
Security Engineer
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Pennsylvania.
• Oversee the design, execution, and ongoing enhancement of the organization's cybersecurity program.
• Create, implement, and sustain enterprise security infrastructure, which includes firewalls, IDS/IPS, endpoint protection platforms, SIEM solutions, and application control technologies.
• Direct the firm's cybersecurity strategy and roadmap, ensuring alignment of initiatives with business goals and risk priorities.
• Monitor security systems, investigate alerts, and coordinate actions in response to security incidents and forensic investigations.
• Perform vulnerability assessments and penetration testing, collaborating with system owners to mitigate identified risks.
• Develop, uphold, and enforce security policies, standards, and procedures that align with NIST CSF, CIS Controls, and ISO 27001.
• Manage identity and access management solutions, encompassing MFA, SSO, privileged access management, and access reviews.
• Assist with security and privacy compliance initiatives, audits, risk assessments, and evaluations of third-party vendors' security.
• Administer and enhance email security gateways, web filtering solutions, and cloud security technologies.
• Lead incident response efforts, business continuity planning, disaster recovery, platform migrations, and zero-trust initiatives.
• Collaborate with infrastructure, cloud, and business teams to incorporate security requirements into technologies and processes.
• Provide guidance to firm leadership regarding cybersecurity risks, security architecture, and strategic technology investments.
• Monitor emerging threats and prepare metrics, dashboards, and reports on security posture and program maturity.
• Mentor team members and promote organization-wide security awareness.
• Report directly to the Chief Information Officer.
• Bachelor’s degree in Information Security, Information Technology, Information Systems, or a related field, or a comparable combination of education and experience.
• Five or more years of progressive experience in cybersecurity or information security, including oversight of complex security programs and initiatives.
• In-depth knowledge of network security, operating system hardening, Azure security, and contemporary security architectures, particularly zero-trust principles.
• Practical experience with SIEM platforms, vulnerability management tools, EDR, firewalls, and IDS/IPS technologies.
• Familiarity with NIST CSF, CIS Controls, ISO 27001, and SOC 2.
• Knowledge of identity and access management technologies and protocols, including SAML, OAuth, LDAP, and directory services.
• Experience with PowerShell and Python scripting and automation techniques.
• Outstanding analytical, troubleshooting, and problem-solving skills.
• Excellent written and verbal communication skills, capable of conveying technical concepts to both technical and non-technical audiences.
• Capability to manage various priorities, work autonomously, and uphold confidentiality in a professional services context.
• CISSP, CISM, CEH, GIAC, or CompTIA Security+ certifications are highly preferred.
• Master’s degree in Cybersecurity, Information Security, or a related discipline is preferred.
• Opportunities for mentorship, leadership development, and continuous learning.
• Flexible work arrangements available.
• Family-oriented culture.
• Reasonable expectations regarding revenue hours.
• Technology that enhances efficiency.
• Opportunities for professional development.
• Competitive compensation package.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.