xelys jobs xelys jobs

Security Engineer

HFD

full-remotemidpermanentsecurity Sherman, TX 45 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Security EngineeringAzure SecurityMicrosoft SentinelMicrosoft DefenderEntra IDIncident ResponseVulnerability ManagementPCI DSSComplianceThreat Hunting

About the role

Role overview

HFD is hiring a Security Engineer to join the IT Security function and report to the Senior Security Engineer. This is a hands-on role spanning cloud security, compliance, incident response, and security architecture, working in a lean environment with room to grow responsibilities over time.

Responsibilities

  • Apply risk management to identify, assess, and reduce security risks across cloud, endpoint, identity, network, and application environments.
  • Maintain knowledge of approved security standards/frameworks, policies, procedures, and best practices.
  • Conduct security control reviews, gap assessments, and remediation planning to strengthen security posture.
  • Support vulnerability management: analyze vulnerabilities, prioritize risk, track remediation, and validate fixes.
  • Monitor alerts/logs/threat indicators from SIEM, EDR, cloud, identity, and other security tools.
  • Triage and investigate security events; support containment, document findings, and assist with incident response.
  • Review system/app/cloud/identity configurations for security risks, misconfigurations, and hardening opportunities.
  • Assist with compliance and audit readiness (evidence collection, control validation, security practice documentation).
  • Support access reviews and identity security (privileged access validation, account hygiene, review of high-risk permissions).
  • Define and document security requirements for new systems, integrations, applications, and processes.
  • Maintain/improve security policies, operational procedures, runbooks, and post-incident documentation.
  • Contribute to detection engineering: improve alerts, reduce false positives, and increase visibility.
  • Identify opportunities to improve automation, monitoring, response workflows, and security operations maturity.
  • Collaborate with IT, engineering, and business teams to communicate risks and drive practical security improvements.
  • Participate in lessons learned and continuous improvement activities.
  • Perform proactive threat hunting across multiple environments.

Requirements

  • 2–5 years hands-on experience in IT security, cloud security, or security operations.
  • Practical experience with Microsoft Azure security services, including:
    • Microsoft Defender
    • Entra ID
    • Secure Score
    • Microsoft Sentinel (or equivalent)
  • Foundational knowledge of PCI DSS or similar compliance frameworks (HIPAA, SOC 2, NIST).
  • Strong written communication skills (e.g., runbooks, RCAs, compliance documentation).
  • Ability to work independently and manage workload with minimal oversight.
  • Solid understanding of IT infrastructure designs and services.
  • Ability to formulate/interpret cyber threat analysis (adversary TTPs).
  • Detail-oriented and self-motivated; able to multitask in a fast-paced environment.

Nice-to-haves

  • Beginner/Intermediate proficiency (as indicated in the posting).

About HFD

HFD is a healthcare-focused company with a mission to make healthcare more affordable by giving people a better way to pay. The role sits within HFD’s IT Security function, supporting security, compliance, and incident response to protect the organization and its systems.

Scraped 6/13/2026