Network Security Engineer
Listed on 2026-08-28
-
IT/Tech
Cybersecurity
Description
MDVIP:Transforming Primary Care, One Patient at a Time
MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work® since 2018, MDVIP is committed to excellence in patient care and employee satisfaction.
PositionSummary
The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers.
This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization’s on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations — including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score — while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule.
Key Responsibilities Security Remediation & Compliance- Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third‑party resources to ensure timely delivery.
- Lead monthly patching cycles and rapid zero‑day response across on‑prem and hybrid server environments.
- Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere).
- Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements.
- Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score.
- Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders.
- Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non‑compliant certificates, and manage key vault rotations for critical cloud‑hosted applications.
- Utilize automation tools to deploy required machine certificates across the organization.
- Manage syslog retention and forwarding across on‑premises and cloud infrastructure, supporting the Security team’s SIEM ingestion, correlation, and compliance reporting needs.
- Administer network micro‑segmentation using Illumio, including policy design, enforcement, and ongoing tuning.
- Review and administer security tools to harden network edge security, including next generation firewalls, SD‑WAN, and switching, striving for zero trust networks.
- Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba Clear Pass.
- Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using Beyond Trust for remote server access, including access reviews and privileged session controls.
- Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices.
- Review and secure SDLC servers and hosted applications, both on‑premises and in Azure, applying measures to keep all public endpoints secure.
- Balance day‑to‑day operational demands (SSL renewals/rotations, security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).