Principal Cybersecurity Engineer & Security Auditor
Principal Cybersecurity Engineer & Security Auditor
Location: Lynnwood, WA - mainly remote. We are open to hiring in WA and out of state in OR, CA, AZ, ID, CO, or UT.
This is a remote first role with occasional travel to HQ in Seattle.
Pay: 160k - 200k DOE
Position Overview
We are seeking a Principal Cybersecurity Engineer & Security Auditor to lead technical security engineering and independent auditing for a complex healthcare organization environment. This role combines hands-on offensive and defensive capabilities with compliance and risk management responsibilities driving security architecture, executing technical assessments, operating and tuning security platforms, and ensuring HIPAA and clinical system protections. The objective is to reduce risk, detect and respond to threats (including ransomware and malicious remote access), and enable secure delivery of clinical and business services across enterprise systems.
Key Responsibilities
- Lead and execute hands-on technical security assessments, penetration tests, red team activities, and vulnerability validation across complex enterprise and clinical environments.
- Design, implement, and optimize security architecture and controls for network, endpoints, identity, cloud, and clinical systems (PACS, RIS, VNA, DICOM, HL7).
- Perform independent security audits and compliance assessments focused on HIPAA and healthcare-specific regulations; prepare audit evidence and remediation roadmaps.
- Administer and tune Fortinet FortiGate devices and centralized management/analytics (FortiManager, FortiAnalyzer) to enforce network segmentation, IDS/IPS, and VPN security.
- Deploy, configure and tune Microsoft Defender for Endpoint, Azure AD identity protections, and Azure Sentinel (or equivalent SIEM) for detection, hunting, and automated response.
- Develop and execute ransomware resilience programs including detection rules, backup validation, IR playbooks, containment strategies, and tabletop exercises.
- Investigate security incidents and lead forensic analysis and remediation planning to remove adversary persistence and restore secure operations.
- Evaluate, harden, and secure clinical imaging and information systems (PACS, RIS, VNA) and their interfaces (DICOM, HL7) to maintain patient safety and data confidentiality.
- Perform risk assessments (including CRQ/Risk Register updates), third-party security reviews, and vendor security management.
- Create clear, actionable audit reports, technical findings, and executive-level briefings; track remediation and verify closure.
- Mentor and coach engineering and security teams; drive security best practices, secure development guidance, and cross-functional collaboration.
- Contribute to security policy, standards, and architecture documentation while staying current with threat trends, tools, and healthcare cybersecurity guidance.
Qualifications
- Bachelors degree in Computer Science, Information Security, or a related field, or equivalent experience; advanced degree preferred.
- 10+ years of progressive cybersecurity experience with substantial hands-on engineering and assessment work in enterprise environments; experience in healthcare or HealthTech strongly preferred.
- Demonstrated experience conducting technical security assessments, penetration tests, and red/blue team exercises in complex environments.
- Strong hands-on experience with Fortinet FortiGate, FortiManager, and FortiAnalyzer administration and policy management.
- Practical experience deploying and tuning Microsoft Defender for Endpoint, identity protection (Azure AD), and Sentinel or equivalent SIEM for threat detection and response.
- Proven incident response, digital forensics, and ransomware mitigation experience including playbook creation and tabletop leadership.
- Familiarity with clinical systems and protocols including PACS, RIS, VNA, DICOM, and HL7 and understanding of their security and patient-safety implications.
- Deep knowledge of HIPAA requirements, healthcare compliance, and experience performing HIPAA readiness assessments and audits.
- Relevant professional certifications such as HCISPP, OSCP, CRISC, and GIAC certifications are highly desirable and demonstrate required technical and governance skills.
- Strong networking, scripting, and systems skills (TCP/IP, routing/switching, Linux, Windows, cloud platforms, automation with PowerShell/Python).
- Excellent written and verbal communication skills with ability to produce audit reports and present technical findings to executive leadership.
- Proven ability to lead cross-functional teams, manage remediation projects, and influence security outcomes across a large organization.
Benefits
Base salary: $160,000 - $200,000 DOE
- For this position, you must be currently authorized to work in the United States without the need for sponsorship for a non-immigrant visa. This job was first posted by CyberCoders on 07/29/2026 and applications will be accepted on an ongoing basis until the position is filled or closed.
Everforth CyberCoders is proud to be an Equal Opportunity EmployerAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity or expression, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, status as a crime victim, disability, protected veteran status, or any other characteristic protected by law. Our hiring process includes AI screening for keywords and minimum qualifications, and a virtual recruiter as part of the application process. A human recruiter reviews all results. Click here for details on our virtual recruiter . Everforth CyberCoders will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable state and local law, including but not limited to the Los Angeles County Fair Chance Ordinance, the San Francisco Fair Chance Ordinance, and the California Fair Chance Act. Everforth CyberCoders is committed to working with and providing reasonable accommodation to individuals with physical and mental disabilities. Individuals needing special assistance or an accommodation while seeking employment can contact a member of our Human Resources team at
Benefits@CyberCoders.com to make arrangements.
Salary
$160000 - $200000 USD per year