Security Engineer
Indexed description
If you want to be part of a growing organization committed to healing, hope, and advanced care, join us and help make a meaningful impact!
Job Description
Security Engineer
Location: Port Jefferson, NY (In-person, non-remote)
Hours/Days: Monday–Friday 8:30am-5pm
Organization: New York Cancer & Blood Specialists (NYCBS)
NY Cancer & Blood is seeking a talented Security Engineer to help design, implement, and maintain and security infrastructure that protects our IT systems, networks, medical devices, and patient data. In this role, you'll work cross-functionally with IT, clinical, and compliance teams to identify vulnerabilities, respond to incidents, and build security into every layer of our environment, from network infrastructure to clinical and administrative systems. This role is well-suited to someone who enjoys both hands-on technical work and the challenge of operating in a highly regulated environment where security failures can have real consequences for patient care and safety.
What You'll Do
- Design, implement, and maintain security controls across on-premises networks, cloud infrastructure, endpoints, and clinical/administrative applications (EMR, lab, and medical devices, etc.)
- Conduct vulnerability assessments and remediate vulnerabilities
- Monitor security systems (SOC, EDR, etc.) and respond to alerts and incidents
- Lead or support incident response efforts, including investigation, containment, and remediation of security incidents
- Ensure systems and processes align with HIPAA and other relevant healthcare regulatory requirements
- Support audits and risk assessments (HITRUST, internal/external audits, regulatory inspections)
- Manage identity and access management (IAM) practices, including least-privilege access reviews for all applications
- Evaluate and implement security tools and technologies to strengthen our security posture
- Develop and maintain security documentation and policies
- Provide security awareness training and guidance to clinical staff, administrative staff, and IT teams
- Stay current on emerging threats and healthcare-specific attack trends (e.g., ransomware targeting hospital systems, PHI breaches, medical device vulnerabilities)
- 3+ years of experience in a security engineering, infrastructure security, or related IT security role
- Solid understanding of network security, endpoint security, and cloud security fundamentals
- Experience with security tools such as SIEM platforms, vulnerability scanners, and EDR solutions
- Familiarity with HIPAA and other healthcare data privacy/security regulations
- Working knowledge of encryption, IAM, and secure network design
- Experience responding to and investigating security incidents
- Strong communication skills, ability to explain risk to both clinical/administrative staff and technical stakeholders
- Additional years of IT experience considered a plus
- Experience securing healthcare-specific systems (EMR platforms, HL7/FHIR interfaces, medical devices, biomedical/IoT equipment)
- Relevant certifications
- Experience with compliance frameworks such as HIPAA, HITRUST, or NIST 800-53
- Experience working in a hospital, health system, or clinical environment
- Salary: Starting at $90,000/yr
- Benefits Include:
- Health Insurance starting Day 1
- Dental, Vision, Life Insurance
- Short & Long-Term Disability
- Generous PTO
- New York Cancer and Blood Specialists is an Equal Opportunity Employer.*
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search