Information Security Engineer
NeoGenomics Laboratories · Ramsey, NJ · 1 wk ago
On-siteInformation TechnologyFull-time
About the role
NeoGenomics is seeking an Information Security Engineer to support the execution and continuous improvement of the company’s enterprise information security program. This hands-on role partners across Security Operations, Governance, Risk and Compliance (GRC), Identity and Access Management (IAM), and Security Architecture to maintain effective security controls and support regulatory and audit requirements in a regulated life sciences environment.
This is a hybrid in-office position with a Monday–Friday schedule, based in either Ramsey, NJ or Fort Myers, FL.
Responsibilities
- Operate and tune enterprise security platforms including Microsoft Defender, Varonis, Mimecast, Zscaler, and Cisco Umbrella; maintain baseline configurations, tune detections, and coordinate updates with the managed security services provider.
- Execute the vulnerability management program on Rapid7 with Active Risk Score prioritization; partner with Infrastructure, Application, and Lab Operations teams to drive remediation of critical and high-risk findings within SLA.
- Support privileged access operations in CyberArk, conditional access policies in Okta and Azure AD/Entra ID, and MFA coverage across critical applications; assist with quarterly access reviews and joiner/mover/leaver automation.
- Serve as a technical responder during security incidents, performing triage, containment actions, evidence collection, and root cause analysis under the direction of Security Operations leadership.
- Contribute to detection engineering activities across the SIEM and endpoint tooling; build, test, and tune correlation rules aligned to MITRE ATT&CK techniques relevant to healthcare and life sciences.
- Produce technical evidence artifacts for SOX ITGC, HIPAA, SOC 2 Type 2, and CAP/CLIA audits; maintain screenshots, exports, and configuration snapshots aligned to the control library.
Requirements
- Bachelor’s Degree in Computer Science, Information Security, Information Technology, or related field required; equivalent work experience considered.
- 2+ years of hands-on experience in information security engineering, security operations, or a closely related technical security role.
- Must be authorized to work in the United States without the need for current or future employer sponsorship.
- One or more of the following industry certifications preferred: Security+, CySA+, GCIH, GCIA, GSEC, or vendor certifications on primary security platforms (Microsoft SC series, Rapid7, CyberArk).
- Demonstrated experience operating enterprise security tooling in at least three of the following categories: EDR/XDR, SIEM, vulnerability management, DLP, email security, PAM, or identity governance.
- Working knowledge of NIST CSF, MITRE ATT&CK, and common security frameworks (HIPAA, SOX ITGC, SOC 2).
- Practical scripting or automation experience with PowerShell, Python, or Power Platform.
- Familiarity with cloud security concepts in Azure and AWS environments.
- Solid understanding of networking fundamentals, endpoint protection, and identity protocols (SAML, OAuth, OIDC).
Benefits
- Highly competitive benefits with a variety of HMO and PPO options.
- Company 401k match and Employee Stock Purchase Program.
- Tuition reimbursement and leadership development programs.
- 16 days of paid time off plus holidays starting on day one.
- Wellness courses and highly engaged employee resource groups.
- Internal career coaches and training opportunities to expand your knowledge base.