Cybersecurity Engineer II

Atlantic Health SystemMorristown, NJ
Onsite

About The Position

The Cybersecurity Engineer II – Cloud Security and Identity is responsible for helping secure the organization's cloud environments and the identities that access them. This role focuses primarily on cloud security engineering and operations—with an emphasis on Amazon Web Services (AWS), supported by Microsoft Azure and Microsoft 365, and using a cloud-native application protection platform (CNAPP) such as Wiz to maintain visibility into cloud configuration, workload, data, and permission risk. Alongside this cloud focus, the Engineer II supports enterprise identity and access security, with particular attention to Microsoft Entra ID, hybrid Active Directory, conditional access, multifactor authentication, and privileged access. The successful candidate is a well-rounded security practitioner: while cloud and identity are the primary areas of contribution, this role sits on a small, versatile team and requires solid working knowledge across the broader cybersecurity landscape, including vulnerability management, data protection, application security, and endpoint and email security. As with every member of this team, the Engineer II serves as part of a dynamic team responsible for cybersecurity incident response and other cybersecurity initiatives, works to safeguard electronic protected health information (ePHI) and other regulated data, and shares in a rotating on-call schedule.

Requirements

  • Solid working knowledge across the broader cybersecurity landscape, including vulnerability management, data protection, application security, and endpoint and email security.
  • Experience with Amazon Web Services (AWS), Microsoft Azure, and Microsoft 365.
  • Experience with cloud-native application protection platforms (CNAPP) such as Wiz.
  • Experience with enterprise identity and access security, including Microsoft Entra ID, hybrid Active Directory, conditional access, multifactor authentication, and privileged access.
  • Familiarity with infrastructure-as-code and container technologies—such as Terraform or CloudFormation templates, CI/CD pipelines, and Kubernetes.

Responsibilities

  • Support the design, implementation, and ongoing operation of security controls across the organization's cloud environments, with a primary emphasis on AWS and additional coverage of Microsoft Azure and Microsoft 365.
  • Administer, configure, and optimize a cloud-native application protection platform such as Wiz to continuously discover cloud assets, identify misconfigurations, excessive permissions, exposed data, and vulnerable workloads, and surface findings for triage.
  • Perform risk-based analysis and prioritization of cloud security findings using severity, exploitability, data sensitivity, and business context, and drive remediation to closure in partnership with cloud, infrastructure, application, and vendor teams.
  • Evaluate cloud environments against recognized benchmarks and best practices—such as the CIS Benchmarks, the AWS Well-Architected Framework security pillar, and internal standards—and track configuration drift and remediation over time.
  • Support cloud identity and entitlement security, including the review and right-sizing of AWS IAM roles, policies, and permission boundaries, and the reduction of standing and excessive privilege across cloud accounts.
  • Administer and support Microsoft Entra ID and hybrid Active Directory identity services, including conditional access policies, multifactor authentication, authentication methods, application registrations, and single sign-on integrations.
  • Configure and operate Microsoft Entra Privileged Identity Management (PIM) and support privileged access practices, just-in-time elevation, and periodic access reviews and certifications for sensitive roles and applications.
  • Monitor, triage, and investigate cloud and identity security alerts from sources such as Wiz, AWS-native security services (GuardDuty, Security Hub, CloudTrail), Microsoft Defender for Cloud, Microsoft Entra ID Protection, and the enterprise SIEM.
  • Contribute to secure cloud onboarding and architecture reviews for new cloud services, SaaS applications, and third-party integrations, including evaluation of authentication, authorization, logging, encryption, and data handling.
  • Maintain familiarity with infrastructure-as-code and container technologies—such as Terraform or CloudFormation templates, CI/CD pipelines, and Kubernetes—sufficient to review security findings in these areas and route them appropriately.
  • Serve as a well-rounded contributor across the broader security program, assisting with vulnerability management, data protection, application security, and endpoint and email security work as team priorities and organizational risk require.
  • Serve as part of a dynamic team responsible for cybersecurity incident response, contributing to the detection, triage, investigation, containment, and remediation of security incidents, including cloud and identity-based attacks.
  • Develop and maintain cloud and identity security metrics, dashboards, runbooks, and technical documentation for technical teams and leadership.
  • Collaborate with teams throughout ISS, as well as Privacy and Compliance, to ensure the protection of ePHI and adherence to HIPAA and other regulatory requirements.
  • Contribute to the development and implementation of cybersecurity strategies, policies, standards, and procedures, particularly those governing cloud and identity.
  • Participate in a rotating on-call schedule to support incident response and time-sensitive security matters outside of standard business hours.

Benefits

  • Medical, Dental, Vision, Prescription Coverage (22.5 hours per week or above for full-time and part-time team members)
  • Life & AD&D Insurance.
  • Short-Term and Long-Term Disability (with options to supplement)
  • 403(b) Retirement Plan: Employer match, additional non-elective contribution
  • PTO & Paid Sick Leave
  • Tuition Assistance, Advancement & Academic Advising
  • Parental, Adoption, Surrogacy Leave
  • Backup and On-Site Childcare
  • Well-Being Rewards
  • Employee Assistance Program (EAP)
  • Fertility Benefits, Healthy Pregnancy Program
  • Flexible Spending & Commuter Accounts
  • Pet, Home & Auto, Identity Theft and Legal Insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service