Security Operations Engineer
SoftheonAbout the role
Job Title: Security Operations Engineer
Team: Cyber Security
Job Location: Remote
About Us:
Join us in revolutionizing healthcare! We build software that simplifies the process of choosing the right health insurance for individuals. Our solutions help our health plan and government customers with the administration, reporting, and operational requirements of their plans. By tackling the complexities of enrollment, administration, renewal, billing, and more, we enable our customers and partners to concentrate on advancing their core missions.
Our Company Culture:
Our culture is built on collaboration, innovation, and appreciation. We value each employee's unique talents and contributions and understand that every individual plays a critical role in our mission to transform healthcare. Every day, we celebrate our team's dedication, creativity, and expertise, which drive us closer to our goals.
At Softheon, our mission is making healthcare more affordable, accessible, and plentiful for every American. Our vision is that everyone can access and choose the healthcare they need.
About the role:
The Security Operations Engineer at Softheon plays a pivotal role in strengthening our cloud and hybrid security posture by implementing advanced information security controls and managing real-time threat detection and response efforts. In addition to deep technical expertise in Microsoft Defender, Sentinel, and cloud-native tools, this role thrives on collaboration—working closely with peers in Cloud Security, Compliance, DevOps, and Engineering to embed security into all facets of the organization.
The engineer contributes to our collective security maturity by performing proactive assessments, maintaining regulatory compliance (e.g., HIPAA, SOC 2), and advancing our security automation and tooling. As a key member of a highly collaborative Security Engineering team, this individual will be expected to function as both a subject matter expert and a flexible team player—taking ownership where appropriate, serving as a backup where needed, and contributing to shared initiatives across disciplines.
This role demands strong self-direction, a problem-solving mindset, and a team-first mentality to help safeguard the integrity, confidentiality, and availability of Softheon’s healthtech SaaS ecosystem.
Requirements
You will:
Security Improvement and Implementation
- Proactively research and identify opportunities to strengthen Softheon’s cloud and hybrid security posture, with emphasis on Microsoft Azure environments and Zero Trust principles.
- Collaborate cross-functionally with IT, DevOps, and Cloud Security teams to design and implement scalable, secure architectures aligned with security best practices and compliance frameworks (HIPAA, SOC 2, PCI).
- Engineer and deploy advanced security controls including detection-as-code and policy-as-code initiatives such as Azure Policy, Kusto Query Language (KQL), and Microsoft Conditional Access policies.
- Support the operationalization of new security tools and features, contributing to the evolution of next-gen automation and security infrastructure across Azure and SaaS platforms.
- Harden and optimize the organization's CSPM and CASB tools to improve cloud threat detection, enforce security policies, and ensure continuous compliance across hybrid-cloud environments.
Monitoring and Incident Response
- Administer Microsoft Sentinel, Microsoft Defender XDR, and related security tools for real-time alerting, correlation, and response to potential threats.
- Respond to escalated incidents based on severity and business impact; coordinate with Cloud and Compliance teams for cross-functional incident response.
- Maintain and optimize infrastructure monitoring and centralized dashboards to provide operational awareness across cloud and on-prem environments.
- Develop automation and SOAR playbooks (e.g., LogicApps, Sentinel automation rules) to collect security metrics and reduce mean time to detect/respond (MTTD/MTTR).
- Continuously assess alert quality and detection fidelity, tuning signals and rules to balance noise reduction and comprehensive coverage.
Compliance and Auditing
- Partner with Compliance, GRC, and Legal stakeholders to ensure technical security controls align with regulatory frameworks including HIPAA, SOC 2, HITRUST, PCI DSS, and ISO 27001.
- Implement and document technical evidence for audits, contributing to readiness for external assessments and client security reviews.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s