Senior Security Engineer

HealthDrive Corporation

Framingham (MA)

Hybrid

USD 85,000 - 115,000

Full time

29 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

HealthDrive Corporation in Framingham is seeking a Senior Security Engineer to own day-to-day security operations, manage alerts, and drive remediation across the Microsoft cloud estate.

This hands-on role monitors phishing, email and DLP, coordinates with managed providers, and enforces identity and endpoint security to protect patient data.

Hybrid work, a competitive salary, and opportunities to strengthen security maturity while supporting healthcare delivery.

Qualifications

  • 7+ years hands-on security engineering or operations experience.
  • Hands-on ownership of email security and data loss prevention (Proofpoint preferred).
  • Experience configuring Microsoft Entra ID and Microsoft 365 in production.
  • Ownership of vulnerability management program and end-to-end remediation.
  • Experience with EDR platforms and SIEM monitoring.
  • Experience overseeing managed security service providers.
  • Ability to communicate risk clearly to non-technical stakeholders.

Responsibilities

  • Triage, investigate and resolve phishing and email-borne threats; follow-up with users.
  • Monitor and tune email security and DLP policy and alerting; handle DLP events involving PHI.
  • Own escalations from managed detection provider; containment and closure of incidents.
  • Investigate security concerns and maintain records of findings and actions taken.
  • Own the vulnerability management cycle end to end; remediation coordination.
  • Coordinate remediation with Infrastructure and Software Development; manage patching conflicts.
  • Review and improve identity, access and privilege configuration; enforce MFA.

Skills

Email security
DLP governance
Microsoft Entra ID
Microsoft 365 security
Vulnerability management
Endpoint security
EDR
Scripting PowerShell
Python
Vendor management

Education

Bachelor's degree in IT / CS / Cybersecurity

Tools

Proofpoint
Microsoft Entra ID
Microsoft 365
SentinelOne
Microsoft Sentinel
Secureworks Taegis
Fortinet
PowerShell
Python

Job description

About HealthDrive :

HealthDrive delivers on-site healthcare services to residents of long-term care facilities, offering a comprehensive suite of specialties including primary care, behavioral health, dentistry, optometry, podiatry, and audiology. Our mission is to improve the quality of life for patients through compassionate and consistent care, while supporting our partners with reliable, integrated healthcare solutions tailored to the unique needs of senior populations.

Overview

HealthDrive delivers on-site healthcare services to residents of long-term care facilities, offering a comprehensive suite of specialties including primary care, behavioral health, dentistry, optometry, podiatry, and audiology. Our mission is to improve the quality of life for patients through compassionate and consistent care, while supporting our partners with reliable, integrated healthcare solutions tailored to the unique needs of senior populations.

About The Role:

The Senior Security Engineer is HealthDrive's in-house owner of day-to-day security operations and security configuration. This role handles the security work that arrives every day — reported phishing, email and data loss prevention alerts, endpoint detections, and escalations from our managed security providers — and drives each to closure. It also owns the configuration and hardening of our Microsoft cloud estate and holds accountability for ensuring identified vulnerabilities are actually remediated.

HealthDrive uses managed security providers for around-the-clock monitoring and for network security engineering. This role sits above those providers: it directs their work, evaluates their performance, and remains the decision-maker for HealthDrive when a genuine security incident occurs. This is a hands‑on engineering role, not a governance or audit role, and not a role that supervises staff.

Work Environment:

Based at HealthDrive’s Framingham, MA office (off Route 9, near Routes 90 and 495) on a hybrid schedule.

Compensation Range:

$85,000 to $115,000 / experience dependent

#INDHDCORPREC

Responsibilities
Day-to-Day Security Operations
  • Triage, investigate and resolve reported phishing and email-borne threats, including user communication and follow-up.
  • Monitor, tune and maintain email security and data loss prevention policy and alerting; investigate and disposition DLP events involving protected health information.
  • Own escalations from HealthDrive's managed detection provider from receipt through containment and closure, including endpoint detection and response alerts.
  • Investigate user-reported security concerns and suspicious activity, and maintain records of findings and actions taken.
Vulnerability Management
  • Own the vulnerability management cycle end to end: scanning, risk-based prioritization, and accountability for remediation reaching completion.
  • Work with Infrastructure and Software Development to schedule and validate remediation, including where patching conflicts with clinical or operational workflows.
  • Report remediation status, aging and exceptions to IT leadership on a defined cadence.
Cloud and Endpoint Security Configuration
  • Own security configuration and hardening of Microsoft Entra ID, including Conditional Access policy design, review and change control.
  • Own Microsoft 365 security configuration and data protection settings across mail, collaboration and file storage.
  • Maintain endpoint security policy and configuration, and verify coverage across the managed device estate.
  • Review and improve identity, access and privilege configuration, including administrative access and multi-factor authentication enforcement.
Managed Provider Oversight
  • Serve as HealthDrive's technical owner of the managed security provider relationships, covering monitoring, response and network security engineering services.
  • Direct provider work, submit and validate detection tuning requests, and reduce recurring false positives.
  • Run periodic service reviews, hold providers to contracted response commitments, and elevate performance shortfalls to IT leadership.
  • Maintain documented escalation paths and ensure HealthDrive retains the knowledge required to change providers without loss of continuity.
Incident Response
  • Recommend and implement containment and recovery actions for affected systems when a provider escalates a confirmed incident.
  • Maintain and exercise incident response procedures, and lead post-incident review and corrective action.
  • Support breach assessment and notification analysis in coordination with Compliance and Legal.
Security Program Support
  • Contribute to security awareness and phishing simulation programs.
  • Support security review of vendors and third parties, and of new applications and integrations, in partnership with Compliance.
  • Maintain security documentation, configuration baselines and operational runbooks.
Qualifications
Must have :
  • Approximately seven or more years of hands-on experience in security engineering or security operations, with demonstrated personal ownership of the work rather than coordination of it.
  • Demonstrated hands-on ownership of email security and data loss prevention. Proofpoint strongly preferred; comparable enterprise platforms considered.
  • Demonstrated hands-on experience configuring and securing Microsoft Entra ID and Microsoft 365, including Conditional Access policy design in a production environment.
  • Demonstrated ownership of a vulnerability management program, including driving remediation to closure across teams that do not report to this role.
  • Practical experience with endpoint detection and response platforms and with security monitoring or SIEM output. SentinelOne, Microsoft Sentinel or Secureworks Taegis are directly relevant.
  • Demonstrated incident response experience with sound judgment on containment decisions.
  • Experience working with or overseeing managed security service providers.
  • Working knowledge of enterprise network and firewall security sufficient to review provider work and partner effectively with Infrastructure. Fortinet experience is relevant.
  • Scripting or automation capability, such as PowerShell or Python.
  • Ability to communicate risk clearly to non-technical stakeholders, including clinical and operational leaders.
Nice To Have :
  • Healthcare provider-side experience and working familiarity with HIPAA and HITECH.
  • Experience with Qualys, Fortinet, SentinelOne, Microsoft Sentinel or Secureworks.
  • Third-party and vendor risk assessment experience.
  • Experience in a small or lean IT organization where breadth and self-direction are required.
Education & Qualifications :
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity or a related field, or equivalent demonstrated professional experience.
Certifications & Licenses :
  • CISSP preferred.
  • In the absence of CISSP, at least one of the following: AZ-500, SC-200, Security+, CySA+, CISM, CCSP or HCISPP
Core Competencies :
  • Communication
  • Cooperation and Team working
  • Adaptability
  • Expertise and Professionalism
  • Problem Solving / Analysis
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

HealthDrive • Framingham (MA)

Hybrid
USD 85,000 - 115,000
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000
IT Security & Compliance Lead (Healthcare)
IT Security & Compliance Lead (Healthcare)

Premium Health Center • New York (NY)

Hybrid
USD 140,000 - 210,000
Paid time off
Medical, dental, and vision plans
Retirement plans
+1
Information Technology Security Manager
Information Technology Security Manager

Wheeler Staffing Partners • Dallas (TX)

Hybrid
USD 120,000 - 140,000
Dir, Security Operations
Dir, Security Operations

PDS Health • Irvine (CA)

On-site
USD 169,000 - 227,000
Medical, dental, and vision insurance
401K
Paid time off
+2
Senior Security Engineer
Senior Security Engineer

agelessrx • United States

On-site
USD 150,000 - 190,000
Senior Healthcare Infrastructure, Cloud & Security Engineer
Senior Healthcare Infrastructure, Cloud & Security Engineer

United Theranostics • United States

On-site
USD 160,000 - 210,000
Senior Security Engineer: Cloud & Incident Response Lead
Senior Security Engineer: Cloud & Incident Response Lead

HealthDrive Corporation • Framingham (MA)

Hybrid
USD 85,000 - 115,000