R
Job Description
Location: Remote - (Designated States)
This position is fully remote and may be performed from one of the following U.S. states: AL, AZ, FL, GA, IN, KS, MA, MI, MS, NC, NV, OR, PA, SC, TN, TX.
Role Overview: The Security Engineer serves as a pivotal member of the IT team, offering operational guidance for the organization's Security Operations to support critical business objectives, functioning as an experienced Subject Matter Expert.
Security Compliance and Operations: This role is responsible for implementing and ensuring electronic healthcare PHI-related security standards, including the NIST Cyber Security Framework, ISO 27000 series, PCI, and HIPAA controls and benchmarks. The Security Engineer will collaborate with third-party security partners, manage tickets and alerts, oversee vulnerability management, and address network, cloud security, and identity & access management.
Strategic Vision: The ideal candidate is expected to continuously strategize on scaling Raintree's security infrastructure with the objective of mitigating overall risk while facilitating business growth and operational efficiency. A core belief is that security should be an inherent attribute of the tools and processes utilized by cybersecurity professionals.
Duties and Responsibilities:
- Assisting the Sr. Security Engineer and IT Director in the implementation, maintenance, and operation of information system security controls and countermeasures.
- Analyzing and recommending security controls and procedures for information system acquisition, development, and change management, and monitoring for compliance.
- Analyzing and recommending security controls and procedures for business processes related to information systems and assets, and monitoring for compliance.
- Monitoring information systems for security incidents and vulnerabilities, developing monitoring and visibility capabilities, and reporting on incidents, vulnerabilities, and trends.
- Assisting team members in developing methods and processes (runbooks & playbooks) to enhance the effectiveness, efficiency, and security of services, desktop support, and end-user support functions.
- Participating in the planning and implementation of security standards, practices, and procedures to ensure system security and legal compliance.
- Partnering effectively with all departments to integrate security into operational processes.
- Demonstrating a solid understanding of risk-based decision-making and risk management frameworks.
- Actively leading Security incident response activities and implementing Security incident response processes and procedures.
- Participating in audits to ensure adherence to security protocols by staff.
- Providing day-to-day support to foster an engaged work environment with a focus on customer service.
- Minimum of 8 years of professional experience in the Technology industry
- Minimum of 6 years of technology leadership experience in high-tech companies, preferably with SaaS business models.
- 5+ years of experience with Security Operations, such as Intrusion Detection Systems (IDS), Security Incident Event Management systems (SIEM), and anti-virus log collection systems.
- Experience deploying and customizing security tools for threat detection and risk reduction, including vulnerability scanners, static analyzers, web application firewalls, and endpoint security monitoring.
- Hands-on day-to-day operational experience with industry-standard tools such as Slack, Zoom, IT Service Management (e.g., Freshservice), Azure Active Directory, and Single Sign-On (e.g., Okta).
- Demonstrated hands-on experience implementing a Tiered approach to Helpdesk, including automation of onboarding & offboarding in conjunction with HRS.
- Proficiency in Cloud platforms: AWS & Azure.
- Knowledge of SOC 2, CIS, and NIST Security Governance & Compliance.
- Broad knowledge of scripting and/or development ability to customize existing security tools.
- Knowledge of physical and logical secure network design, UDP/TCP protocols, and cloud topologies.
- Knowledge of Microsoft and Google product suites.
- Strong leadership presence.
- Significant experience working and leading cross-functionally in high-growth organizations.
- Outstanding written and verbal communication skills; proven ability to communicate effectively at all levels.
- Broad knowledge of IT disciplines, with particular emphasis on Information Security, System Administration, and Cloud Engineering.
- Understanding of modern cloud technology components and deployment patterns, including virtual machines, containers, Kubernetes, serverless, and infrastructure as code.
- Remote Work/Work From Home
- Paid Time Off/11 Paid Holidays/Year-End Holiday Break
- Health, Dental, Vision, HSA/FSA
- 401K with Company Match
- Disability & Life Insurance
- Employee Assistance Program
- Paid Parental Leave
Similar Jobs
Explore other opportunities that match your interests
Visa Sponsorship
Relocation
Remote
Job Type
Full-time
Experience Level
Mid-Senior level
Stripe
United State
Senior Compliance Program Manager, Engineering
••••••
••••••
••••••
Job Type
••••••
Experience Level
••••••
Palo Alto Networks
United State
Senior IT Controls & External Audit Manager (SOC 1/SOC 2/SOX)
••••••
••••••
••••••
Job Type
••••••
Experience Level
••••••
Kraken
United State