Summary
Imagine Pediatrics is a tech-enabled, pediatrician-led medical group reimagining care for children with special health care needs through virtual-first and in-home medical, behavioral, and social care. The Security Engineer will operate, tune, and improve security technologies and processes across cloud, endpoint, identity, and application environments, collaborating with the Senior Security Engineer to protect systems, data, and patients from cybersecurity threats.
Responsibilities
- Collaborate closely with the Senior Security Engineer to scope, design, and solution security initiatives, from early brainstorming through implementation and validation
- Participate in peer review of security configurations, policies, and automation, and contribute to shared documentation, runbooks, and design decisions
- Administer and tune core security platforms across endpoint detection and response, endpoint management and device compliance, email security, cloud access and network traffic monitoring, data loss prevention, and vulnerability management
- Support the security of our cloud infrastructure in Microsoft Azure/EntraID and Amazon Web Services (AWS), including identity and access management, logging and monitoring, network controls, encryption and key management, and configuration baselines
- Respond to alerts and escalations from our managed detection and response (MDR) provider and other security systems as part of the on-call rotation
- Interpret log outputs from a wide selection of IT, security, and cloud infrastructure, and help route the right telemetry into our centralized logging and SIEM solution
- Ensure configurations and deployments are aligned with relevant industry standards such as HITRUST, NIST, CIS Benchmarks, HIPAA, and the OWASP Top 10
- Translate framework requirements into practical technical controls, and apply them to new systems, cloud accounts, and services as the company grows rather than retrofitting them later
- Create, implement, and test incident response procedures for new threat content and alerts
- Respond to and resolve cyber security threats that may impact the confidentiality, integrity, or availability of Imagine Pediatrics systems and personnel
- Use AI tooling thoughtfully to reduce manual effort in areas such as log review, documentation, evidence preparation, scripting, and alert triage
- Ensure security control initiatives are executed on schedule and in line with Imagine Pediatrics Information Security program objectives and corporate policies
- Apply professional discretion and judgement when viewing sensitive and personal data or information in the process of conducting work
- Other duties as assigned
Skills
- Relevant license(s) or certification(s): AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC, Security+, CySA+, CEH, CISSP
- 3+ years of experience as an Information Security Analyst, Risk Analyst, Security Engineer, Information Security Engineer, or similar role, ideally with 2 of those 3+ years within the healthcare industry
- Experience using Artificial Intelligence (AI) tools to enhance and automate security processes and procedures
- Experience managing HITRUST and HIPAA requirements and working with auditors
- Knowledge of IT systems such as AWS, Microsoft Intune, EntraID, JAMF, Meraki, and JIRA Service Management
- Strong diagnostic and problem-solving abilities, and an ability to innovate and grow knowledge in a fast-paced environment
- Comfortable working knowledge of key technology concepts such as access control, confidential data, encryption, business continuity, information security vulnerability scans, and cloud services
- Proven history executing business impact projects within defined scope, deliverables, and timeframe
- Ability to remain calm and lead the technical response to security incidents and data breaches
- Bachelor of Science degree in Computer Science, Information Security, Business, Management, or a related field is preferred
Qualifications
Must Haves
- Relevant license(s) or certification(s): AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC, Security+, CySA+, CEH, CISSP
- 3+ years of experience as an Information Security Analyst, Risk Analyst, Security Engineer, Information Security Engineer, or similar role, ideally with 2 of those 3+ years within the healthcare industry
- Experience using Artificial Intelligence (AI) tools to enhance and automate security processes and procedures
- Experience managing HITRUST and HIPAA requirements and working with auditors
- Knowledge of IT systems such as AWS, Microsoft Intune, EntraID, JAMF, Meraki, and JIRA Service Management
- Strong diagnostic and problem-solving abilities, and an ability to innovate and grow knowledge in a fast-paced environment
- Comfortable working knowledge of key technology concepts such as access control, confidential data, encryption, business continuity, information security vulnerability scans, and cloud services
- Proven history executing business impact projects within defined scope, deliverables, and timeframe
- Ability to remain calm and lead the technical response to security incidents and data breaches
Nice to Haves
- Bachelor of Science degree in Computer Science, Information Security, Business, Management, or a related field is preferred
Benefits
- Annual bonus incentive
- Eligibility to participate in an employee equity purchase program (as applicable)
- Competitive medical, dental, and vision insurance
- Healthcare and Dependent Care FSA; Company-funded HSA
- 401(k) with 4% match, vested 100% from day one
- Employer-paid short and long-term disability
- Life insurance at 1x annual salary
- 20 days PTO + 10 Company Holidays & 2 Floating Holidays
- Paid new parent leave