
Senior Information Security Engineer
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in United States.
• Act as a senior technical authority within Baylor Genetics’ Information Security team.
• Design, execute, and manage security controls to safeguard systems, networks, endpoints, and cloud environments.
• Lead and manage detection and response capabilities, including SIEM/MDR, EDR/XDR, and SOAR.
• Optimize security detections by utilizing organization-specific policies and response strategies.
• Establish and enhance a centralized, risk-oriented vulnerability management program with patch SLAs and secure configuration standards.
• Address findings from penetration tests.
• Design and implement identity and access security measures, including PAM, JIT access, MFA, SSO, Conditional Access, and least privilege principles.
• Progress the Zero Trust framework across identity, endpoints, networks, cloud, and data.
• Respond to and investigate security incidents through detection, containment, investigation, and recovery processes.
• Lead reviews following incidents to assess and improve response strategies.
• Implement and oversee PHI/PII data protection measures, including auto-classification and DLP across endpoints and cloud services.
• Collaborate with IT, Privacy, Compliance, and application teams to integrate security best practices into system designs, cloud deployments, and the software development lifecycle (SDLC).
• Provide technical guidance and mentorship to other engineers.
• Report directly to the Director of Information Security.
• Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or an equivalent combination of education and experience.
• At least 6–8 years of experience in information security engineering, security operations, or a related field.
• Practical experience with SIEM/MDR and EDR platforms (e.g., CrowdStrike, Microsoft Sentinel) as well as security event monitoring, triage, and tuning.
• In-depth knowledge of network security, firewalls, IDS/IPS, cryptography, and the principles of authentication and authorization.
• Experience in vulnerability management, remediation of penetration test findings, incident response, and endpoint/OS hardening.
• Familiarity with cloud security (Azure and/or AWS) and identity management platforms (SSO, MFA, conditional access).
• Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, HITRUST, NIST, and GDPR.
• Exceptional written and verbal communication skills, capable of explaining complex security concepts to both technical and non-technical audiences.
• Advanced certifications such as CISSP, CISM, GCIA, GCIH, or a cloud security specialty (e.g., Azure/AWS Security) are preferred.
• Experience with privileged access management (PAM), SOAR, and Zero Trust architectures is preferred.
• Knowledge of data loss prevention (e.g., Microsoft Purview) and data classification initiatives is preferred.
• Previous experience in a healthcare, clinical laboratory, or similarly regulated (HIPAA/PHI) environment is preferred.
• Strong analytical and problem-solving capabilities with a risk-based, outcome-focused approach.
• Ability to exercise sound judgment and maintain composure when addressing security incidents under pressure.
• Collaborative and cross-functional mindset with the ability to influence peers and mentor others.
• Self-motivated, detail-oriented, and adept at prioritizing competing demands in a dynamic environment.
• Remote work opportunities available for candidates based in the USA.
• Periodic on-call availability may be necessary to assist with security incident responses.
• Occasional travel may be required for meetings, conferences, or audits.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.