Senior Security Engineer

North East Medical Service
  • Daly City, CA
    30+ days ago

    Job Description

    The Senior Security Engineer is responsible for designing, implementing, and governing NEMS enterprise security architecture across all clinic sites, data center environments, and cloud infrastructure. Operating within a hybrid multi-site environment spanning multiple hosting locations with defined security SLAs aligned to HIPAA and NIST standards, this role serves as a hands-on technical leader who collaborates with external security vendors, cloud providers, and internal infrastructure teams to architect and enforce a cohesive, Zero-Trust security environment. The Senior Security Engineer plays a critical role in IAM governance, endpoint protection, lifecycle management, security policy development and enforcement, SOC coordination, and continuous compliance monitoring across endpoints and data centers.

    ESSENTIAL JOB FUNCTIONS:

    • Designs and maintains enterprise security architecture aligned to Zero-Trust principles, NIST Cybersecurity Framework, and organizational risk tolerance across all environments.

    • Defines security baselines and governance frameworks for identity management, endpoint protection, network controls, encryption, and compliance standards.

    • Designs, implements, and governs cloud identity platforms (Azure AD/Entra ID) and hybrid IAM across on-premises and cloud infrastructure.

    • Establishes and enforces multi-factor authentication (MFA) and privileged access management (PAM) policies across all critical systems.

    • Conducts quarterly IAM audits and access reviews ensuring compliance with least-privilege principles and HIPAA-required access controls.

    • Deploys and configures endpoint management agents across 2,500+ endpoints spanning clinic sites and data centers

    • Establishes, enforces, and monitors security patching schedules across all operating systems, applications, and firmware.

    • Deploys and manages Endpoint Detection and Response (EDR) solutions across critical systems and user workstations.

    • Configures Zero-Trust Network Access agents and network micro-segmentation policies to enforce zero-trust principles and limit lateral movement.

    • Develops security policies aligned to NIST CSF, NIST 800-53, HIPAA Security Rule, and HITECH requirements; conduct annual policy reviews.

    • Conducts quarterly security risk assessments and vulnerability assessments in coordination with penetration testing vendors.

    • Establishes incident response frameworks, escalation procedures, and post-incident review processes validated through tabletop exercises and drills.

    • Collaborates with external SOC vendors to define alert severity levels, routing procedures, and response time objectives.

    • Participates in incident triage, investigations, and root cause analysis for significant security events.

    • Establishes network security policies including segmentation, firewall architecture, and encrypted communications standards.

    • Coordinates with infrastructure teams to design and validate Zero-Trust architecture implementation across all domains.

    • Maintains centralized compliance documentation and prepares evidence packages for regulatory audits and HIPAA risk assessments.

    • Serves as primary technical liaison between NEMS and external security vendors; defines SLAs and monitor performance.

    • Mentors junior security team members and provides technical guidance on security best practices and policy implementation.

    • Stays current with evolving threat landscape, regulatory requirements, and industry standards; recommends quarterly security enhancements aligned to NEMS roadmap.

    • Performs other job duties as required by the manager/supervisor.

    Numbers & Facts

    LocationDaly City, CA

    Skills

    • Access Controlunmatched
    • Auditingunmatched
    • Authenticationunmatched
    • Best Practicesunmatched
    • Cloud Computingunmatched
    • Computer Securityunmatched
    • Computer Workstationsunmatched
    • Cryptographyunmatched
    • Documentationunmatched
    • Endpoint Securityunmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • Firewallsunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Identity Data Managementunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Internet Securityunmatched
    • Maintain Complianceunmatched
    • Mentoringunmatched
    • Microsoft Windows Azureunmatched
    • Network Operations Centerunmatched
    • Network Securityunmatched
    • Penetration Testingunmatched
    • Performance Analysisunmatched
    • Policy Developmentunmatched
    • Policy Implementationunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Root Cause Analysisunmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Policyunmatched
    • Service Level Agreement (SLA)unmatched
    • Technical Leadershipunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder