Summary
GetixHealth is a healthcare revenue cycle management provider serving healthcare organizations. The Security Engineer II, SecOps role is responsible for implementing, maintaining, and improving technical security controls across cloud, endpoint, network, identity, and application environments. The position also supports security monitoring, incident response, vulnerability remediation, compliance, and collaboration with infrastructure, DevOps, engineering, IT, and GRC teams.
Responsibilities
- Design, implement, configure, and maintain security controls across cloud, endpoint, network, identity, and application environments
- Manage and improve security technologies including SIEM, EDR/XDR, vulnerability management, email security, DLP, identity protection, firewalls, and cloud security platforms
- Monitor and investigate security alerts, suspicious activity, potential threats, and security incidents
- Develop and tune security detections, alerts, dashboards, and automated response workflows
- Perform vulnerability scanning and support remediation across servers, endpoints, applications, cloud infrastructure, and network devices
- Support penetration testing, security assessments, and remediation efforts
- Support identity and access management controls, including SSO, MFA, conditional access, and privileged access management
- Investigate suspicious login activity, compromised accounts, and identity-related threats
- Help secure cloud infrastructure and services within Microsoft Azure and/or AWS
- Partner with DevOps and Software Engineering to incorporate security into CI/CD pipelines and software development practices
- Participate in incident response, including investigation, containment, eradication, recovery, and post-incident analysis
- Analyze security logs, endpoint telemetry, authentication events, network activity, and forensic evidence
- Support compliance with HIPAA, HITRUST, SOC 2, PCI-DSS, and applicable contractual and regulatory requirements
- Assist GRC teams with technical evidence for audits, assessments, and customer security reviews
- Maintain security documentation, procedures, standards, diagrams, and technical control evidence
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience
- **3–5 years of professional cybersecurity, security engineering, security operations, or related IT security experience**
- Hands-on experience with several of the following:
- SIEM and security monitoring platforms
- EDR/XDR technologies
- Vulnerability management platforms
- Identity and access management
- Microsoft 365 / Entra ID or similar enterprise identity platforms
- Azure and/or AWS cloud security
- Firewalls, network security, and secure remote access
- Email and phishing protection
- Data Loss Prevention (DLP)
- Experience investigating security alerts and responding to security incidents
- Working knowledge of vulnerability management and remediation
- Understanding of **TCP/IP, DNS, HTTP/S, VPNs, firewalls, and network segmentation**
- Understanding of Windows and Linux security fundamentals
- Ability to analyze logs and security telemetry across multiple systems
- Familiarity with scripting or automation using **PowerShell, Python, Bash, APIs**, or similar technologies
- Strong troubleshooting, analytical, and documentation skills
- Ability to communicate technical security risks to both technical and non-technical audiences
- Experience in healthcare, healthcare technology, revenue cycle management, medical billing, or another highly regulated industry
- Experience securing environments that store, process, or transmit **PHI**
- Strong technical problem-solving and troubleshooting skills
- In-depth knowledge of incident response
- A curious, investigative mindset and willingness to dig into complex technical issues
- Strong organizational and planning skills
- Ability to manage multiple priorities in a fast-paced environment
- Commitment to continuous learning as cybersecurity threats and technologies evolve
- Relevant certifications are preferred but not required, including:
- **Security+ | CySA+ | SSCP | GSEC | AZ-500 | SC-200 | Cisco | AWS Certified Security – Specialty**
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience
- **3–5 years of professional cybersecurity, security engineering, security operations, or related IT security experience**
- Hands-on experience with several of the following:
- SIEM and security monitoring platforms
- EDR/XDR technologies
- Vulnerability management platforms
- Identity and access management
- Microsoft 365 / Entra ID or similar enterprise identity platforms
- Azure and/or AWS cloud security
- Firewalls, network security, and secure remote access
- Email and phishing protection
- Data Loss Prevention (DLP)
- Experience investigating security alerts and responding to security incidents
- Working knowledge of vulnerability management and remediation
- Understanding of **TCP/IP, DNS, HTTP/S, VPNs, firewalls, and network segmentation**
- Understanding of Windows and Linux security fundamentals
- Ability to analyze logs and security telemetry across multiple systems
- Familiarity with scripting or automation using **PowerShell, Python, Bash, APIs**, or similar technologies
- Strong troubleshooting, analytical, and documentation skills
- Ability to communicate technical security risks to both technical and non-technical audiences
- Experience in healthcare, healthcare technology, revenue cycle management, medical billing, or another highly regulated industry
- Experience securing environments that store, process, or transmit **PHI**
- Strong technical problem-solving and troubleshooting skills
- In-depth knowledge of incident response
- A curious, investigative mindset and willingness to dig into complex technical issues
- Strong organizational and planning skills
- Ability to manage multiple priorities in a fast-paced environment
- Commitment to continuous learning as cybersecurity threats and technologies evolve
Nice to Haves
- Relevant certifications are preferred but not required, including:
- **Security+ | CySA+ | SSCP | GSEC | AZ-500 | SC-200 | Cisco | AWS Certified Security – Specialty**
Benefits
- Choose from a variety of medical, dental, and vision plans designed to support your overall well-being.
- Company-paid Basic Life and AD&D insurance, short-term and long-term disability coverage, with the option to purchase additional voluntary Life and AD&D benefits.
- 401(k) Retirement Plan: Become eligible to participate in the company's 401(k) plan on the first day of the quarter following three months of continuous employment, with a company match to help you invest in your future.
- Begin accruing PTO on your first day of employment.
- Flexible benefit options to meet individual and family needs.