Information Security Engineer
Health Plans Inc United States · $92K–$109K/yr
Insurance · 201-500 employees
About the role
The Security Engineer is responsible for the design, implementation, and administration of enterprise cybersecurity technologies and controls. This role supports security operations, incident response, vulnerability management, and regulatory compliance initiatives while working closely with various internal stakeholders.
What they look for
Requirements
Candidates must have an associate's degree with industry certifications and at least five years of experience in information security or related technology fields. Two or more years of hands-on security engineering or platform administration experience is required.
Benefits
Full description
Information Security Engineer at HPI
Do you envision working for a company that has the expertise of a long-standing industry leader, but the spirit of an entrepreneur? Does the thought of making a real impact motivate and energize you? If so, HPI is the place for you. Join a team that values integrity, flexibility, loyalty, compassion and dedication—we can’t wait to meet you.
What we do:
HPI is unique. A respected industry leader that’s been serving customers for over 44 years, we’re known for our innovation and adaptability. Our experience has given us our expertise, but our forward-thinking, entrepreneurial spirit has given us our strong reputation. As a third-party administrator, we offer a suite of health and benefit solutions to employers. By joining HPI, you’ll contribute to ideas that make a real difference for employers and employees nationwide. There isn’t a challenge we won’t accept and we’re looking for people who have a passion to take it on. Not just a job—a mission.
Our commitment extends beyond our clients to our own employees. We foster a supportive and inclusive work environment where innovation thrives. By investing in our team’s growth and well-being, we ensure they are equipped to provide exceptional service.
What you’ll do:
The Security Engineer reports directly to the Chief Information Security Officer (CISO) and is responsible for the design, implementation, administration, and continuous improvement of enterprise cybersecurity technologies and controls. This role serves as a key technical contributor supporting security operations, endpoint protection, cloud security, identity management, vulnerability management, data protection, and regulatory compliance initiatives.
The Security Engineer works closely with Information Services, Infrastructure, Applications, Privacy, business stakeholders, end users, and external vendors to identify and reduce cybersecurity risk while supporting organizational objectives and regulatory requirements. The position requires a hands-on cybersecurity professional capable of balancing operational responsibilities with strategic security initiatives.
Duties and Responsibilities (other duties may be assigned):
Security Platform Administration
- Administer, maintain, monitor, and optimize enterprise cybersecurity platforms, including CrowdStrike, Microsoft security technologies, Zscaler, Varonis, vulnerability management tools, and other approved security solutions.
- Monitor platform health, investigate control failures, and ensure security technologies operate effectively and in accordance with approved standards.
- Maintain security configurations, documentation, dashboards, reporting, and operational procedures.
Threat Protection and Incident Response
- Investigate security alerts, suspicious activity, and potential cybersecurity incidents.
- Support incident response activities, including identification, analysis, containment, eradication, recovery, documentation, and root cause analysis.
- Develop and maintain detection logic, response procedures, and security playbooks.
Cloud, Identity, and Microsoft Security
- Assist in securing Microsoft 365, Azure, Microsoft Entra ID, Intune, and hybrid technology environments.
- Review cloud and identity configurations and recommend improvements that reduce risk and support Zero Trust principles.
- Implement and maintain security baselines, identity protections, Conditional Access controls, privileged access safeguards, and configuration standards.
Vulnerability Management
- Perform or support vulnerability assessments and coordinate remediation activities with technology owners.
- Validate remediation, track risk reduction, and escalate aging or high-risk vulnerabilities as appropriate.
Data Protection and Governance
- Assist with data classification, monitoring, access governance, and protection initiatives.
- Support Varonis administration, alerting, reporting, investigation, and remediation activities.
Security Architecture and Projects
- Participate in enterprise projects to ensure cybersecurity requirements are incorporated into solution design and implementation.
- Develop and maintain security standards, technical procedures, diagrams, and other supporting documentation.
Compliance and Audit Support
- Support internal and external audits, customer assessments, and regulatory examinations, including SOC 2 and HIPAA-related activities.
- Assist with evidence collection, control validation, remediation tracking, and responses to audit requests.
What you bring:
- Associate's degree with Industry certification(s)
- Five years of information security, cybersecurity, systems administration, network engineering, or related technology experience.
- Two or more years of hands-on security engineering or security platform administration experience.
- Experience supporting enterprise security technologies, Microsoft environments, cloud services, or hybrid infrastructure.
- Experience participating in security incident response, vulnerability management, or security control implementation.
Preferred Experience
- Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
- Microsoft 365, Azure, Microsoft Entra ID, Intune, and the Microsoft Defender security ecosystem
- CrowdStrike Falcon platform
- Varonis Data Security Platform
- Security Information and Event Management (SIEM) and log management platforms
- Vulnerability scanning and management tools
- Email security, endpoint protection, identity security, cloud security, data protection, and Zero Trust architecture
- Healthcare, insurance, or another regulated industry
- SOC 2, HIPAA, NIST Cybersecurity Framework, or CIS Controls
- Working with Managed Detection and Response (MDR) or other external security service providers
Why choose us?
- We’re a people-first company and value giving back to our community. Ask us about our volunteer opportunities.
- Our space is a reflection of who we are—innovative, open and collaborative.
- We think feeling your best is an important factor in producing great work, so we embrace a “smart casual” dress code and work at ergonomic desks.
- Need to reenergize? When at our Westborough headquarters, take a break to chat in the onsite café, go for a walk on one of the beautiful trails in our office park, or get in a quick workout at one of the campus gyms.
Our Benefits Package
We care about you and believe the greatest gift you can give yourself, your family, and the world is a healthy you! We offer a comprehensive and competitive benefits package to help you lead a happy, healthy life, including:
- Medical, Dental and Vision and Prescription Drug Coverage
- Fitness Reimbursement Benefit
- Employee Assistance Program
- Flexible Spending Account & Health Savings Account
- 401(k) and Quarterly Bonuses
- Generous Paid-Time Off & Volunteering Opportunities
- Educational Assistance & Professional Development Opportunities
So, think you want to join the HPI team? We hope to hear from you!
You can read more about us at hpitpa.com/about-us/careers/
EEO/AA/M/F/Vet/Disability Employer
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr