Infrastructure Security Engineer – Job Description
Position Summary
The Infrastructure Security Engineer is responsible for protecting the organization’s core systems, networks, cloud environments, and critical infrastructure against cyber threats. This role ensures secure architecture, implements strong controls, conducts continuous monitoring, and partners with IT and operations teams to maintain a hardened, compliant, and resilient environment.
Key Responsibilities
Infrastructure & Network Security
- Design, implement, and maintain secure network architectures (segmentation, firewalls, VPNs, zero-trust).
- Harden on-premises and cloud infrastructure following CIS/NIST benchmarks.
- Maintain endpoint and server security configurations across Linux and Windows systems.
Cloud Security
- Secure AWS/Azure/GCP environments, including IAM, network controls, policies, encryption, and monitoring.
- Detect and remediate cloud misconfigurations using automated tools.
- Oversee secure configuration of VMs, containers, storage, and identity services.
Threat Detection & Monitoring
- Configure and tune SIEM/SOAR tools to monitor logs, system events, and network traffic.
- Investigate suspicious activity, triage alerts, and escalate or respond to incidents.
- Perform root-cause analysis and implement corrective actions.
Vulnerability & Patch Management
- Conduct vulnerability assessments on servers, networks, cloud assets, and infrastructure components.
- Prioritize findings and coordinate patching, remediation, and configuration corrections.
- Manage vulnerability scanning tools and reporting processes.
Identity, Access & Privilege Management
- Enforce least-privilege access and maintain strong IAM controls across infrastructure.
- Manage privileged access systems (PAM), MFA, SSH key policies, and credential rotation.
- Audit and maintain user access reviews for compliance.
Security Tools & Controls
- Manage enterprise security tools such as EDR/XDR, WAF, IDS/IPS, DLP, CASB, and endpoint protection.
- Automate security tasks using scripts (Python, Bash, PowerShell).
- Implement scalable security controls that support infrastructure growth.
Incident Response & Continuity
- Participate in incident response activities including detection, containment, recovery, and reporting.
- Assist in disaster recovery and business continuity planning and testing.
- Maintain documentation, playbooks, and runbooks.
Required Skills & Qualifications
- 3+ years experience in infrastructure security, system administration, network engineering, or cybersecurity.
- Strong knowledge of network security, firewalls, routing, VPNs, and secure architectures.
- Experience with cloud security (AWS/Azure/GCP).
- Proficiency with Linux, Windows Server, virtualization, and container environments.
- Familiar with SIEM, endpoint security, and vulnerability management tools.
- Strong scripting or automation skills.
- Understanding of compliance frameworks: NIST, CIS, ISO 27001, SOC 2, HIPAA (optional).
Preferred / Nice-to-Have
- Certifications: Security+, CySA+, CISSP, CCSP, GSEC, AWS/Azure Security.
- Experience with zero-trust models and microsegmentation.
- Background in system hardening or penetration testing.
Soft Skills
- Strong documentation and communication abilities.
- Ability to collaborate with IT, security, cloud, and operations teams.
- Analytical, detail-oriented, and proactive about risk reduction.
- Capable of handling complex, distributed infrastructure environments.
Company Description
Alivia Analytics is helping customers Achieve Healthcare Payment Integrity, Finally. By turning mountains of data into actionable answers, Alivia Analytics does the heavy lifting – delivering the accuracy, confidence and speed our customers need to solve their healthcare payment integrity challenges. Through the Alivia Analytics Healthcare Payment Integrity Suite we help private and public healthcare payers achieve payment integrity globally. In the US alone, up to 10% of every dollar spent is attributed to Fraud, Waste or Abuse that amounts to up to 370 Billion dollars lost annually. If your ambition is to grow your responsibilities and career while building world class analytic SaaS systems and fixing a huge problem for social good, please come and join us.