- Company Name
- CBTS
- Job Title
- Security Engineer
- Job Description
-
**Job Title**
Security Engineer
**Role Summary**
Lead the design, implementation, and management of security operations, incident response, and compliance initiatives. Provide technical mentorship, drive cross‑functional security projects, and lay the groundwork for future security leadership.
**Expectations**
- Deliver expert guidance on detection, response, and threat remediation in a regulated environment.
- Mentor and develop a squad of security analysts.
- Champion security tools, processes, and policies aligned with HIPAA, SOC 2, NIST, HITRUST, ISO 27001.
- Own security projects that embed protection into business processes.
- Communicate complex security concepts to non‑technical stakeholders.
**Key Responsibilities**
- Monitor security events, analyze alerts, contain incidents, and conduct root‑cause analyses.
- Design and refine incident‑response workflows and security‑operations playbooks.
- Lead technical mentorship and set quality standards for analysts.
- Develop, enforce, and audit security policies and documentation.
- Perform proactive vulnerability assessments, scans, and risk‑mitigation guidance.
- Collaborate with engineering, legal, and compliance teams to embed security into product and infrastructure.
- Evaluate, select, and implement advanced security solutions (SIEM, MDR/EDR, IDS/IPS, Microsoft Defender, Sentinel, Purview).
- Serve as a security ambassador, translating technical threats into actionable business guidance.
- Stay current on emerging threats and technology trends, shaping internal security roadmaps.
**Required Skills**
- 5+ years in information‑security roles, preferably in healthcare or regulated sectors.
- 5+ years general IT experience (systems, networking, cloud platforms).
- Deep expertise in Microsoft 365 & Azure security (Defender, Sentinel, Purview).
- Proficiency with SIEM, vulnerability management, IDS/IPS, MDR/EDR.
- Strong knowledge of NIST CSF, HITRUST, ISO 27001, HIPAA, SOC 2 compliance.
- Excellent leadership, mentorship, and communication abilities.
- Strong documentation, reporting, and stakeholder‑management skills.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent experience).
- Relevant certifications such as Microsoft Security, ISO 27001 Lead Implementer, HITRUST CSF, or NIST CSF would be advantageous.