North East Medical Services (NEMS) Logo

North East Medical Services (NEMS)

SENIOR SECURITY ENGINEER

Posted One Month Ago
Be an Early Applicant
In-Office
94014, Daly City, CA, USA
156K-180K Annually
Senior level
In-Office
94014, Daly City, CA, USA
156K-180K Annually
Senior level
Designs and governs enterprise Zero-Trust security architecture across on-premises, clinic, and cloud environments. Leads IAM, endpoint protection, EDR, patching, network segmentation, security policy development, risk and vulnerability assessments, incident response, SOC coordination, and compliance with NIST and HIPAA. Mentors team members and liaises with external vendors and auditors.
The summary above was generated by AI

The Senior Security Engineer is responsible for designing, implementing, and governing NEMS enterprise security architecture across all clinic sites, data center environments, and cloud infrastructure. Operating within a hybrid multi-site environment spanning multiple hosting locations with defined security SLAs aligned to HIPAA and NIST standards, this role serves as a hands-on technical leader who collaborates with external security vendors, cloud providers, and internal infrastructure teams to architect and enforce a cohesive, Zero-Trust security environment. The Senior Security Engineer plays a critical role in IAM governance, endpoint protection, lifecycle management, security policy development and enforcement, SOC coordination, and continuous compliance monitoring across endpoints and data centers. 


ESSENTIAL JOB FUNCTIONS:

  • Designs and maintains enterprise security architecture aligned to Zero-Trust principles, NIST Cybersecurity Framework, and organizational risk tolerance across all environments. 

  • Defines security baselines and governance frameworks for identity management, endpoint protection, network controls, encryption, and compliance standards. 
  • Designs, implements, and governs cloud identity platforms (Azure AD/Entra ID) and hybrid IAM across on-premises and cloud infrastructure. 
  • Establishes and enforces multi-factor authentication (MFA) and privileged access management (PAM) policies across all critical systems. 
  • Conducts quarterly IAM audits and access reviews ensuring compliance with least-privilege principles and HIPAA-required access controls. 
  • Deploys and configures endpoint management agents across 2,500+ endpoints spanning clinic sites and data centers 
  • Establishes, enforces, and monitors security patching schedules across all operating systems, applications, and firmware. 
  • Deploys and manages Endpoint Detection and Response (EDR) solutions across critical systems and user workstations. 
  • Configures Zero-Trust Network Access agents and network micro-segmentation policies to enforce zero-trust principles and limit lateral movement. 
  • Develops security policies aligned to NIST CSF, NIST 800-53, HIPAA Security Rule, and HITECH requirements; conduct annual policy reviews. 
  • Conducts quarterly security risk assessments and vulnerability assessments in coordination with penetration testing vendors. 
  • Establishes incident response frameworks, escalation procedures, and post-incident review processes validated through tabletop exercises and drills. 
  • Collaborates with external SOC vendors to define alert severity levels, routing procedures, and response time objectives. 
  • Participates in incident triage, investigations, and root cause analysis for significant security events. 
  • Establishes network security policies including segmentation, firewall architecture, and encrypted communications standards. 
  • Coordinates with infrastructure teams to design and validate Zero-Trust architecture implementation across all domains. 
  • Maintains centralized compliance documentation and prepares evidence packages for regulatory audits and HIPAA risk assessments. 
  • Serves as primary technical liaison between NEMS and external security vendors; defines SLAs and monitor performance. 
  • Mentors junior security team members and provides technical guidance on security best practices and policy implementation. 
  • Stays current with evolving threat landscape, regulatory requirements, and industry standards; recommends quarterly security enhancements aligned to NEMS roadmap. 
  • Performs other job duties as required by the manager/supervisor. 
Qualifications
  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Information Security, or a related STEM field required.  
  • Equivalent combination of 8+ years of directly relevant security engineering and IAM experience may be substituted for degree requirement.  
  • Certified Information Systems Security Professional (CISSP) is required.   
  • Minimum 5 years of enterprise security engineering experience including architecture design, security policy governance, hands-on technical implementation, and demonstrated security leadership owning outcomes across infrastructure, applications, and networks. 
  • Minimum 3 years of hands-on experience in each of the following: designing and implementing identity and access management; designing and implementing endpoint detection and response solutions; developing and maintaining security policies aligned to NIST or ISO 27001 frameworks; and coordinating with external security vendors, SOCs, and managed security service providers. 
  • Demonstrated experience conducting security risk assessments, vulnerability management, and threat analysis.  
  • Demonstrated experience with incident response coordination, root cause analysis, and post-incident reviews.  
  • Demonstrated experience with healthcare compliance frameworks including HIPAA Security Rule and HITECH requirements.  
  • Experience in healthcare information technology or Federally Qualified Health Center (FQHC) environments preferred.   

 

LANGUAGE:


  • Must be able to read, write, and speak English fluently. 
  • Ability to speak and/or understand Chinese (Cantonese or Mandarin) is an asset.

STATUS:

  • This is an FLSA exempt position.
  • This is not an OSHA high-risk position.
  • This is a Full Time position.

NEMS is proud to be an Equal Opportunity Employer welcoming diversity in our workforce. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

NEMS BENEFITS: Competitive benefits, including free medical, dental and vision insurance for employee, spouse and/or children; and company contribution to 401(k).


Similar Jobs

12 Days Ago
Easy Apply
Hybrid
San Francisco, CA, USA
Easy Apply
142K-212K Annually
Senior level
142K-212K Annually
Senior level
Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
Develop and operate detection and response capabilities across enterprise, cloud, and product environments. Responsibilities include building detections-as-code, triaging alerts, leading incident response and forensic investigations, threat hunting, automating workflows, maintaining SIEM and security data pipelines, developing AI-enabled security tooling, and participating in on-call rotations. The role also involves threat intelligence collaboration, security engineering mentorship, and continuous improvement of detection and response systems.
Top Skills: AICi/CdCloud PlatformsData PipelinesGitGitGoPythonSecurity Data LakesSIEMSplunkSQL
20 Days Ago
Easy Apply
Hybrid
San Francisco, CA, USA
Easy Apply
142K-212K Annually
Senior level
142K-212K Annually
Senior level
Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
Build and maintain scalable security observability, detection, and response systems. Develop AI- and ML-based detections, normalize large-scale security logs, automate incident workflows, respond to alerts and threats, conduct investigations and threat hunts, and participate in detection and response on-call rotations.
Top Skills: Centralized LoggingCi/CdData LakesData PipelinesGitGitGoMachine Learning ModelsPythonSIEM
2 Days Ago
In-Office
146K-230K Annually
Senior level
146K-230K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads spacecraft and avionics cybersecurity architecture, cryptographic subsystem integration, secure boot, key storage, red/black isolation, threat assessment, and security verification. Designs constellation and vehicle networks across RF and optical links, manages requirements and supplier coordination, supports DoD RMF compliance, and briefs customers and government stakeholders on product-level security.
Top Skills: Anti-Tamper DesignAvionics ArchitecturesCryptographyDod Risk Management FrameworkEmbedded LinuxFlight Software ArchitecturesIpsecIpv6LanMplsOptical LinksQosRed/Black SeparationRf LinksRoot Of TrustSecure BootTempestVirtualizationVlan SegmentationVpn TunnelingWanWlan

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account