Information Security Engineer
WFA Digital Insight
Vytalize Health’s Information Security Engineer sits at the intersection of healthcare compliance and modern cloud protection, a blend you don’t see on every remote posting. The role demands hands‑on design of cloud‑native security controls while also steering incident response and business continuity drills—tasks that keep the security posture both proactive and resilient. What makes this opportunity distinct is the focus on HIPAA, HITECH, and PCI DSS within a fast‑moving health‑tech environment, meaning every recommendation directly influences patient data safety. Candidates who can translate technical assessments into clear guidance for senior leaders will thrive, especially when they can navigate third‑party risk reviews without losing sight of day‑to‑day threat mitigation.
Job Description
ROLE SUMMARY As an Information Security Engineer, you play a critical role in designing and implementing security mechanisms to protect Vytalize data and information systems. Responsibilities involve assessing risks, designing information system security architecture, performing regular control assessments to identify control deficiencies, and coordinating security risk assessments across the ecosystem, audits, or information security program certifications. You will conduct third-party information security risk assessments and work as a team to respond to and manage information security events.
Key Responsibilities
INCIDENT RESPONSE - Assist in the testing of the incident response plans to effectively address and mitigate security breaches or compliance violations.- Assist in the testing of the business continuity plans and disaster recovery plan to effectively sustain business process and restore operability during and after a cyber incident disruption.
- Respond to and resolve information security events and escalations.
- Design cloud security strategies and implement controls to protect data, applications, and infrastructure hosted in the cloud.
- In coordination with the information security team, design security architecture to protect IT infrastructure, including networks, systems, and applications, aligning with business objectives.
- Coordinate data gathering for audits and risk assessments across various teams.
- Conduct vendor risk assessments and develop processes for third-party compliance monitoring.
- Develop and maintain a continuous assessment process to ensure security controls are operating effectively.
- Monitor training campaigns to improve phishing detection and overall program effectiveness.
- Monitor remediation of vulnerability assessment findings, including penetration test results.
- Communicate security risks and recommendations to senior management and stakeholders.
- Previous Health Information Technology (HIT) experience implementing controls for federal security and privacy regulations.
- 3+ years of relevant work experience in IT security in a complex enterprise environment preferred. KNOWLEDGE, SKILLS & ABILITIES - Demonstrated knowledge of IT processes, risks, infrastructure, and information security.
- Proficiency in HIPAA, HITECH, and PCI DSS standards.
- Experience with incident response, vulnerability management, and security audits.
- Strong written and verbal communication skills with the ability to collaborate across departments.
- Ability to analyze security designs and recommend configurations with a detail-oriented approach.
How to Stand Out
- Highlight any hands‑on experience with HIPAA, HITECH, or PCI DSS compliance in your résumé and be ready to discuss specific controls you’ve implemented.
- Prepare a concise case study of a security incident you managed, focusing on detection, response steps, and lessons learned.
- Include examples of cloud security designs you’ve created, especially for AWS or Azure, and mention the tools used for identity and access management.
- Showcase any vendor risk assessments you performed; bring documentation or metrics that illustrate your methodology.
- During interviews, ask about Vytalize’s current incident response workflow to demonstrate proactive interest in their processes.
- If you hold certifications like CISSP or CISM, list them prominently and be prepared to explain how they inform your daily work.
- Negotiate remote‑work benefits such as a home‑office stipend or professional development budget early in the offer stage.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.