Designs, implements, and manages cybersecurity controls across healthcare IT environments, including EHRs, medical devices, and cloud systems. Configures security tools, conducts vulnerability assessments and penetration testing, monitors and responds to incidents, performs forensic investigations, and maintains incident response plans. The role supports HIPAA, HITECH, HITRUST, and SOC 2 compliance, audit readiness, security reporting, client collaboration, and security awareness initiatives.
Cybersecurity Engineer – Remote
DAS Health – Healthcare IT Managed Services & Solutions
Overview
DAS Health is seeking a Cybersecurity Engineer to join our growing cybersecurity team. This role plays a critical part in protecting client and organizational data, with a strong focus on safeguarding patient health information (PHI) in a healthcare environment.
The Cybersecurity Engineer will design, implement, and manage security controls across complex healthcare IT systems while ensuring compliance with key regulatory frameworks such as HIPAA, HITECH, and SOC 2. This role is ideal for someone who thrives in a fast-paced MSP environment and is passionate about security, compliance, and protecting critical healthcare systems.Key Responsibilities
At DAS Health, we’re helping healthcare organizations operate more efficiently and securely through innovative technology solutions. When you join our team, you’ll benefit from:
DAS Health is a leading healthcare IT managed services provider and technology partner. We support healthcare organizations with managed IT services, cybersecurity, and consulting solutions that improve operational efficiency, enhance patient experiences, and drive better outcomes
DAS Health – Healthcare IT Managed Services & Solutions
Overview
DAS Health is seeking a Cybersecurity Engineer to join our growing cybersecurity team. This role plays a critical part in protecting client and organizational data, with a strong focus on safeguarding patient health information (PHI) in a healthcare environment.
The Cybersecurity Engineer will design, implement, and manage security controls across complex healthcare IT systems while ensuring compliance with key regulatory frameworks such as HIPAA, HITECH, and SOC 2. This role is ideal for someone who thrives in a fast-paced MSP environment and is passionate about security, compliance, and protecting critical healthcare systems.Key Responsibilities
- Design and implement security architecture across healthcare systems, including EHR platforms, medical devices, and healthcare information exchanges
- Configure and manage security tools such as firewalls, IDS/IPS, SIEM, DLP, MFA, EDR, and encryption technologies
- Conduct vulnerability assessments and penetration testing, identifying and mitigating risks across client environments
- Monitor and respond to security incidents, performing root cause analysis and implementing corrective actions
- Develop and maintain incident response plans, ensuring rapid and compliant response to security breaches
- Perform forensic analysis and support breach investigations, including HIPAA reporting requirements
- Monitor security systems and logs, proactively identifying threats and unusual activity
- Build and maintain reporting dashboards for clients and internal stakeholders
- Ensure compliance with industry standards, including HIPAA, HITECH, HITRUST, and SOC 2 Type II
- Support audit readiness and participation, including documentation and control maintenance
- Collaborate with internal teams and clients to integrate security into daily workflows and operations
- Support security awareness training and partner with vendors to ensure strong security practices
- Bachelor’s degree in Computer Science, Information Security, or a related field (Master’s or certifications preferred)
- 3–5 years of cybersecurity engineering experience, ideally within a healthcare or MSP environment
- Hands-on experience with security technologies including firewalls, IDS/IPS, SIEM, DLP, MFA, EDR, and email security
- Experience securing cloud environments (AWS, Azure, or GCP)
- Experience supporting or preparing for SOC 2 Type II audits
- Strong knowledge of healthcare compliance frameworks (HIPAA, HITECH, HITRUST)
- Familiarity with network and security architecture in complex environments
- Experience with scripting tools such as Python or PowerShell
- Strong analytical and problem-solving skills with the ability to manage complex security challenges
- Ability to communicate technical concepts clearly to both technical and non-technical stakeholders
- High level of professionalism, attention to detail, and integrity
At DAS Health, we’re helping healthcare organizations operate more efficiently and securely through innovative technology solutions. When you join our team, you’ll benefit from:
- Competitive compensation and benefits
- Career growth opportunities within a fast-growing organization
- Exposure to diverse client environments and technologies
- A collaborative, team-oriented culture
- The opportunity to make a meaningful impact in healthcare
DAS Health is a leading healthcare IT managed services provider and technology partner. We support healthcare organizations with managed IT services, cybersecurity, and consulting solutions that improve operational efficiency, enhance patient experiences, and drive better outcomes
Similar Jobs
Retail • Sports
Lead the architecture and execution of a large-scale CIAM platform migration and consolidation. Own customer identity operations, authentication flows, integrations, microservices, mobile login experiences, observability, resilience, and identity-related incident response. Partner with product, marketing, business, and customer support teams to optimize security, fraud prevention, customer experience, and conversion. Communicate platform health, migration progress, and fraud metrics to stakeholders.
Top Skills:
Api IntegrationsAuth0Aws CognitoCi/CdCiamFido2ForgerockLogging And MonitoringMfaMicroservicesMobile Application UiOauth 2.0OktaOpenid Connect (Oidc)PasskeysPing IdentitySAML
Cloud • Information Technology • Software
Lead cybersecurity for software deployed in federal and DoD environments. Manage RMF and ATO activities, STIG implementation, vulnerability remediation, FedRAMP and FISMA compliance, POA&Ms, SSPs, incident response, SIEM monitoring, and threat modeling. Integrate security testing into CI/CD pipelines, coordinate with government security stakeholders, and guide engineering teams on secure design, compliance, and remediation requirements.
Top Skills:
AcasAtoAzure DevopsCac/PivCi/CdDastDevsecopsDisa SccFedrampFismaIds/IpsJenkinsNessusNist Sp 800-53 Rev. 5Owasp Top 10PkiRmfSastScaSIEMStigStig ViewerTenable.Sc
Hardware • Security • Software • Cybersecurity
Lead cybersecurity assessments for government and enterprise clients, focusing on FedRAMP, FISMA, and NIST RMF compliance. Conduct vulnerability scanning, analyze security architectures and controls, validate remediation, author assessment documentation, engage client stakeholders, mentor team members, and support secure cloud architecture and risk mitigation. The role is remote, requires U.S. citizenship and clearance eligibility, and involves up to 25–50% travel.
Top Skills:
AcasAcunetixApplication SecurityApplied CryptographyAuthentication ProtocolsCjis Security PolicyCloud ComputingDb ProtectDisa StigsFedrampFismaNessusNist RmfNist Sp 800-SeriesNmapSoftware Development Lifecycle (Sdlc)Stig ViewerWebinspect
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute


