Security Engineer

4 Months ago • 3-5 Years • Cyber Security • $135,000 PA - $160,000 PA

Job Summary

Job Description

The Security Engineer at Lirio is responsible for implementing and operating information security systems, focusing on the cloud-native Precision Nudging platform and internal networks. This role partners with various teams to improve security posture, conduct security operations (monitoring, analysis, remediation), perform testing (internal scans, phishing, penetration testing), and manage incidents. The engineer will contribute to evaluating and maturing security tools (Microsoft Defender suite, Azure Sentinel, Snyk), create security playbooks and dashboards, conduct security architecture reviews, implement security policies, and support compliance audits (HIPAA, HITRUST, SOC2, NIST CSF). Experience with cloud architectures (microservices, containers, Kubernetes, Kafka) and security principles (zero trust, conditional access) is essential. The role involves creating technical documentation, deploying vulnerability scans, conducting risk assessments, and leveraging scripting skills (Python, Bash, Go) for security testing and API integrations.
Must have:
  • 3-5 years experience
  • Microsoft Defender & Azure Sentinel expertise
  • Cloud security experience (microservices, containers)
  • Security operations & incident management
  • Vulnerability management & remediation
  • Security architecture & policy implementation
  • Compliance (HIPAA, HITRUST, SOC2, NIST CSF)
  • Scripting (Python, Bash, Go)
  • KQL for Azure Sentinel
Good to have:
  • CISSP, CEH, CCSP certifications
  • Terraform and Security as Code
  • Experience with Kafka
  • Penetration testing experience
Perks:
  • Medical (HSA available)
  • Dental
  • Vision
  • Short-term & long-term disability (company-paid)
  • Life & AD&D (company-paid)
  • 401K with company match
  • 10 paid holidays + holiday week company closure
  • Flexible time off policy
  • Work from home

Job Details

Position Summary

The Security Engineer is responsible for the implementation and operation of the information security systems at Lirio, including the security of the cloud native implementation of Lirio’s Precision Nudging platform, and the security of its internal business networksThis role partners with Cloud Engineers, Data Engineers, IT and Architecture teams to establish and improve departmental and system security posture.  The Security Engineer is a primary contributor to the security operations at Lirio, and also in evaluating, maturing and implementing the security tools and processes to assure Lirio is well-positioned to protect the privacy of the sensitive data being managed within its network

Essential Duties & Responsibilities

  • Key contributor to security operations & analysis, including 
  • Monitoring of log and alert streams across the Lirio networks 
  • Security event/alert analysis, investigation and remediation
  • Prioritizing and remediating CVEs
  • Performing security access and vendor reviews
  • Execute internal testing activities, including but not limited to internal scans, phishing campaigns, and internal penetration testing
  • Key contributor to incident management activities
  • Strengthen Lirio's security posture by continuously evaluating and maturing security tools such as Defender for Cloud, Defender for Endpoint, Defender for Containers & API's, Azure Sentinel and Snyk security platform
  • Continuously improves the level of automation/information in the security tools by creating security playbooks and dashboards in KQL for Azure Sentinel SIEM
  • Contribute to security architecture reviews of application designs, cloud infrastructure, identifying threats and vulnerabilities to Lirio systems; provide security recommendations and aligning them to GRC risk ranking systems
  • Implement information security policies, controls and systems adhering to Governance, Risk and Compliance standards
  • Create and maintain technical documentation around security practices and initiatives, ensuring detailed records of security protocols, tools, processes, and incident responses
  • Implement and monitor the secure baseline and secure configuration required for production systems at Lirio
  • Supports risk assessments, including privacy risk assessments, as needed
  • Supports compliance and security audits as needed through evidence gathering
  • Deploy and run cloud-based vulnerability scans for internal and external asset
  • Offensive security & penetration testing experience to drive security posture improvements across the organization
  • Conduct black box testing, code reviews, automation, threat modeling and research to reduce risk to Lirio microservices and Infrastructure 

