Cybersecurity Engineer in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cybersecurity Engineer based in United States.
The Cybersecurity Engineer will serve as a senior technical contributor responsible for strengthening and continuously improving enterprise cybersecurity capabilities.
This role combines vulnerability management, offensive security, cloud security, security engineering, secure software development, and AI-enabled defense technologies.
You will help protect critical systems, sensitive data, and business operations within a highly regulated healthcare environment.
Working across Infrastructure, Cloud, Architecture, Application Development, Data, Clinical Technology, and Security Operations, you will drive practical security improvements across complex environments.
The role offers significant hands-on ownership, from engineering automated security controls to conducting assessments and integrating security into development workflows.
You will also evaluate emerging AI and automation technologies while helping teams adapt to evolving cyber threats.
As a technical leader, you will mentor colleagues, influence enterprise security strategy, and demonstrate measurable improvements in organizational risk reduction.
- Lead enterprise vulnerability and exposure management across endpoints, servers, cloud platforms, applications, databases, networks, and medical devices.
- Develop risk-based approaches for vulnerability prioritization, remediation tracking, validation, reporting, and overall exposure reduction.
- Conduct application, API, network, cloud, Active Directory, wireless, and infrastructure security assessments.
- Design, implement, integrate, and optimize security technologies including EDR/XDR, SIEM, SOAR, CSPM, identity security, email security, network security, and data protection platforms.
- Engineer and automate security controls across cloud, on-premises, SaaS, and hybrid environments.
- Develop scripts, APIs, workflows, dashboards, and automation solutions that improve detection, remediation, reporting, threat intelligence processing, and operational efficiency.
- Integrate security throughout the software development lifecycle through secure development practices, threat modeling, security testing, and DevSecOps automation.
- Partner with development teams to strengthen secure coding practices and remediate application security findings.
- Evaluate and optimize AI-enabled security capabilities for threat detection, phishing analysis, vulnerability prioritization, investigations, threat hunting, and incident response.
- Assess security risks associated with emerging technologies, AI platforms, large language models, autonomous agents, and automation solutions.
- Participate in security architecture reviews, technology evaluations, enterprise transformation programs, and strategic technical initiatives.
- Collaborate with Security Operations, Incident Response, Infrastructure, Cloud, Architecture, and Application teams to strengthen controls and reduce organizational risk.
- Support regulatory, audit, compliance, and third-party risk management activities within a highly regulated healthcare environment.
- Develop and maintain technical standards, policies, playbooks, runbooks, security baselines, and engineering documentation.
- Provide technical leadership, mentoring, and subject matter expertise to engineers, analysts, and project teams.
- Create executive and operational metrics demonstrating risk reduction, vulnerability remediation progress, program maturity, and security effectiveness.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline; equivalent relevant education and experience may be considered.
- 8+ years of progressive cybersecurity experience, including at least 5 years of hands-on cybersecurity engineering experience.
- Demonstrated experience operating in large, complex enterprise environments and leading technical initiatives across multiple teams.
- Experience in healthcare, financial services, or another highly regulated industry is preferred.
- Advanced knowledge of vulnerability management, exposure management, remediation lifecycle processes, and security validation.
- Hands-on offensive security experience, including penetration testing, adversary emulation, attack simulation, exploitation techniques, and security assessments.
- Strong application security and DevSecOps knowledge, including OWASP Top 10, secure coding, SAST, DAST, SCA, threat modeling, and CI/CD security integration.
- Experience securing Microsoft Azure, AWS, and hybrid cloud environments.
- Expertise in identity and access management, authentication, secrets management, encryption, network segmentation, and zero-trust principles.
- Experience implementing and supporting EDR/XDR, SIEM, SOAR, email security, DLP, CSPM, vulnerability management, identity security, and data protection technologies.
- Strong programming and scripting capabilities in Python, PowerShell, JavaScript, Go, C#, Bash, or similar languages.
- Experience developing APIs, integrations, automation solutions, and infrastructure-as-code security controls.
- Knowledge of container and Kubernetes security, cloud-native architectures, and modern application environments.
- Experience with AI-enabled security solutions, generative AI, security copilots, machine learning concepts, prompt engineering, and intelligent automation.
- Knowledge of threat intelligence, threat hunting, digital forensics, and incident response methodologies.
- Familiarity with healthcare security and compliance frameworks such as HIPAA, HITECH, NIST, HITRUST, and CIS Controls.
- Strong technical writing, risk communication, presentation, analytical, and problem-solving abilities.
- Ability to communicate effectively with both technical and executive audiences and influence outcomes across cross-functional teams.
- Relevant certifications such as CISSP, OSCP, OSWE, GIAC GPEN, GWAPT, GXPN, GCIH, GCFA, CCSP, CSSLP, Azure Security Engineer Associate, AWS Security Specialty, or CISSP-ISSAP are preferred.
- High integrity, accountability, professionalism, adaptability, and commitment to continuous learning.
- Annual compensation range of $140,000–$150,000.
- Opportunity to work on enterprise-scale cybersecurity initiatives within a highly regulated healthcare environment.
- Broad technical scope spanning cloud security, vulnerability management, offensive security, DevSecOps, AI-enabled security, and security engineering.
- Opportunity to influence security architecture, engineering standards, automation, and emerging technology adoption.
- Strong opportunities for technical leadership, mentoring, and professional development.
- Collaborative environment with exposure to infrastructure, cloud, application development, architecture, data, and security operations teams.