Jobs Companies OnMed Senior Infrastructure & Security Engineer

À propos de ce poste Senior Infrastructure & Security Engineer chez OnMed

OnMed · Sur site · White Plains, New York, United States

Who We Are and Why Join Us  

At OnMed our purpose is simple but powerful...to improve the quality of life and sense of well-being in our communities by bringing access to healthcare to everyone, everywhere. Our path to everywhere has already begun, with our innovative CareStation, a small but mighty, Clinic-in-a-Box, bringing #healthcareaccess anywhere with an outlet to plug it in. Poised to become a key component in America’s public health infrastructure, the OnMed CareStation is the only tech-enabled, AI-powered, human-delivered, hybrid care solution that combines the comprehensive experience, trust and outcomes of a clinic,  with the rapid scalability of virtual care.  

At OnMed, every role, everyday, is directly impacting the communities we serve. You’ll join a high-performing purpose-driven team, innovating to break down the barriers that keep people from the care they need.  

This is not just a job...it's a movement to bring access to healthcare where and when people need it most. It’s healthcare that shows up. 

Who You Are 

You are a hands-on, deeply technical infrastructure engineer who treats security as part of the job rather than someone else’s department. You are fluent in the Microsoft Azure and Entra ecosystem, you understand networking and firewall rules cold, and you move comfortably between building cloud infrastructure, administering identity and endpoints, tuning detections in an XDR/SIEM console, working an incident to ground, and closing out a ticket queue. You automate what should be automated, you document as you go, and you would rather fix the underlying cause than absorb the same escalation twice. 

You’ll be the front line dedicated engineer in this seat, working directly with the Head of Security and Infrastructure, who owns the architecture, the compliance program, and the vendor relationships. You take the operational reins: you’ll inherit an environment currently supported through an interim vendor engagement, so you’re someone who can work productively from imperfect documentation and improve it as you go. You thrive in a new, fast-paced, high-demand environment and take pride in the availability, security, and resilience of the systems that protect our patients’ healthcare data. 

 

The Role 

This is a hands-on infrastructure and security engineering role reporting to the Head of Security and Infrastructure. The role owns day-to-day Azure infrastructure and identity operations, IT service management, security engineering and incident response, the operational posture of customer- and public-facing endpoints, and compliance evidence and vendor coordination — taking over work currently supported through an interim vendor engagement. 

 

Key Responsibilities 

Infrastructure & Cloud Operations 

  • Owning day-to-day Microsoft Azure operations hands-on — resource configuration, patching, backup and recovery, monitoring, and cost and capacity hygiene. 
  • Building and maintaining infrastructure across cloud and on-prem, and automating provisioning and routine administration through scripting. 
  • Administering identity and access in Entra ID — provisioning and deprovisioning, access reviews, privileged account audits, MFA/SSO enforcement, and vendor access processes. 
  • Managing endpoint administration and device hardening across corporate laptops, mobile, and field-deployed customer-facing systems. 
  • Maintaining and documenting network architecture in partnership with the Head of Security and Infrastructure — segmentation, firewall rule sets, VPN, and Zero Trust access for the remote workforce and field devices. 

IT Service Management 

  • Running IT service management end to end: ticket intake, triage, assignment, escalation coordination, and resolution tracking across OnMed, its managed service providers, and other vendors — with clear SLAs and no dropped handoffs. 
  • Serving as the technical escalation point for infrastructure and security issues, including after-hours events affecting internal systems and patient-facing endpoints. 
  • Building the runbooks, documentation, and self-service that reduce repeat tickets over time. 

