All Jobs Vacancy

Security Engineer with Azure and Healthcare Domain : Remote Opportunity : Long-Term Contract

Posted Today by HAN IT Staffing Inc.

Job Requirements

  • Experience 8+ years of hands-on security engineering experience, including at least 3 years in a regulated healthcare, health payments or financial services environment.
  • Healthcare security Practical experience implementing the HIPAA Security Rule inside commercial technology environments technical safeguards as built and operated not policy authorship alone.
  • Commercial compliance frameworks Demonstrated experience supporting SOC 2 Type II and or HITRUST CSF assessments and working knowledge of PCI DSS as it applies to card-based payment flows.
  • Azure Demonstrated depth in Microsoft Azure security network security groups private endpoints and Entra ID.
  • Candidates whose cloud experience is exclusively AWS are not a fit for this engagement.
  • Practical experience securing VMware-based infrastructure in co-located or on-premises data centers and the network segmentation east-west controls and hardening standards that apply thereIdentity.
  • Hands-on experience with hybrid identity across Okta Microsoft Entra ID and on-premises Active Directory — federation SSO conditional access privileged access management.
  • Able to produce control narratives and diagrams that satisfy auditors and enterprise client security teams, and to hold a peer-level technical conversation with engineers.
  • Familiarity with NIST SP 800-53 and the NIST Cybersecurity Framework as control references.
  • Azure security certification or equivalent demonstrated capability.
  • Web and edge security Collaborate with security and infrastructure teams to review rationalize and remediate web application firewall and edge security configurations including rules exceptions proxying DNS traffic paths, and validation of protections across relevant platformsIdentity and access. Remediate findings in the IAM implementation spanning Okta Microsoft Entra ID and on-premises Active Directory including service accounts and non-human identities.
  • Control documentation and evidence Update security control narratives architecture and data flow diagrams, and system stand up to SOC 2 HITRUST HIPAA and PCI DSS assessment.
Rate:
Not specified
Location:
Remote
IR35 Status:
Outside
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Share job