Search Remote Jobs

Security Operations Engineer

Job not on LinkedIn

🔥 0 minutes ago

🌐 United States, Netherlands, +1 more countries – Remote

infoinfo

🍂 Massachusetts – Remote

infoinfo

💵 $110 - $120 / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🛡️ Security Operations

👻 Ghost score 20%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of DeepHealth

DeepHealth

11 - 50 employees

🏥 Healthcare

💼 Consulting

📦 Logistics

💰 $225k Grant on 2019-08

Healthcare • Consulting • Logistics

DeepHealth is a global leader in AI-powered health informatics, providing innovative solutions designed to enhance operational efficiency and clinical confidence in radiology. As a wholly-owned subsidiary of RadNet, Inc. , DeepHealth offers a comprehensive suite of diagnostic and imaging tools, including the DeepHealth OS, a pioneering cloud-native operating system. Their AI-powered solutions support large-scale diagnostic programs and streamline workflows in areas such as breast, prostate, lung, and brain cancer detection. DeepHealth collaborates with leading healthcare institutions worldwide to transform radiology practices and improve care delivery.

📋 Description

• Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments • Develop and maintain SIEM detection content, correlation rules, and SOAR response automation • Onboard log sources and telemetry feeds while validating ingestion, parsing, and field normalization • Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation • Integrate security tooling with adjacent platforms through APIs • Implement security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure • Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework • Implement policy-as-code and preventive guardrails • Support cloud security posture management, including finding deduplication, theme mapping, and routing to owning teams • Harden compute, storage, database, container, and serverless cloud resources against established benchmarks • Configure and maintain Microsoft 365 and Entra ID security controls, including conditional access, identity protection, and Defender workloads • Implement least-privilege access models, roles, and policies across cloud identity systems • Implement container and Kubernetes security controls, including RBAC, workload security standards, image scanning, and runtime protection • Maintain secrets management practices and eliminate hard-coded credentials • Operate vulnerability management tooling and translate scanner output into prioritized, owner-routed findings • Provide remediation guidance and implement fixes for security-owned tooling and configurations • Support penetration test and vulnerability assessment remediation tracking • Support incident detection and response through log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review • Support escalations from the external managed security partner • Tune alerts and contribute to post-incident reviews, tabletop exercises, and resilience testing • Document security control changes, validation criteria, and rollback plans • Produce runbooks, playbooks, technical procedures, code, and configuration • Support audits, certifications, and customer assurance activities with technical evidence • Maintain inventory of security tooling, control coverage, licensing position, and operating status • Maintain confidentiality of security testing results, control configurations, and investigative material • Report to the Director, Security Operations, with future reporting to the Manager, Security Operations

🎯 Requirements

• 4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role • Bachelor's degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience • 2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred • 2+ years operating and tuning a SIEM platform, including detection content and log sources • 1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment • Working knowledge of security automation; scripting and infrastructure-as-code experience required • Working knowledge of cloud security posture management and preventive controls • Working knowledge of container and Kubernetes security, including role-based access control and image scanning • Working knowledge of secrets management tooling and practices • Practical experience with endpoint detection and response tooling • Working knowledge of vulnerability management and risk-based finding prioritization • Scripting capability in Python, PowerShell, or Bash • Familiarity with NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2 • Ability to communicate technical findings clearly to technical and non-technical audiences • Ability to manage assigned work independently and escalate appropriately • Availability to support incident response outside standard business hours as required • Microsoft Office experience • Must be legally authorized to work in the United States without current or future sponsorship from DeepHealth • Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification (Preferred) • Experience in healthcare, medical device, or another regulated industry and familiarity with HIPAA obligations (Preferred) • Experience working alongside or integrating with a managed security service provider (Preferred)

🏖️ Benefits

• Remote work arrangement • Option to come into the Somerville office, but not required • Up to 10% domestic/international travel • Opportunity to work with global operating teams and security environments • Professional development through hands-on work with cloud security, automation, compliance, and regulated healthcare environments

Apply Now

Similar Jobs

🔥 23 hours ago

Forward Financing

201 - 500

💸 Finance

💳 Fintech

🤝 B2B

Security Operations Manager defending Forward Financing’s fintech infrastructure, SaaS, endpoints, and identity systems. Leading incident response, detection engineering, risk assessments, and AI security strategy.

🇺🇸 United States – Remote

💵 $172k - $237k / year

💰 $250M Debt Financing on 2021-05

⏰ Full Time

🟠 Senior

🔴 Lead

🛡️ Security Operations

🕒 Yesterday

Included Health

1001 - 5000

🏥 Healthcare

☁️ SaaS

👥 HR Tech

Senior Security Operations Engineer protecting Included Health’s integrated virtual care and healthcare navigation platform. Designing DLP controls, investigating data exfiltration, and automating security response.

🕒 Yesterday

phia, LLC

11 - 50

💼 Consulting

🎖️ Defense

📦 Logistics

Cyber Operations Analyst supporting phia’s federal CSOC with 24x7 threat monitoring and incident management. Applying AI/ML, SIEM/SOAR, threat intelligence, and cloud security expertise to improve detection and response.

🕒 2 days ago

Unqork

201 - 500

🛡️ Insurance

🏥 Healthcare

💼 Consulting

Security Operations Analyst defending Unqork’s AI-powered enterprise application platform. Monitoring threats, engineering SIEM/SOAR detections, and supporting incident response and compliance.

🕒 5 days ago

FICO

1001 - 5000

💼 Consulting

🛡️ Insurance

🏥 Healthcare

Senior incident response engineer strengthening security operations at FICO, a global analytics software company. Leading tabletop exercises, enterprise incident response, forensics, and cloud security readiness.