ModMed

Security Operations Engineer

ModMed

full-time

Posted on:

Origin:  • 🇺🇸 United States

Visit company website
AI Apply
Apply

Job Level

SeniorLead

Tech Stack

CloudCyber SecurityPythonSpringTerraform

About the role

  • Perform vulnerability scanning and assessments across enterprise systems, applications, and networks
  • Analyze and prioritize vulnerabilities based on risk and exploitability; coordinate remediation with system owners and engineering teams
  • Track remediation progress and produce vulnerability management metrics for leadership and compliance reporting
  • Investigate and analyze security events by correlating logs, network traffic, and system telemetry
  • Support incident response activities, including containment, forensic data collection, root cause analysis, and lessons learned reviews
  • Research emerging vulnerabilities, threats, and attack techniques to inform detection, response, and risk management
  • Collaborate with the Security Operations Analysts to integrate vulnerability intelligence and technical findings into threat detection and response workflows
  • Develop and maintain operational playbooks, procedures, and technical documentation to support audits, compliance, and continuous improvement

Requirements

  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Computer Science, or equivalent experience (in lieu of degree, minimum 7 years related technical experience)
  • 7+ years of experience in systems administration, network engineering, or infrastructure engineering with a security focus
  • Strong understanding of enterprise networking, operating systems, and IT infrastructure
  • Experience conducting vulnerability assessments and coordinating remediation
  • Familiarity with incident response processes (investigation, containment, recovery)
  • Ability to analyze logs, network traffic, and system telemetry to identify threats
  • Experience working in regulated environments or with compliance frameworks (HIPAA, NIST, ISO)
  • Strong written and verbal communication skills with the ability to present findings to both technical and executive audiences
  • Preferred: 9+ years of combined infrastructure engineering and security experience
  • Preferred: Experience in healthcare or other highly regulated industries
  • Preferred: Scripting, IaC, or automation experience (e.g., Python, Bash, Terraform)
  • Preferred: Exposure to advanced security monitoring, detection engineering, or threat analysis (SIEM/SOAR)
  • Preferred: Relevant security certifications such as Security+, CySA+, GCIH, or CISSP
  • Preferred: Experience collaborating across IT, Engineering, and Compliance teams to drive remediation actions and risk reduction