Baylor Genetics Logo

Baylor Genetics

Sr Information Security Engineer

Posted 3 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Leads the design, implementation, and operation of information security controls across systems, networks, endpoints, and cloud environments. Responsibilities include SIEM/MDR, EDR/XDR, SOAR, vulnerability management, PAM, Zero Trust, incident response, data protection, DLP, and cloud security. The role collaborates with IT, Privacy, Compliance, and application teams, mentors engineers, supports security architecture and SDLC practices, and may provide periodic on-call incident response support.
The summary above was generated by AI

JOB SUMMARY

Baylor Genetics is seeking a Senior Information Security Engineer to serve as a senior technical leader within our Information Security team. As one of the nation’s leading clinical genetic testing laboratories, we safeguard some of the most sensitive data that exists — patient genomic and health information — and this role is critical to protecting it.

Reporting to the Director of Information Security, the Senior Information Security Engineer designs, implements, and operates the security controls that protect Baylor Genetics’ systems, networks, endpoints, and cloud environments. This role leads key operational security initiatives — including managed detection and response (MDR/SIEM), privileged access management, vulnerability management, and Zero Trust — and provides technical mentorship to other engineers. Scope may evolve as organizational needs change.

KEY RESPONSIBILITIES

• Lead and operate the organizational detection and response capabilities, including SIEM/MDR and EDR/XDR, and SOAR (e.g., CrowdStrike or Microsoft Sentinel), tuning detections with organization specific policies and response actions.

• Establish and mature a centralized, risk-based vulnerability management program with enforced patch SLAs, secure configuration baselines, and remediation of penetration test findings.

• Design and implement identity and access security controls, including Privileged Access Management (PAM), Just-in-Time (JIT) access, MFA, SSO, Conditional Access, and least-privilege .

• Advance the Zero Trust roadmap across identity, endpoints, networks, cloud, and data.

• Respond to and investigate security incidents end to end — detection, containment, investigation, and recovery — in line with the incident response playbook, and lead post-incident reviews.

• Implement and manage data protection controls for PHI/PII, including auto-classification and DLP (e.g., Microsoft Purview) across endpoints and cloud services.

• Collaborate with IT, Privacy, Compliance, and application teams to embed security best practices into system designs, cloud deployments, and the SDLC.


QUALIFICATIONS

Required

• Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field — or an equivalent combination of education and experience.

• Minimum of 6–8 years of experience in information security engineering, security operations, or a related discipline.

• Hands-on expertise with SIEM/MDR and EDR platforms (e.g., CrowdStrike, Microsoft Sentinel) and security event monitoring, triage, and tuning.

• Strong knowledge of network security, firewalls, IDS/IPS, cryptography, authentication, and authorization principles.

• Experience with vulnerability management, penetration test remediation, incident response, and endpoint/OS hardening.

• Working knowledge of cloud security (Azure and/or AWS) and identity platforms (SSO, MFA, conditional access).

• Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, HITRUST, NIST, and GDPR.

• Excellent written and verbal communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.

Preferred

• Advanced certifications such as CISSP, CISM, GCIA, GCIH, or a cloud security specialty (e.g., Azure/AWS Security).

• Experience with privileged access management (PAM), SOAR, and Zero Trust architectures.

• Familiarity with data loss prevention (e.g., Microsoft Purview) and data classification programs.

• Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment.


.

COMPETENCIES

• Strong analytical and problem-solving skills with a risk-based, outcome-driven mindset.

• Sound judgment and composure when responding to security incidents under pressure.

• Collaborative, cross-functional approach with the ability to influence peers and mentor others.

• Self-directed, detail-oriented, and able to prioritize competing demands in a fast-moving environment.


PHYSICAL DEMANDS AND WORK ENVIRONMENT

• Remote role based in the USA.

• Frequently required to sit and use hand and finger dexterity for prolonged periods.

• May require periodic on-call availability to support security incident response.

• Occasional travel for meetings, conferences, or audits.

EEO STATEMENT

Baylor Genetics is proud to be an equal opportunity employer committed to fostering an inclusive and diverse workplace. We welcome and encourage applicants from all backgrounds to apply. We do not discriminate on the basis of race, color, religion, national origin, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, pregnancy, childbirth, or any other status protected by applicable federal, state, or local law. If you need an accommodation during the application process, please contact our Human Resources team. 

Note to Recruiters:

We value building direct relationships with our candidates and prefer to manage our hiring process internally. While we occasionally partner with select recruitment agencies for specialized roles, we do not accept unsolicited resumes from recruiters or agencies without a written agreement executed by the authorized signatory for Baylor Genetics ("Agreement"). Any resumes submitted to Baylor Genetics in the absence of an Agreement executed by Baylor Genetics' authorized signatory will be considered the property of Baylor Genetics, and Baylor Genetics will not be obligated to pay any associated recruitment fees.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Similar Jobs

18 Days Ago
Easy Apply
Remote or Hybrid
Lafayette, CO, USA
Easy Apply
110K-150K Annually
Senior level
110K-150K Annually
Senior level
Automotive • Greentech • HR Tech • Sales • Software
Own and improve enterprise security platforms, cloud and infrastructure security, identity governance, endpoint protection, vulnerability management, incident response, network controls, and DevSecOps practices. Lead complex security initiatives, compliance controls, vendor assessments, security architecture reviews, and AI security governance. Build automation with PowerShell and Python, partner with IT Operations and DevOps, reduce manual work, and serve as the senior escalation point for technical security incidents.
Top Skills: Amazon SesAuth0AWSAws Identity CenterAzureChatgpt EnterpriseCi/CdCisco DuoCisco MerakiCisco UmbrellaClaudeConditional AccessContainersCrowdstrikeDastDkimDmarcInfrastructure As CodeKnowbe4KubernetesMcpMicrosoft 365Microsoft Entra IdMicrosoft GraphNist CsfPimPowershellPythonRapid7 InsightappsecRapid7 InsightidrRapid7 InsightvmRapid7 MdrRest ApisSastScimSendgridSnykSoc 2SpfSsoVpn
2 Hours Ago
Remote
United States
Senior level
Senior level
Fintech • Software • Financial Services
The Senior IT Security Engineer strengthens cybersecurity across architecture reviews, AI and emerging technology assessments, IAM governance, vulnerability management, third-party risk, security assurance, incident response, phishing simulations, automation, and regulatory compliance. The role validates security controls, supports remediation, develops risk metrics and reporting, oversees identity platforms, and partners with technology, business, audit, compliance, procurement, and vendors in a regulated banking environment.
Top Skills: Active DirectoryAi Governance PlatformsAzureCis ControlsConditional AccessIdentity And Access Management (Iam)Identity FederationMicrosoft 365 Security TechnologiesMicrosoft Entra IdMulti-Factor Authentication (Mfa)Nist Cybersecurity FrameworkPrivileged Access Management (Pam)Role-Based Access Control (Rbac)Single Sign-On (Sso)
5 Days Ago
In-Office or Remote
95K-125K Annually
Senior level
95K-125K Annually
Senior level
Retail
Designs and evolves enterprise information security architecture, standards, and roadmaps while engineering and operating security platforms such as SIEM, SOAR, EDR, vulnerability management, Entra ID, and DLP. Advises enterprise and solution architects on secure cloud, application, data, and infrastructure designs; integrates security tools; supports automation, detection, incident response, governance, audits, and continuous improvement.
Top Skills: APIsCloud Security PlatformsData Loss PreventionEdrEntra IdNetwork Security PlatformsPowershellPythonSaas Security PlatformsSIEMSoarVulnerability Management

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account