Description:
Location: Pacific Northwest (Remote)
Position Type: Full Time (Salary)
Reports To: Principal Cloud Engineer - Josh Duncan
Sponsor Job Ad: Yes
About the Role
As an IT Security and Compliance Engineer at Cascadia Healthcare, you’ll be responsible for implementing and enforcing security controls for our cloud and enterprise environments. You’ll work closely with the IT and engineering teams to ensure regulatory compliance, protect sensitive data, and respond to security threats.
Key Responsibilities
- Implement and enforce security controls for cloud and enterprise environments, including endpoint security configurations (Microsoft Defender, Intune policies, device compliance, app protection).
- Manage and monitor the full Microsoft Defender stack, including Defender for Cloud, Defender for Endpoint, and related security solutions.
- Conduct compliance audits, prepare reports for regulatory and internal requirements.
- Ensure technical controls are mapped to policy and evidence is available for auditors.
- Manage identity protection solutions, conduct regular access reviews, and support PIM and conditional access policy enforcement.
- Support secure file-sharing processes and ensure secure, auditable external data exchange.
- Manage and configure endpoint security solutions, ensuring all device types are covered.
- Maintain security policies, compliance records, incident response documentation, and endpoint security configuration guides.
- Advise and support the engineering team on security and compliance best practices.
Requirements:Required Qualifications
- 3–5 years of experience in security engineering, compliance, or a related IT field.
- Experience implementing and enforcing security policies in cloud and enterprise environments.
- Hands-on experience with Microsoft Defender (including Defender for Cloud and Defender for Endpoint), Intune, and endpoint security solutions.
- Hands-on experience with Microsoft Purview or a similar compliance tool.
- Experience with identity protection, access reviews, and privileged identity management (PIM).
- Strong documentation and reporting skills.
- Ability to respond to and manage security incidents.
Nice to Have
- Experience with SIEM/SOAR tools (Azure Sentinel, Splunk, etc.).
- Experience with compliance audits and evidence collection for regulatory requirements.
- Experience with secure file-sharing and external data protection.
- Experience in healthcare environments.
- Familiarity with regulatory compliance frameworks (HIPAA, etc.).
- Relevant certifications (e.g., CISSP, CISM, Microsoft Certified: Security, Compliance, and Identity Fundamentals).
- Experience collaborating with SOC and MSSP teams, including coordinating and responding to incidents.
- Experience with automation of security controls and compliance reporting.