conduct quarterly security risk assessments and vulnerability assessments.
  • Collaborate with external security vendors for optimal security compliance.

Skills

Enterprise security architecture design
Identity and access management
Incident response coordination
Vulnerability management

Education

Bachelor's Degree in Cybersecurity or related field

Tools

Cloud identity platforms (Azure AD/Entra ID)
Endpoint Detection and Response solutions

Job description

Job Details

Job Location: Daly City, CA 94014

Position Type: Full Time

Salary Range: $74.79 - $86.40 Hourly

SUMMARY OF POSITION

The Senior Security Engineer is responsible for designing, implementing, and governing NEMS enterprise security architecture across all clinic sites, data center environments, and cloud infrastructure. Operating within a hybrid multi-site environment spanning multiple hosting locations with defined security SLAs aligned to HIPAA and NIST standards, this role serves as a hands‑on technical leader who collaborates with external security vendors, cloud providers, and internal infrastructure teams to architect and enforce a cohesive, Zero‑Trust security environment. The Senior Security Engineer plays a critical role in IAM governance, endpoint protection, lifecycle management, security policy development and enforcement, SOC coordination, and continuous compliance monitoring across endpoints and data centers.

ESSENTIAL JOB FUNCTIONS
  • Designs and maintains enterprise security architecture aligned to Zero-Trust principles, NIST Cybersecurity Framework, and organizational risk tolerance across all environments.
  • Defines security baselines and governance frameworks for identity management, endpoint protection, network controls, encryption, and compliance standards.
  • Designs, implements, and governs cloud identity platforms (Azure AD/Entra ID) and hybrid IAM across on-premises and cloud infrastructure.
  • Establishes and enforces multi‑factor authentication (MFA) and privileged access management (PAM) policies across all critical systems.
  • Conducts quarterly IAM audits and access reviews ensuring compliance with least‑privilege principles and HIPAA‑required access controls.
  • Deploys and configures endpoint management agents across 2,500+ endpoints spanning clinic sites and data centers.
  • Establishes, enforces, and monitors security patching schedules across all operating systems, applications, and firmware.
  • Deploys and manages Endpoint Detection and Response (EDR) solutions across critical systems and user workstations.
  • Configures Zero‑Trust Network Access agents and network micro‑segmentation policies to enforce zero‑trust principles and limit lateral movement.
  • Develops security policies aligned to NIST CSF, NIST 800‑53, HIPAA Security Rule, and HITECH requirements; conducts annual policy reviews.
  • Conducts quarterly security risk assessments and vulnerability assessments in coordination with penetration testing vendors.
  • Establishes incident response frameworks, escalation procedures, and post‑incident review processes validated through tabletop exercises and drills.
  • Collaborates with external SOC vendors to define alert severity levels, routing procedures, and response time objectives.
  • Participates in incident triage, investigations, and root cause analysis for significant security events.
  • Establishes network security policies including segmentation, firewall architecture, and encrypted communications standards.
  • Coordinates with infrastructure teams to design and validate Zero‑Trust architecture implementation across all domains.
  • Maintains centralized compliance documentation and prepares evidence packages for regulatory audits and HIPAA risk assessments.
  • Serves as primary technical liaison between NEMS and external security vendors; defines SLAs and monitors performance.
  • Mentors junior security team members and provides technical guidance on security best practices and policy implementation.
  • Stays current with evolving threat landscape, regulatory requirements, and industry standards; recommends quarterly security enhancements aligned to NEMS roadmap.
  • Performs other job duties as required by the manager/supervisor.
QUALIFICATIONS
  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Information Security, or a related STEM field required.
  • Equivalent combination of 8+ years of directly relevant security engineering and IAM experience may be substituted for the degree requirement.
  • Certified Information Systems Security Professional (CISSP) is required.
  • Minimum 5 years of enterprise security engineering experience including architecture design, security policy governance, hands‑on technical implementation, and demonstrated security leadership owning outcomes across infrastructure, applications, and networks.
  • Minimum 3 years of hands‑on experience in each of the following: designing and implementing identity and access management; designing and implementing endpoint detection and response solutions; developing and maintaining security policies aligned to NIST or ISO 27001 frameworks; and coordinating with external security vendors, SOCs, and managed security service providers.
  • Demonstrated experience conducting security risk assessments, vulnerability management, and threat analysis.
  • Demonstrated experience with incident response coordination, root cause analysis, and post‑incident reviews.
  • Demonstrated experience with healthcare compliance frameworks including HIPAA Security Rule and HITECH requirements.
  • Experience in healthcare information technology or Federally Qualified Health Center (FQHC) environments preferred.
LANGUAGE
  • Must be able to read, write, and speak English fluently.
  • Ability to speak and/or understand Chinese (Cantonese or Mandarin) is an asset.
STATUS
  • This is an FLSA exempt position.
  • This is not an OSHA high‑risk position.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
ENTERPRISE ARCHITECT
ENTERPRISE ARCHITECT

NORTH EAST MEDICAL SERVICES • Daly City (CA)

On-site
USD 169,000 - 196,000
Free medical, dental and vision insurance
401(k) company contribution
TECHNICAL PROJECT MANAGER
TECHNICAL PROJECT MANAGER

NORTH EAST MEDICAL SERVICES • Daly City (CA)

On-site
USD 132,000 - 152,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
IT Security Administrator
IT Security Administrator

Chase Brexton Health Care • Baltimore (MD)

On-site
USD 120,000 - 180,000
Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Zero-Trust Security Architect (IAM & Cloud)
Zero-Trust Security Architect (IAM & Cloud)

North East Medical Services • Daly City (CA)

Hybrid
USD 103,030 - 119,024
Network/Firewall Security Engineer - Information Tech (Onsite) (Days)
Network/Firewall Security Engineer - Information Tech (Onsite) (Days)

Tanner Health • Carrollton (GA)

On-site
USD 90,000 - 120,000
Security/CyberArk Engineer- On-site/local only
Security/CyberArk Engineer- On-site/local only

Stone Search, LLC • South Foxboro (MA)

On-site
USD 80,000 - 120,000