Qualifications

  • 3-5 years of related experience
  • Experience configuring, operating and optimizing the Microsoft Defender suite and Azure Sentinel.
  • Experience with cloud architectures and security, including concepts like microservices, containers, and technologies like Kubernetes and Kafka.
  • Experience in cybersecurity implementations and operations within the healthcare industry.
  • Knowledge in modern network architectures, technologies and network security best practices
  • Knowledge in modern security principles including zero trust, conditional access, defense in depth and attack surface reduction.
  • Experience writing technical Security documentation.
  • Experienced in Terraform and Security As Code methodologies.  
  • Experience writing Azure Sentinel Queries with Kusto Query Language (KQL).
  • Experience supporting GRC adherence from an application security and infrastructure standpoint, codifying controls based on standards like HIPAA HITRUST, SOC2, NIST CSF.
  • Cloud IaaS security experience.
  • Secrets management experience with Azure Key vault
  • Experience analyzing, assessing, and respond to various internet threats; conduct regular security assessments.
  • General *nix and system administration knowledge
  • Scripting knowledge for Security testing and API integrations (Python, Bash, Go etc.)
  • Security Tool Expertise like Microsoft Defender for: Endpoint, for Cloud for Containers, Runtime Security, EDR, Snyk.
  • Microsoft Intune
  • Firewalls & Access Control Lists, Web Application Firewalls, building policies and analyzing flows using SIEM, tcpdump, Wireshark 
  • Understanding of containers and microservices architecture (docker, Kubernetes etc.)
  • Source Code Management: Git, Gradle, Azure Devops
  • Infrastructure as code: Terraform, CloudFormation, Ansible, Chef, Helm
  • Written and verbal communication skills, time management skills, comfortable in a fast-paced environment
  • Collaborative / team oriented, willingness to teach and learn
  • Ability to quickly learn company terminology and processes
  • CISSP, CEH, and/or CCSP  certifications a plus

Benefits

  • Medical (HSA available) 
  • Dental 
  • Vision 
  • Short-term & long-term disability (company-paid) 
  • Life & AD&D (company-paid) 
  • 401K with company match 
  • 10 paid holidays + holiday week company closure 
  • Flexible time off policy 
  • Work from home
  • Salary range: $135,000-$160,000

 

Similar Jobs

OpenGov - DevOps Engineer III

OpenGov

Atlanta, Georgia, United States (Hybrid)
5 Months ago
Skybox Labs - QA Tester | Minecraft (12-14 Month Contract)

Skybox Labs

Burnaby, British Columbia, Canada (Hybrid)
1 Month ago
Paypal - Staff Engineer, Backend (Java)

Paypal

San Jose, California, United States (Hybrid)
6 Months ago
Microsoft - Mechanical Engineer (Taipei)

Microsoft

Taipei City, Taiwan (On-Site)
3 Months ago
MiQ - Software Engineer II

MiQ

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
ION - Network Security Engineer

ION

Italy (Hybrid)
5 Months ago
NVIDIA - GPU Firmware Engineer (RDSS Intern)

NVIDIA

Taipei City, Taiwan (On-Site)
2 Months ago
Blue Yonder - Bug Bounty Technical Lead- (Vulnerability disclosure (VDP))

Blue Yonder

Hyderabad, Telangana, India (On-Site)
6 Months ago
PwC - Senior Associate IT Auditor

PwC

Zagreb, Croatia (On-Site)
6 Months ago
Microsoft - Senior Software Engineer

Microsoft

(On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Dentsu - APAC Data Architect & Engineer

Dentsu

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Revolgy - Customer Support Engineer

Revolgy

United Kingdom (Remote)
2 Weeks ago
The Walt Disney Company - Software Engineer, Test

The Walt Disney Company

Emeryville, California, United States (On-Site)
4 Months ago
Trend Micro - (Sr.) Backend Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
5 Months ago
Nagarro - Principal Engineer, Java Fullstack

Nagarro

Mumbai, Maharashtra, India (On-Site)
5 Months ago
DraftKings - Lead Software Engineer

DraftKings

Sofia, Sofia City Province, Bulgaria (Hybrid)
4 Months ago
ARHS - AWS or Azure Cloud Architect

ARHS

Luxembourg (On-Site)
5 Months ago
BigID - Senior Solutions Engineer, Global Alliances

BigID

London, England, United Kingdom (On-Site)
4 Months ago
GoTo Group - Principal SRE Engineer (SE5)

GoTo Group

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Next Level Business Services - Windows Azure Build Engineer

Next Level Business Services

Redmond, Washington, United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Worldwide

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Cyber Security Jobs

Netflix - Security Engineer L5, Incident Response

Netflix

Warsaw, Masovian Voivodeship, Poland (On-Site)
1 Month ago
Google - Security Engineer, Detection

Google

(On-Site)
4 Months ago
PwC - Cyber Security Associate

PwC

Bangkok, Bangkok, Thailand (On-Site)
5 Months ago
PwC - IN_Associate_Microsoft365_OneCloud _Advisory _Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
5 Months ago
Axinous - Hardware Compliance - Sr. Staff Program Manager

Axinous

San Jose, California, United States (Remote)
3 Months ago
PwC - Cyber Security Architect

PwC

Amsterdam, North Holland, Netherlands (On-Site)
2 Months ago
ION - Markets Product Security Engineer - UK

ION

London, England, United Kingdom (On-Site)
5 Months ago
NVIDIA - Senior Software Security Architect

NVIDIA

Santa Clara, California, United States (On-Site)
2 Months ago
Scopely - Principal Security Engineer

Scopely

Seville, Andalusia, Spain (Hybrid)
5 Months ago
PwC - Senior Associate IT Auditor

PwC

Zagreb, Croatia (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded