Security Engineer
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Lyric is an AI-first, platform-based healthcare technology company, committed to simplifying the business of care by preventing inaccurate payments and reducing overall waste in the healthcare ecosystem, enabling more efficient use of resources to reduce the cost of care for payers, providers, and patients.
Lyric, formerly Claims Xten, is a market leader with 35 years of pre-pay editing expertise, dedicated teams, and top technology. Lyric is proud to be recognized as 2025 Best in KLAS for Pre-Payment Accuracy and Integrity and is HI-TRUST and SOC2 certified, and a recipient of the 2025 CandE Award for Candidate Experience.
Applicants must already be legally authorized to work in the U.S. Visa sponsorship/sponsorship assumption and other immigration support are not available for this position.
ESSENTIAL JOB RESPONSIBILITIES- Design, build, deploy, and operate security controls and tooling across AWS, Azure, corporate networks, and endpoints.
- Engineers, tune, and maintain SIEM content – log onboarding, parsing, correlation rules, and detections – and develop automation and orchestration playbooks to reduce response times.
- Administer and optimize the endpoint detection and response (EDR) platform, including sensor deployment, policy tuning, threat hunting support, and endpoint hardening.
- Engineer and maintain identity and access management capabilities, including SSO, MFA, conditional access, privileged identity/access management, and role lifecycle automation.
- Partner with Security Architecture to translate reference architectures and design principles into implemented, measurable technical controls, providing feedback that improves future designs.
- Serve as a technical lead during security incidents – building and maintaining containment tooling, forensics readiness, and response runbooks, and participating in post-incident reviews.
- Operate the vulnerability management lifecycle: scanning, risk‑based prioritization, and partnering with application and infrastructure teams to drive remediation to closure.
- Implement and enforce baseline security configuration standards (e.g., CIS benchmarks, OS hardening, network segmentation, web application firewall) through infrastructure‑as‑code and policy‑as‑code where possible.
- Evaluate, proof‑of‑concept, and recommend security technologies, tools, and services to the broader security team based on security policy, threat drivers, and operational fit.
- Mentor junior engineers, maintain high‑quality documentation and runbooks, and participate in an on‑call rotation for security escalations.
- Minimum of seven (7) years of experience in hands‑on security engineering and/or security operations.
- Minimum of three (3) years of experience engineering and operating security controls within Amazon Web Services (AWS) and Microsoft Azure.
- Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience.
- Certifications:
CISSP, CCSP, GIAC (e.g., GSEC, GCIH, GCIA), AWS Security Specialty, Azure Security Engineer. - Experience with identity platforms such as Microsoft Entra , including conditional access, privileged identity management, and identity governance.
- Experience administering EDR platforms such as Crowd Strike Falcon and engineering SIEM detections, including detection‑as‑code.
- Proficiency with scripting and automation – Python, Power Shell, Terraform – to deliver security capabilities at scale.
- Experience in Dev Sec Ops , container and Kubernetes security, CI/CD pipeline security, and securing SaaS, IaaS, and PaaS workloads.
- Experience with network security technologies – WAF/CDN/DDoS services, IDS/IPS, network segmentation, zero‑trust access patterns.
- Knowledge of security frameworks and standards such as NIST Cybersecurity Framework, HITRUST, CIS benchmarks, MITRE ATT&CK.
- Experience with data protection, DLP, cryptography, key management, and public key infrastructure (PKI).
- Experience operating security tooling in regulated environments subject to HIPAA or similar obligations.
The U.S. base salary range for this full‑time position is: $ – $.
EEO STATEMENTLyric is an Equal Opportunity Employer that strives to create an inclusive environment, empower employees and embrace collaborative success.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).