Information Security Engineer

NeoGenomics Laboratories
  • Ramsey, NJ
    4 days ago

    Job Description

    Are you motivated to participate in a dynamic, multi-tasking environment? Do you want to join a company that invests in its employees? Are you seeking a position where you can use your skills while continuing to be challenged and learn? Then we encourage you to dive deeper into this opportunity.

    We believe in career development and empowering our employees. Not only do we provide career coaches internally, but we offer many training opportunities to expand your knowledge base! We have highly competitive benefits with a variety HMO and PPO options. We have company 401k match along with an Employee Stock Purchase Program. We have tuition reimbursement, leadership development, and even start employees off with 16 days of paid time off plus holidays. We offer wellness courses and have highly engaged employee resource groups. Come join the Neo team and be part of our amazing World Class Culture!

    NeoGenomics is looking for an Information Security Engineer who wants to continue to learn in order to allow our company to grow. This is a hybrid in office position with Monday - Friday schedule to work out of either Ramsey, NJ or Fort Myers, FL locations.

    Now that you know what we're looking for in talent, let us tell you why you'd want to work at NeoGenomics:

    As an employer, we promise to provide you with a purpose driven mission in which you have the opportunity to save lives by improving patient care through the exceptional work you perform. Together, we will become the world's leading cancer reference laboratory.

    Position Summary:

    As a Information Security Engineer you support the execution and continuous improvement of NeoGenomics' enterprise information security program This hands-on role

    partners across Security Operations, Governance, Risk and Compliance (GRC), Identity and Access Management (IAM), and Security Architecture to maintain effective security controls and support regulatory and audit requirements. You will manage the day-to-day configuration, monitoring, and optimization of core security tools; supports vulnerability remediation, incident response, and threat-hunting activities; and maintains technical documentation and evidence for audits, customer requests, and regulatory reviews The position requires practical information security experience and the ability to work cross-functionally within a regulated life sciences environment

    Responsibilities:

    • Operate and tune enterprise security platforms including Microsoft Defender, Varonis,

    Mimecast, Zscaler, and Cisco Umbrella Maintain baseline configurations, tune

    detections, and coordinate updates with the managed security services provider

    • Execute the vulnerability management program on Rapid7 with Active Risk Score

    prioritization Partner with Infrastructure, Application, and Lab Operations teams to drive

    remediation of critical and high-risk findings within SLA

    • Support privileged access operations in CyberArk, conditional access policies in Okta

    and Azure AD/Entra ID, and MFA coverage across critical applications Assist with

    quarterly access reviews and joiner/mover/leaver automation

    • Serve as a technical responder during security incidents Perform triage, containment

    actions, evidence collection, and root cause analysis under the direction of Security

    Operations leadership

    • Contribute to detection engineering activities across the SIEM and endpoint tooling
    • Build, test, and tune correlation rules aligned to MITRE ATT&CK techniques relevant to

    healthcare and life sciences

    • Produce technical evidence artifacts for SOX ITGC, HIPAA, SOC 2 Type 2, and

    CAP/CLIA audits Maintain screenshots, exports, and configuration snapshots aligned to

    the control library

    Education, Experience & Qualifications:

    • Bachelor's Degree in Computer Science, Information Security, Information Technology, or

    related field required; equivalent work experience considered

    • 2+ years of hands-on experience in information security engineering, security operations,

    or a closely related technical security role

    • Must be authorized to work in the United States without the need for current or future employer sponsorship.
    • One or more of the following industry certifications preferred: Security+, CySA+, GCIH, GCIA,

    GSEC, or vendor certifications on primary security platforms (Microsoft SC series, Rapid7,

    CyberArk)

    • Demonstrated experience operating enterprise security tooling in at least three of the

    following categories: EDR/XDR, SIEM, vulnerability management, DLP, email security,

    PAM, or identity governance

    • Working knowledge of NIST CSF 20, MITRE ATT&CK, and common security

    frameworks (HIPAA, SOX ITGC, SOC 2)

    • Practical scripting or automation experience with PowerShell, Python, or Power Platform
    • Familiarity with cloud security concepts in Azure and AWS environments
    • Solid understanding of networking fundamentals, endpoint protection, and identity

    protocols (SAML, OAuth, OIDC)

    Numbers & Facts

    LocationRamsey, NJ

    Skills

    • Amazon Web Services (AWS)unmatched
    • Automationunmatched
    • Biologyunmatched
    • Cancerunmatched
    • Career Counselingunmatched
    • Career Developmentunmatched
    • Cisco Network Systemsunmatched
    • Cloud Computingunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • Cross-Functionalunmatched
    • Endpoint Securityunmatched
    • Enterprise Protectionunmatched
    • Environmental Sciencesunmatched
    • Establish Prioritiesunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Health Maintenance Organization (HMO)unmatched
    • Healthcareunmatched
    • Huntingunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information/Data Security (InfoSec)unmatched
    • Knowledge Baseunmatched
    • Laboratory Operationsunmatched
    • Leadershipunmatched
    • Machine Toolunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Multitaskingunmatched
    • Operational Supportunmatched
    • Patient Assessmentunmatched
    • Preferred Provider Organization (PPO)unmatched
    • Protective Servicesunmatched
    • Python Programming/Scripting Languageunmatched
    • Regulationsunmatched
    • Riskunmatched
    • Root Cause Analysisunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Scripting (Scripting Languages)unmatched
    • Security Architectureunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Technical Writingunmatched
    • Testingunmatched
    • Training/Teachingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder