← Back to jobs

Cybersecurity Engineer I

Skills

active directorycloudcloud securitycybersecuritydlpdnsedrentra idfirewallhipaalinuxnessusnetworkingnistpowershellpythonservice deskservicenowsiemtcp ipvpnvulnerability scanning

Description

The Cybersecurity Engineer I provides hands-on operational support across the cybersecurity program while building the technical depth to grow a career in the field. Working under the direction and mentorship of senior engineers, the Engineer I focuses on execution and follow-through—running vulnerability scans, triaging alerts and data protection events, driving remediation to closure with system and application owners, managing security request and exception queues, maintaining security tool coverage, and producing recurring metrics and documentation. This is not a purely entry-level position; the successful candidate arrives with a working foundation in cybersecurity concepts, operating systems, and networking, and—just as important—a genuine passion for cybersecurity and a real desire to expand that knowledge. The role offers exceptional exposure across a healthcare security program alongside experienced engineers who invest in developing the people around them and is an outstanding learning opportunity for someone who enjoys working on a great team in a fast-paced environment. The position is hybrid, pairing remote flexibility with regular on-site presence, because much of the mentoring and knowledge sharing that makes this such a strong learning opportunity happens through in-person collaboration. As with every member of this team, the Engineer I supports incident

Duties and Responsibilities
•
Working from established runbooks and procedures under the direction and mentorship of senior engineers, run scheduled and ad hoc vulnerability scans using platforms such as Rapid7 InsightVM and Tenable Nessus, validate scan coverage and credentialed scan success, and prepare findings for senior review and risk-based prioritization.
•
Track vulnerability, audit, and assessment remediation to closure—maintaining tickets with IT, infrastructure, application, and vendor owners, validating completed fixes, and escalating stalled findings.
•
Perform first-level triage of security alerts, user-reported phishing, and findings escalated by the managed security services provider; gather context, document observations, and escalate according to defined criteria.
•
Support data protection and identity operations, including initial triage of Data Loss Prevention alerts in platforms such as Microsoft Purview and Varonis, periodic access and privileged access reviews, and cleanup of stale accounts and entitlements.
•
Own the intake and coordination of cybersecurity request queues—exception requests, security reviews, vendor questionnaires, and application requests—verifying completeness and preparing submissions for senior review.
•
Maintain the health and coverage of security tooling such as EDR, device management, and logging agents; produce recurring metrics, dashboards, and runbooks; and support the security awareness and phishing simulation program.
•
Serve as part of a dynamic team responsible for cybersecurity incident response, supporting evidence and log collection, documentation, and directed containment tasks, and collaborating with ISS, Privacy, and Compliance.
•
Share in the team’s on-call rotation, joining after a ramp-up period of roughly three months and with senior engineer support throughout; because the rotation is shared across the full team, it comes around about once every two months.
•
Pursue certification, cross-training, and progressive ownership that build technical depth and advance the individual’s cybersecurity career.

Education, Training and Certification
•
Associate’s or Bachelor’s degree in Cybersecurity, Information Technology, or a related field is preferred; equivalent professional experience, military experience, or certifications will be considered.
•
A foundational security certification such as CompTIA Security+, (ISC)² SSCP, or CompTIA CySA+ is strongly preferred; candidates hired without one are expected to obtain one within twelve months. Progress toward certifications such as Microsoft SC-900, SC-200, or AZ-500 is supported through the team’s training program.
Knowledge and Experience
•
One to three years of experience in information technology, service desk, systems or network administration, or cybersecurity, with hands-on security exposure; relevant internship, military, or substantive home lab experience will be considered.
•
A solid grasp of foundational cybersecurity concepts—defense in depth, least privilege, risk-based prioritization, CVSS scoring, and common attack types such as phishing, ransomware, and credential theft—plus conceptual familiarity with MITRE ATT&CK and the NIST Cybersecurity Framework, and awareness of HIPAA requirements for protecting ePHI.
•
Working knowledge of Windows and Linux operating systems, Active Directory and Microsoft Entra ID concepts, and networking fundamentals including TCP/IP, DNS, firewalls, VPN, and proxy services; exposure to PowerShell or Python and to an ITSM process such as ServiceNow is a plus.
•
Familiarity with the major categories of enterprise security tooling—EDR, SIEM, vulnerability scanning, email security, DLP, and cloud security—with hands-on experience in at least one; breadth and aptitude matter more than depth at this level.
Skills and Abilities
•
A genuine passion for cybersecurity and a real desire to expand that knowledge, demonstrated through curiosity, self-directed learning, and enthusiasm for unfamiliar problems.
•
Enjoys working on a great team in a fast-paced environment, and is energized rather than discouraged by shifting priorities and multiple concurrent assignments.
•
Strong follow-through and ownership, with the persistence to drive work to closure across teams that do not report to this role, and the judgment to know when to escalate rather than assume.
•
Clear written communication, disciplined documentation habits, attention to detail, and discretion in handling confidential information.

Get similar jobs in United States by email

We'll email you when new jobs similar to this one appear.

Similar jobs

Explore more Security Engineer jobs in United States.

Finding similar jobs…