Why This Role Stands Out
This hybrid role offers a fantastic opportunity to advance your career by implementing cutting-edge security solutions in complex cloud and on-premises environments, including Microsoft Azure and VMware. You'll thrive here if you have hands-on experience securing regulated industries and a passion for practical security engineering, making a significant impact on KBC Technologies' robust security posture. Don't miss the chance to apply for this exciting position!
Quick Overview
Job Description
About the Role
We are looking for an experienced Senior Security Engineer to support security engineering, compliance and remediation activities across cloud, on-premises and hybrid environments.
The ideal candidate will have strong hands-on experience securing Microsoft Azure environments, hybrid identity platforms and VMware infrastructure, with experience working in regulated healthcare, health payments or financial services environments.
This role requires practical implementation experience with security controls rather than policy-writing experience alone. The candidate should be comfortable working directly with engineering teams while also producing technical documentation and evidence suitable for auditors and enterprise security teams.
Key Responsibilities
Cloud & Infrastructure Security
- Design, implement and maintain security controls across Microsoft Azure environments.
- Work with Azure security capabilities including:
- Network Security Groups (NSGs)
- Private Endpoints
- Microsoft Entra ID
- Azure networking and segmentation
- Review and remediate Azure security configurations and findings.
- Secure VMware-based infrastructure across co-located and on-premises data centers.
- Implement and maintain network segmentation, east-west traffic controls and infrastructure hardening standards.
Healthcare & Regulatory Security
- Implement practical security controls aligned with the HIPAA Security Rule within commercial technology environments.
- Support security assessments and compliance activities for:
- SOC 2 Type II
- HITRUST CSF
- PCI DSS
- Understand PCI DSS requirements as they apply to card-based payment flows.
- Translate regulatory and compliance requirements into practical technical controls.
- Support audits by providing technical evidence, control narratives and architecture documentation.
Identity & Access Management
- Manage and remediate identity and access security issues across hybrid environments.
- Work hands-on with:
- Okta
- Microsoft Entra ID
- On-premises Active Directory
- Implement and troubleshoot:
- Federation
- SSO
- Conditional Access
- Privileged Access Management (PAM)
- Service accounts
- Non-human identities
- Identify and remediate IAM security findings across hybrid environments.
Web & Edge Security
- Collaborate with security and infrastructure teams to review, rationalize and remediate WAF and edge security configurations.
- Review:
- WAF rules
- Exceptions
- Proxy configurations
- DNS traffic paths
- Network traffic flows
- Validate that security protections are functioning correctly across relevant platforms.
Security Documentation & Audit Support
- Create and maintain security control narratives.
- Develop and update:
- Architecture diagrams
- Data-flow diagrams
- Security control documentation
- System/environment documentation
- Prepare technical evidence to support SOC 2, HITRUST, HIPAA and PCI DSS assessments.
- Work directly with auditors and enterprise security teams.
- Communicate effectively with engineers and participate in peer-level technical discussions.
Required Skills & Experience
- 5+ years of hands-on Security Engineering experience.
- At least 3 years of experience in a regulated healthcare, health payments or financial services environment.
- Strong practical experience implementing the HIPAA Security Rule in commercial technology environments.
- Experience supporting SOC 2 Type II and/or HITRUST CSF assessments.
- Working knowledge of PCI DSS, particularly in card-based payment environments.
- Strong hands-on Microsoft Azure security experience.
- Experience with:
Similar jobs
- CD
Identity Governance and Security Posture Analyst
NewCloud Destinations LLC
United States🇺🇸Remote21 hours agoStakeholder ManagementAdministrative - GI
On-Site Senior Certified Application Security Analyst (NIST SP 800-53/Cybersecurity/CSF controls/ Microsoft 365/Defender/Purview/ CISA/CRISC/CGRC/CISM/CISSP)
NewGlobal Information Services
Tallahassee, FL🇺🇸On-site21 hours agoHIPAAPowerShellTechnology - MS
Sr. Network Security Engineer III (6852) with Security Clearance
NewMetroStar Systems Inc.
Washington, DC🇺🇸$207k - $320k/yrHybrid21 hours agoAgileZero TrustTechnology - IT
CyberArk Consultant
Infosys Technologies Ltd
Richardson, TX🇺🇸On-site2 weeks agoAWSAzureGoogle Cloud+1Technology - IN
CRIBL Data Modeling Security Engineer
NewInnosoul inc
United States🇺🇸On-site21 hours agoBashPythonTechnology - ST
IAM Engineer
NewSRI Tech Solutions
United States🇺🇸Hybrid21 hours agoSQLMFAOAuth+10Technology