Tbc
Staff Security Engineer
Remote - US · Staff+ · Full-time
Sponsorship not specified$125k-$188kDetected 21 hours ago
PythonPowerShellAWSAzureKubernetesTerraformCI/CDCybersecurityNetwork SecuritySIEMSOARSOC OperationsComplianceRecruitingIntellectual PropertyFirewallZero TrustHIPAACISSP
About the role
- Lyric is proud to be recognized as 2025 Best in KLAS for Pre-Payment Accuracy and Integrity and is HI-TRUST and SOC2 certified, and a recipient of the 2025 CandE Award for Candidate Experience.
- Interested in shaping the future of healthcare with AI?
Responsibilities
- Design, build, deploy, and operate security controls and tooling across AWS, Azure, corporate networks, and endpoints
- Engineer, tune, and maintain SIEM content - log onboarding, parsing, correlation rules, and detections - and develop automation and orchestration (SOAR) playbooks to reduce response times
- Administer and optimize the endpoint detection and response (EDR) platform, including sensor deployment, policy tuning, threat hunting support, and endpoint hardening
- Engineer and maintain identity and access management capabilities, including single sign-on (SSO), multi-factor authentication (MFA), conditional access, privileged identity/access management (PIM/PAM), and role lifecycle automation
- Partner with Security Architecture to translate reference architectures and design principles into implemented, measurable technical controls, providing feedback that improves future designs
- Serve as a technical lead during security incidents - building and maintaining containment tooling, forensics readiness, and response runbooks, and participating in post-incident reviews
Requirements
- Minimum of seven (7) years of experience in hands-on security engineering and/or security operations
- Minimum of three (3) years of experience engineering and operating security controls within Amazon Web Services (AWS) and Microsoft (MS) Azure
- Lyric, formerly ClaimsXten, is a market leader with 35 years of pre-pay editing expertise, dedicated teams, and top technology.
Nice to have
- Bachelor's degree in Computer Science, Information Systems, or equivalent practical experience
- CISSP, CCSP, GIAC (e.g., GSEC, GCIH, GCIA), or other relevant security-related designation(s)
- AWS Security Specialty Certification, Azure Security Engineer Certification
- Experience engineering identity platforms such as Microsoft Entra ID, including conditional access, privileged identity management (PIM), and identity governance
- Experience administering endpoint detection and response (EDR) platforms (e.g., CrowdStrike Falcon) and engineering SIEM detections, including detection-as-code practices
- Proficiency with scripting and automation - Python, PowerShell, and infrastructure-as-code tooling such as Terraform - to deliver security capabilities at scale
- Experience in DevSecOps, container and Kubernetes security, CI/CD pipeline security, and securing SaaS, IaaS, and PaaS workloads
- Experience with network security technologies, including WAF/CDN/DDoS services, intrusion detection/prevention systems (IDS/IPS), network segmentation, and zero trust access patterns
Compensation
- $125,241.00 - $187,862.00
- The specific salary offered to a candidate may be influenced by a variety of factors including but not limited to the candidate's relevant experience, education, and work location.
- Please note that the compensation details listed in US role postings reflect the base salary only, and does not reflect the value of the total rewards compensation. ***
Equal opportunity
- Lyric is an Equal Opportunity Employer that strives to create an inclusive environment, empower employees and embrace collaborative success.
Visa & Work Authorization
- Applicants must already be legally authorized to work in the U.S. Visa sponsorship/sponsorship assumption and other immigration support are not available for this position.
This listing is sourced directly from Tbc's careers page and normalized into a canonical job model.