Security Engineering & Operations 

  • Deploying, configuring, and managing security controls hands-on across cloud, network, and endpoint environments — implementing the architecture, not just monitoring it. 
  • Hardening the Azure and M365/Entra environment — network security groups, firewall rules, conditional access, and encryption at-rest and in-transit across corporate, field, and customer-facing endpoints. 
  • Operating and tuning the security stack day to day: XDR/MDR, SIEM, and SOC workflows — refining detections, triaging alerts, and working them hands-on. 
  • Executing incident response: triage, containment, eradication, root cause analysis, and documentation, escalating to the Head of Security and Infrastructure as severity warrants. 
  • Running vulnerability management — scanning, prioritization, patch and configuration remediation, and tracking exceptions to closure. 
  • Contributing to security review of integrations, vendor systems, and system designs, and partnering with engineering on remediation. 

Customer- and Public-Facing Endpoint Fleet 

  • Owning the operational and security posture of customer- and public-facing endpoints deployed in unattended settings — device identity, network isolation, remote access, telemetry, physical tamper considerations, and secure update and recovery paths. 
  • Partnering with product and field operations teams so that manageability and security are designed into new endpoint deployments rather than retrofitted after they ship. 

Compliance Support & Vendor Coordination 

  • Producing and maintaining control evidence for SOC 2, HITRUST, FedRAMP, HIPAA, and related frameworks in support of the compliance program — refreshing evidence on cadence, responding to auditor and assessor requests, and tracking assigned findings through to remediation. 
  • Implementing HIPAA-scoped PHI handling practices: data classification, Security Rule technical safeguards, minimum necessary access, and breach notification readiness. 
  • Serving as the day-to-day technical point of contact for managed service and managed security providers — coordinating work, escalating issues, and validating that deliverables actually landed. 
  • Supporting vendor and third-party risk assessment, security awareness training, and responses to customer and vendor security questionnaires. 

Transition & Stabilization (First 90 Days) 

  • Taking over the operational work currently covered by an interim vendor engagement, working alongside the Head of Security and Infrastructure through the handoff. 
  • Building out the asset, identity, and network documentation the environment is missing, and establishing the operating cadence for tickets, patching, access reviews, and evidence collection. 

Requirements

 

Knowledge, Skills and Abilities 

Must Have: 

  • Deep, hands-on experience building, deploying, and operating infrastructure and security controls across multiple technology stacks — engineering it yourself, not directing others. 
  • Strong hands-on expertise with Microsoft Azure operations and security, and the M365/Entra ID stack — identity, network security, and workload protection. 
  • Excellent understanding of networking and firewall rules — segmentation, NGFW and Azure Firewall rule administration, VPN, IDS/IPS, and Zero Trust Network Access across remote users and field devices. 
  • Practical IT service management experience — working an ITSM platform and queue day to day, including intake, triage, escalation, and resolution tracking across internal teams and external vendors. 
  • Endpoint management and device hardening experience, with encryption at-rest and in-transit across cloud, corporate, and field-deployed devices. 
  • Hands-on experience operating XDR/MDR, SIEM, and SOC environments — tuning detections and working alerts directly. 
  • Hands-on incident response experience — triage, containment, root cause analysis, and documentation. 
  • Vulnerability management experience — scanning, prioritizing, and driving remediation to closure. 
  • Scripting and automation ability (e.g., PowerShell, Python, KQL) to automate administration, hardening, detection, and response. 
  • Working knowledge of at least one major compliance framework (SOC 2, NIST, CIS, HITRUST, or FedRAMP) and practical experience producing control evidence for auditors. 
  • Working knowledge of HIPAA-scoped PHI handling, data classification, and Security Rule technical safeguards. 
  • Experience coordinating with managed service or managed security providers as part of a small internal team. 
  • Clear written communication and a documentation habit — this role writes runbooks, evidence narratives, and incident write-ups regularly. 
  • Comfort working from imperfect documentation in a rapidly growing, fast-paced, high-demand environment. 

