About Medical Guardian:ย
Medical Guardian is a fast-growing digital health and safety company on a mission to help people live a life without limits. With 13 consecutive years on the Inc. 5000 list of Fastest Growing Companies, we're redefining what it means to age confidently and independently.ย
We support over 625,000 members nationwide with life-saving emergency response systems and remote patient monitoring solutions. Trusted by families, healthcare providers, and care managers, our work is powered by a culture of innovation, compassion, and purpose.ย
Position Summary:
We areย seekingย a highly skilled and strategic Senior Security Engineer to strengthen and mature our enterprise security capabilities as part of the broader IT Operations organization. This roleย is responsible forย securing cloud infrastructure, AI platforms, applications, endpoints, identity systems, and core operational environments.ย
The Senior Security Engineer will work closely with Infrastructure, Engineering, Compliance, QA, IT Operations, and external security service providers to proactively reduce risk while enabling business growth. This position reports directly to the Head of Infrastructure and Information Security, with a dotted-line reporting relationship to the CISO for strategic alignment, governance oversight, and security program direction.ย
This role serves as the primary technical lead for security incident response, responsible for coordinating internal response teams, activating third-party incident response partners when required, and leading containment and recovery efforts during active security events. The position requires the ability to respond to and manage security incidents outside of standard business hours when necessary.ย
This is a hands-on senior engineering role with architectural ownership, external partner oversight, and mentorship responsibilities.
Key Responsibilities:
Security Architecture and Engineeringย
- Design and implement secure architecture patterns across Azure and AWS cloud environments, as well as on-prem and hybrid infrastructuresย
- Lead security design reviews for infrastructure and application initiativesย
- Engineer and optimize enterprise security controls across endpoint protection, threat detection and response, network security, email security, data protection, cloud access governance, and privileged access managementย
- Define and implement Zero Trust principlesย
Cloud Security, Azure Focusedย
- Harden Azure security posture including Entra ID governance, RBAC design, Conditional Access, PIM, Defender for Cloud, Defender for Cloud Apps, and Private Link architectureย
- Implement and manage cloud posture management and cloud workload protection capabilities, including CSPM and CNAPP toolingย
- Secure Kubernetes and containerized workloadsย
- Automateย securityย guardrails using infrastructure as code such as Terraform, Bicep, and CloudFormationย
- Implement enterprise data classification, DLP, encryption, and tenant-level controls across Microsoft 365 and Azure to prevent data exfiltration and unauthorized AI service accessย
AI and Emerging Technology Securityย
- Design, implement, and enforce security controls for enterprise AI platforms including Azure OpenAI, Microsoft Copilot, Azure Machine Learning, and related AI servicesย
- Secure AI model training data, inference endpoints, APIs, and serviceย principalsย whileย enforcingย governance controls to prevent exposure of sensitive or regulated dataย
- Develop guardrails to detect and prevent shadow AI adoptionย
- Evaluate third-party AI tools for security, privacy, and data residency risksย
- Partner with Legal and Compliance teams to support responsible AI governance and regulatory requirementsย
Application Securityย
- Partner with DevOps and Engineering teams to integrate automated application security testing, including static analysis, dynamic testing, and secret detection, into CI and CD pipelines prior to deploymentย
- Perform threat modeling and architecture risk assessmentsย
Threat Detection and Incident Responseย
- Serve as incident response lead for security events, coordinating internal response teams and activating third-party incident response partners as neededย
- Lead containment, eradication, and recovery efforts during security incidentsย
- Enhance detection engineering use cases within SIEM and develop automated response playbooksย
- Lead post-incident reviews and root cause analysisย
- Lead andย facilitateย regular incident response tabletop exercises and coordinated response simulations toย validateย detection, escalation, and cross-functional readinessย
Vulnerability Managementย
- Oversee enterprise vulnerability management including scanning, risk-based prioritization, and remediation trackingย
- Develop metrics and reporting for executive visibilityย
Compliance and Riskย
- Support regulatory requirements including HIPAA,ย HITRUST,ย SOC 2, and PCI-DSSย as applicableย
- Assistย with audits andย evidenceย collectionย
- Develop andย maintainย security policies and standardsย
- Perform third-party risk assessmentsย
Security Operations and External Partner Managementย
- Oversee MDR detection coverage, alert tuning, escalation workflows, service level adherence, and integration of logging and telemetry between internal systems and third-party providersย
- Collaborate with the MSP on infrastructure security hardening, patching strategy, endpoint protection, and configuration managementย
- Drive continuous improvement through regular performance reviewsย and security posture assessments with external partnersย
Leadership and Mentorshipย
- Provideย technical guidance and drive security best practices across IT and Engineering initiativesย
- Serve as escalation point for complex security issuesย
Requirements
Required Qualificationsย
- Must be legally authorized to work in the United States without the need for employer sponsorship now or in the futureย
- 5ย or more years of progressive experience in cybersecurity engineeringย
- Strong experience in Azure security architecture and hands-on implementation of controls including Entra ID, Conditional Access, PIM, Defender for Cloud, and Private Endpointsย
- Deep understanding of network security, identity and access architecture, endpoint protection, and security monitoring and detection engineering principlesย
- Experience securing AI and ML platforms or cloud-native AI servicesย
- Experience implementing enterprise data protection controls including DLP, Purview, labeling, encryption, and key managementย
- Experience withย infrastructureย as code and automation using Python, PowerShell, Terraform, Bicep, or similar toolsย
- Experience securing CI and CD pipelines and containerized environmentsย
- Strong knowledge of security frameworks including NIST, CIS, and ISO 27001ย
- Experience managing third-party security operations relationships and holding vendors accountable to defined service levelsย
Preferred Qualificationsย
- Experience in regulated industries such as healthcareย
- Experience implementing Zero Trust architecturesย
- Security certifications such as CISSP or CCSPย stronglyย preferred. Azure security certifications including AZ-500ย highlyย valued. GIAC certifications such as GCED orย GCIAย and OSCP are considered a plus.ย
Work Environment & Requirements:ย
- Hybrid work model with on-site presence required two days per week at the Philadelphia locationย
- Serve as the primary incident response lead, including availability outside standard business hours to coordinate and manage security incidents and engage third-party incident response partners when necessaryย
- Candidates must be authorized to work in the United States without current or future need for visa sponsorship.
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Paid Time Off (Vacation, Sick Time Off & Holidays)
- Company Paid Short Term Disability and Life Insurance
- Retirement Plan (401k) with Company Match