Security Operations Engineer
Listed on 2026-08-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Responsibilities
The Security Operations Engineer builds and operates security controls, tooling, and automation across Deep Health's cloud and corporate environments. This role is responsible for configuring, integrating, and maintaining the enterprise security tooling stack, developing detection content, and automating security operations tasks so that controls are repeatable, version-controlled, and auditable.
Working within Deep Health's established security frameworks and under the direction of the Director, Security Operations, this position operates and tunes security controls, detection content, and guardrails. Independent validation of those controls sits with the security operations watch function — a deliberate separation that keeps the control environment defensible under audit. Remediation follows system ownership across Cloud Operations, Platform, and Application Development;
this role supplies technical guidance and implements fixes directly where the control is security-owned.
This position operates within a regulated healthcare environment across a global operating footprint, with obligations under HIPAA, ISO/IEC 27001, and SOC 2. The role reports to the Director, Security Operations, with future reporting to the Manager, Security Operations as that position is established.
- Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments.
- Develop and maintain detection content, correlation rules, and response automation within the SIEM and SOAR platform.
- Onboard new log sources and telemetry feeds, validating ingestion completeness, parsing accuracy, and field normalization.
- Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation.
- Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality.
- Implement and maintain security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.
- Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework, so that controls are version-controlled, repeatable, and auditable.
- Implement policy-as-code and preventive guardrails using native cloud policy engines or an equivalent open policy framework.
- Support cloud security posture management across all cloud environments, including finding deduplication, theme mapping, and routing to owning teams.
- Harden cloud resources including compute, storage, database, container, and serverless services against established benchmarks.
- Configure and maintain Microsoft 365 and Entra controls, including conditional access, identity protection, and Defender workloads in a hybrid directory environment.
- Implement and maintain least-privilege access models, roles, and policies across multiple cloud identity systems.
- Implement container and Kubernetes security controls, including role-based access control, workload security standards, image scanning, and runtime protection.
- Implement and maintain secrets management practices and tooling, and support the elimination of hard-coded credentials across environments.
- Operate vulnerability management tooling, validate scan coverage, and translate raw scanner output into prioritized, owner-routed findings.
- Provide technical remediation guidance to cloud, platform, identity, application, and endpoint owners, who retain accountability for closure of findings in their systems.
- Implement engineering fixes for findings that fall to security-owned tooling and configuration.
- Support remediation tracking for penetration test and vulnerability assessment findings by supplying technical detail and validating that fixes are technically sound.
- Support incident detection and response through hands-on technical investigation, including log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review.
- Support escalations raised by the external managed security partner by supplying technical analysis and environment context.
- Provide feedback into detection quality and alert tuning to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).