Security Operations Engineer
K Health · New York, NY · United States · Hybrid
Pay: USD 125,000 – 150,000 a year
Posted Sep 4, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About the Role
As a Security Engineer at K Health, you will serve as a foundational force in securing our healthcare technology ecosystem. Reporting directly to the Director of Security, this is a deeply hands-on individual contributor role focused primarily on Security Operations (SecOps) and IT Security projects. You will be responsible for building, automating, and maintaining our security controls while acting as a key responder to security incidents. If you thrive in a fast-paced environment where you are empowered to own your domain, automate repetitive tasks, and directly safeguard patient and organizational data, this role is for you.
What You Will Do
Design, implement, and maintain hands-on SecOps workflows, threat detection, and incident response procedures across our corporate and cloud infrastructure.
Build low-code and custom automations (using tools like Torq) to streamline security alerts, routine IT security tasks, and incident triage.
Administer, optimize, and manage key security and endpoint management tools, including Sumo Logic, Jamf, Intune, Slack Enterprise, CrowdStrike, and related platforms.
Maintain and support continuous compliance with SOC2 and HIPAA security controls, actively participating in audit preparation, evidence gathering, and control enforcement.
Partner with cross-functional IT and engineering teams to harden systems, enforce zero-trust endpoint policies, and secure employee workflows.
Conduct root-cause analysis on security incidents and proactively implement preventative security measures to eliminate recurring risks.
What We Are Looking For
Experience: 3–5 years of dedicated hands-on experience in Security Operations, IT Security, or System Administration with a strong security focus.
Incident Response: Proven background in actively detecting, investigating, and remediating security incidents in a modern cloud/hybrid environment.
Technical Depth: Deep foundational IT background spanning endpoint administration (macOS/Windows), identity management, and network security.
Compliance Standards: Demonstrated experience maintaining controls for SOC2 and/or HIPAA frameworks in an operational setting.
Automation Mindset: Hands-on experience automating security operations or IT tasks using SOAR platforms, scripting (Python, PowerShell, Bash), or API integrations.
Bonus
Direct experience implementing SOC2 or HIPAA controls from scratch or directly interfacing with external auditors.
Hands-on familiarity with our specific technology stack: Sumo Logic, Jamf, Intune, Slack Enterprise, CrowdStrike, and Torq.
Relevant industry certifications (e.g., Security+, Network+, GIAC, or vendor-specific platform certifications).
Benefits & Perks: #LI-Hybrid
Hybrid work schedule with weekly lunches and stocked fridges
Monthly social committees for company events
18 vacation days, 9 company holidays, 5 sick days, and 2 personal days
Stock options for every full-time employee
…