RadNet logo
RadNet
Posted 45 days agoVerified live 15h ago

Security Operations Engineer

Brief overview

Remote
UndergradOr in progress
4+ yrsMinimum
1 H-1B approvalsDept. of Labor
Cloud SecuritySecurity Information and Event Management (SIEM)Microsoft 365 and Entra ID SecuritySecurity Automation and Infrastructure as CodeTerraformCloud Security Posture Management (CSPM)Container and Kubernetes SecuritySecrets ManagementEndpoint Detection and Response (EDR)Vulnerability ManagementPython, PowerShell, or Bash

About the company

RadNet provides diagnostic imaging services through a network of 400 owned and operated outpatient imaging centers.

Visa sponsorship history

1 year sponsoring, last filed FY2024

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
1H-1B approved
100%approval rate
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20241

Job description

Summary

RadNet is seeking a Security Operations Engineer to build and operate security controls, tooling, and automation across cloud and corporate environments. The role focuses on enterprise security tooling, detection content, cloud and identity security, vulnerability management, incident investigation, remediation guidance, and audit support within a regulated healthcare environment.

Responsibilities

  • Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments
  • Develop and maintain detection content, correlation rules, and response automation within the SIEM and SOAR platform
  • Onboard new log sources and telemetry feeds, validating ingestion completeness, parsing accuracy, and field normalization
  • Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation
  • Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality
  • Implement and maintain security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure
  • Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework, so that controls are version-controlled, repeatable, and auditable
  • Implement policy-as-code and preventive guardrails using native cloud policy engines or an equivalent open policy framework
  • Support cloud security posture management across all cloud environments, including finding deduplication, theme mapping, and routing to owning teams
  • Harden cloud resources including compute, storage, database, container, and serverless services against established benchmarks
  • Configure and maintain Microsoft 365 and Entra ID security controls, including conditional access, identity protection, and Defender workloads in a hybrid directory environment
  • Implement and maintain least-privilege access models, roles, and policies across multiple cloud identity systems
  • Implement container and Kubernetes security controls, including role-based access control, workload security standards, image scanning, and runtime protection
  • Implement and maintain secrets management practices and tooling, and support the elimination of hard-coded credentials across environments
  • Operate vulnerability management tooling, validate scan coverage, and translate raw scanner output into prioritized, owner-routed findings
  • Provide technical remediation guidance to cloud, platform, identity, application, and endpoint owners, who retain accountability for closure of findings in their systems
  • Implement engineering fixes for findings that fall to security-owned tooling and configuration
  • Support remediation tracking for penetration test and vulnerability assessment findings by supplying technical detail and validating that fixes are technically sound
  • Support incident detection and response through hands-on technical investigation, including log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review
  • Support escalations raised by the external managed security partner by supplying technical analysis and environment context
  • Provide feedback into detection quality and alert tuning to reduce noise and improve signal for the monitoring function
  • Contribute technical findings to post-incident review, and implement the resulting control and detection improvements
  • Participate in tabletop exercises and resilience testing, and act on the technical gaps those exercises surface
  • Document all engineering changes to security controls through the change management process, including validation criteria and rollback plans
  • Produce and maintain runbooks, playbooks, and technical operating procedures for repeatable security operations tasks
  • Write clear, documented, and reviewable code and configuration so that work can be inspected, maintained, and handed over without dependence on any one individual
  • Support audit, certification, and customer assurance activities by producing technical evidence on request
  • Maintain accurate inventory of security tooling, control coverage, licensing position, and control operating status
  • Maintain strict confidentiality of security testing results, control configuration detail, and investigative material, and follow established standards for external disclosure

Skills

  • 4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role. (Required)
  • Bachelor's degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience. (Required)
  • 2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred. (Required)
  • 2+ years operating and tuning a SIEM platform, including working with detection content and log sources. (Required)
  • 1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment. (Required)
  • Working knowledge of security automation; experience with scripting and infrastructure-as-code is required, with Terraform experience preferred. (Required)
  • Working knowledge of cloud security posture management and preventive controls. (Required)
  • Working knowledge of container and Kubernetes security, including role-based access control and image scanning. (Required)
  • Working knowledge of secrets management tooling and practices. (Required)
  • Practical experience with endpoint detection and response tooling. (Required)
  • Working knowledge of vulnerability management and the finding remediation lifecycle, including risk-based prioritization. (Required)
  • Scripting capability in at least one of: Python, PowerShell, or Bash. (Required)
  • Familiarity with recognized security frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2. (Required)
  • Able to communicate technical findings clearly in writing and verbally to both technical and non-technical audiences. (Required)
  • Able to manage assigned work independently and escalate appropriately. (Required)
  • Available to support incident response activity outside standard business hours as required. (Required)
  • Microsoft Office experience. (Required)
  • This position requires domestic / international travel up to 10%
  • This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally
  • DeepHealth does not provide immigration sponsorship for this position, including sponsorship for employment-based visas or other work authorization requiring employer sponsorship. Candidates must be legally authorized to work in the United States without current or future sponsorship from DeepHealth for the duration of employment
  • Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification. (Preferred)
  • Experience in healthcare, medical device, or another regulated industry, and working familiarity with HIPAA obligations. (Preferred)
  • Experience working alongside or integrating with a managed security service provider. (Preferred)

Qualifications

Must Haves

  • 4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role. (Required)
  • Bachelor's degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience. (Required)
  • 2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred. (Required)
  • 2+ years operating and tuning a SIEM platform, including working with detection content and log sources. (Required)
  • 1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment. (Required)
  • Working knowledge of security automation; experience with scripting and infrastructure-as-code is required, with Terraform experience preferred. (Required)
  • Working knowledge of cloud security posture management and preventive controls. (Required)
  • Working knowledge of container and Kubernetes security, including role-based access control and image scanning. (Required)
  • Working knowledge of secrets management tooling and practices. (Required)
  • Practical experience with endpoint detection and response tooling. (Required)
  • Working knowledge of vulnerability management and the finding remediation lifecycle, including risk-based prioritization. (Required)
  • Scripting capability in at least one of: Python, PowerShell, or Bash. (Required)
  • Familiarity with recognized security frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2. (Required)
  • Able to communicate technical findings clearly in writing and verbally to both technical and non-technical audiences. (Required)
  • Able to manage assigned work independently and escalate appropriately. (Required)
  • Available to support incident response activity outside standard business hours as required. (Required)
  • Microsoft Office experience. (Required)
  • This position requires domestic / international travel up to 10%
  • This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally
  • DeepHealth does not provide immigration sponsorship for this position, including sponsorship for employment-based visas or other work authorization requiring employer sponsorship. Candidates must be legally authorized to work in the United States without current or future sponsorship from DeepHealth for the duration of employment

Nice to Haves

  • Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification. (Preferred)
  • Experience in healthcare, medical device, or another regulated industry, and working familiarity with HIPAA obligations. (Preferred)
  • Experience working alongside or integrating with a managed security service provider. (Preferred)

Benefits

  • Remote work arrangement

More jobs like this