 

Nice-to-Have: 

  • Experience securing IoT, embedded devices, or infrastructure deployed in unattended public settings. 
  • Application security exposure — reviewing integrations, code, or system designs for vulnerabilities, with familiarity with the OWASP Top 10 and SAST/DAST tooling. 
  • Direct experience carrying an organization through a SOC 2, HITRUST, or FedRAMP audit or authorization cycle. 
  • Hands-on experience with Palo Alto NGFW, Azure Firewall administration, and Cloudflare security services. 
  • Advanced security operations automation (e.g., leveraging Elastic). 
  • Experience with ITSM platforms and endpoint/RMM tooling (e.g., ServiceNow, Jira Service Management, Freshservice, Microsoft Intune). 
  • Experience implementing and managing cloud service provider, SaaS, and PaaS security. 
  • Infrastructure-as-code experience (e.g., Terraform, Bicep, ARM). 
  • Familiarity with securing AI tools and platforms in use across an organization, or with GRC and compliance tracking platforms. 
  • Prior healthcare or other regulated-industry experience. 

 

Education and Experience 

  • Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent practical experience. 
  • 7+ years of hands-on experience across IT infrastructure and information security, preferably in a regulated industry. 
  • 5+ years operating and securing cloud (Azure preferred) and on-prem environments hands-on. 
  • AZ-104, AZ-500, Security+, or CySA+ preferred; GSEC, GCIH, ITIL Foundation, or CISSP/CISM are good nice-to-haves. 

Benefits

OnMed provides a competitive salary and benefits package, including unlimited PTO and paid holidays. 

The base salary for this role is $150,000 - $160,000 commensurate with the candidate's experience.

OnMed is a proud equal opportunity employer. All qualified applicants will be considered without regard to race, color, creed, religion, gender, sexual orientation, national origin, genetic information, disability, age, marital status, veteran status, or any other category protected by law. 

 

Prêt à postuler chez OnMed ?
Postuler chez OnMed

Comment se compare ce salaire pour Security Engineer

Ce poste paie $155,000/yrdans la fourchette habituelle pour les postes Security Engineer.

$107,662 la médiane $190,500 $271,000

Fourchette typique $147,225–$230,000/yr, à partir de 961 annonces Security Engineer comparables sur JobsRadar (rémunération annualisée en USD). Voir les aperçus de salaire pour Security Engineer →

À propos de OnMed

OnMed is the premier tech-enabled hybrid care company partnering with public and private organizations to reimagine healthcare access and improve health equity in communities across the country. With its patented CareStations, OnMed combines the best elements of traditional primary, urgent, or post-acute care facilities and virtual telemedicine to deliver convenient, affordable care to underserved communities, anywhere they are. OnMed licenses its cutting-edge technology and care delivery model to a wide range of organizations, including governments, employers, colleges, healthcare provider systems, payors, and high-traffic venues. OnMed is paving the way for everyday healthcare, everywhere.

Voir tous les emplois chez OnMed →

Emplois similaires

OnMed
Senior Security Engineer
OnMed
⚡ Postuler tôt White Plains, New York, United... Sur site $130,000–$140,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 mois
LawnStarter
Lead Security Engineer
LawnStarter
⚡ Postuler tôt Brazil · lieu restreint $80,000–$100,000
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
One Park Financial
Senior Cybersecurity Engineer
One Park Financial
⚡ Postuler tôt Santo Domingo, Distrito Nacion... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
LatamCent
Lead Security and Infrastructure Engineer
LatamCent
⚡ Postuler tôt Tampa, Florida · lieu restreint $170,000–$210,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
LanceDB
Senior Product Security Engineer
LanceDB
⚡ Postuler tôt United States | Canada Sur site $180,000–$250,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
incident.io
Security Engineer
incident.io
⚡ Postuler tôt London · lieu restreint £110,000–£200,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Teleport
Senior Software Engineer, Security - UK
Teleport
⚡ Postuler tôt United Kingdom (Remote) · lieu restreint £122,400–£204,600
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Teleport
Senior Software Engineer, Security - US
Teleport
⚡ Postuler tôt United States (Remote) · lieu restreint $189,040–$342,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Baseten
Security Engineer
Baseten
⚡ Postuler tôt San Francisco Hybride $150,000–$250,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez OnMed

Voir tous les emplois chez OnMed →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit