GetixHealth logo
GetixHealth
Posted 33 days agoVerified live 1d ago

Security Engineer II

Brief overview

Remote
$110k–$135k/yrStated range
SIEMEDR/XDRVulnerability ManagementIdentity and Access Management SSOIdentity and Access Management MFAIdentity and Access Management Conditional AccessIdentity and Access Management PAMAzure/AWS Cloud SecurityIncident ResponseNetwork Security TCP/IPNetwork Security DNSNetwork Security HTTP/SNetwork Security VPNsNetwork Security FirewallsNetwork Security Network SegmentationWindows and Linux SecurityPowerShell, Python, Bash, and APIs

About the company

GetixHealth logo
GetixHealthgetixhealth.com

GetixHealth provides hospitals, clinics, university medical centers, and other healthcare facilities across the United States with comprehensive revenue cycle management (RCM) services.

Job description

Summary

GetixHealth is a healthcare revenue cycle management provider serving healthcare organizations. The Security Engineer II, SecOps role is responsible for implementing, maintaining, and improving technical security controls across cloud, endpoint, network, identity, and application environments. The position also supports security monitoring, incident response, vulnerability remediation, compliance, and collaboration with infrastructure, DevOps, engineering, IT, and GRC teams.

Responsibilities

  • Design, implement, configure, and maintain security controls across cloud, endpoint, network, identity, and application environments
  • Manage and improve security technologies including SIEM, EDR/XDR, vulnerability management, email security, DLP, identity protection, firewalls, and cloud security platforms
  • Monitor and investigate security alerts, suspicious activity, potential threats, and security incidents
  • Develop and tune security detections, alerts, dashboards, and automated response workflows
  • Perform vulnerability scanning and support remediation across servers, endpoints, applications, cloud infrastructure, and network devices
  • Support penetration testing, security assessments, and remediation efforts
  • Support identity and access management controls, including SSO, MFA, conditional access, and privileged access management
  • Investigate suspicious login activity, compromised accounts, and identity-related threats
  • Help secure cloud infrastructure and services within Microsoft Azure and/or AWS
  • Partner with DevOps and Software Engineering to incorporate security into CI/CD pipelines and software development practices
  • Participate in incident response, including investigation, containment, eradication, recovery, and post-incident analysis
  • Analyze security logs, endpoint telemetry, authentication events, network activity, and forensic evidence
  • Support compliance with HIPAA, HITRUST, SOC 2, PCI-DSS, and applicable contractual and regulatory requirements
  • Assist GRC teams with technical evidence for audits, assessments, and customer security reviews
  • Maintain security documentation, procedures, standards, diagrams, and technical control evidence

Skills

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience
  • **3–5 years of professional cybersecurity, security engineering, security operations, or related IT security experience**
  • Hands-on experience with several of the following:
  • SIEM and security monitoring platforms
  • EDR/XDR technologies
  • Vulnerability management platforms
  • Identity and access management
  • Microsoft 365 / Entra ID or similar enterprise identity platforms
  • Azure and/or AWS cloud security
  • Firewalls, network security, and secure remote access
  • Email and phishing protection
  • Data Loss Prevention (DLP)
  • Experience investigating security alerts and responding to security incidents
  • Working knowledge of vulnerability management and remediation
  • Understanding of **TCP/IP, DNS, HTTP/S, VPNs, firewalls, and network segmentation**
  • Understanding of Windows and Linux security fundamentals
  • Ability to analyze logs and security telemetry across multiple systems
  • Familiarity with scripting or automation using **PowerShell, Python, Bash, APIs**, or similar technologies
  • Strong troubleshooting, analytical, and documentation skills
  • Ability to communicate technical security risks to both technical and non-technical audiences
  • Experience in healthcare, healthcare technology, revenue cycle management, medical billing, or another highly regulated industry
  • Experience securing environments that store, process, or transmit **PHI**
  • Strong technical problem-solving and troubleshooting skills
  • In-depth knowledge of incident response
  • A curious, investigative mindset and willingness to dig into complex technical issues
  • Strong organizational and planning skills
  • Ability to manage multiple priorities in a fast-paced environment
  • Commitment to continuous learning as cybersecurity threats and technologies evolve
  • Relevant certifications are preferred but not required, including:
  • **Security+ | CySA+ | SSCP | GSEC | AZ-500 | SC-200 | Cisco | AWS Certified Security – Specialty**

Qualifications

Must Haves

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience
  • **3–5 years of professional cybersecurity, security engineering, security operations, or related IT security experience**
  • Hands-on experience with several of the following:
  • SIEM and security monitoring platforms
  • EDR/XDR technologies
  • Vulnerability management platforms
  • Identity and access management
  • Microsoft 365 / Entra ID or similar enterprise identity platforms
  • Azure and/or AWS cloud security
  • Firewalls, network security, and secure remote access
  • Email and phishing protection
  • Data Loss Prevention (DLP)
  • Experience investigating security alerts and responding to security incidents
  • Working knowledge of vulnerability management and remediation
  • Understanding of **TCP/IP, DNS, HTTP/S, VPNs, firewalls, and network segmentation**
  • Understanding of Windows and Linux security fundamentals
  • Ability to analyze logs and security telemetry across multiple systems
  • Familiarity with scripting or automation using **PowerShell, Python, Bash, APIs**, or similar technologies
  • Strong troubleshooting, analytical, and documentation skills
  • Ability to communicate technical security risks to both technical and non-technical audiences
  • Experience in healthcare, healthcare technology, revenue cycle management, medical billing, or another highly regulated industry
  • Experience securing environments that store, process, or transmit **PHI**
  • Strong technical problem-solving and troubleshooting skills
  • In-depth knowledge of incident response
  • A curious, investigative mindset and willingness to dig into complex technical issues
  • Strong organizational and planning skills
  • Ability to manage multiple priorities in a fast-paced environment
  • Commitment to continuous learning as cybersecurity threats and technologies evolve

Nice to Haves

  • Relevant certifications are preferred but not required, including:
  • **Security+ | CySA+ | SSCP | GSEC | AZ-500 | SC-200 | Cisco | AWS Certified Security – Specialty**

Benefits

  • Choose from a variety of medical, dental, and vision plans designed to support your overall well-being.
  • Company-paid Basic Life and AD&D insurance, short-term and long-term disability coverage, with the option to purchase additional voluntary Life and AD&D benefits.
  • 401(k) Retirement Plan: Become eligible to participate in the company's 401(k) plan on the first day of the quarter following three months of continuous employment, with a company match to help you invest in your future.
  • Begin accruing PTO on your first day of employment.
  • Flexible benefit options to meet individual and family needs.

More jobs like this