Senior Infrastructure & Security Engineer

OnMedWhite Plains, NY
$150,000 - $160,000

About The Position

At OnMed, our purpose is to improve the quality of life and sense of well-being in our communities by bringing access to healthcare to everyone, everywhere. Our innovative CareStation, a Clinic-in-a-Box, brings healthcare access anywhere with an outlet. Poised to become a key component in America’s public health infrastructure, the OnMed CareStation is a tech-enabled, AI-powered, hybrid care solution combining the experience, trust, and outcomes of a clinic with the scalability of virtual care. Every role at OnMed directly impacts the communities we serve. You’ll join a high-performing, purpose-driven team innovating to break down barriers to healthcare access. This is a movement to bring access to healthcare where and when people need it most.

Requirements

  • Deep, hands-on experience building, deploying, and operating infrastructure and security controls across multiple technology stacks — engineering it yourself, not directing others.
  • Strong hands-on expertise with Microsoft Azure operations and security, and the M365/Entra ID stack — identity, network security, and workload protection.
  • Excellent understanding of networking and firewall rules — segmentation, NGFW and Azure Firewall rule administration, VPN, IDS/IPS, and Zero Trust Network Access across remote users and field devices.
  • Practical IT service management experience — working an ITSM platform and queue day to day, including intake, triage, escalation, and resolution tracking across internal teams and external vendors.
  • Endpoint management and device hardening experience, with encryption at-rest and in-transit across cloud, corporate, and field-deployed devices.
  • Hands-on experience operating XDR/MDR, SIEM, and SOC environments — tuning detections and working alerts directly.
  • Hands-on incident response experience — triage, containment, root cause analysis, and documentation.
  • Vulnerability management experience — scanning, prioritizing, and driving remediation to closure.
  • Scripting and automation ability (e.g., PowerShell, Python, KQL) to automate administration, hardening, detection, and response.
  • Working knowledge of at least one major compliance framework (SOC 2, NIST, CIS, HITRUST, or FedRAMP) and practical experience producing control evidence for auditors.
  • Working knowledge of HIPAA-scoped PHI handling, data classification, and Security Rule technical safeguards.
  • Experience coordinating with managed service or managed security providers as part of a small internal team.
  • Clear written communication and a documentation habit — this role writes runbooks, evidence narratives, and incident write-ups regularly.
  • Comfort working from imperfect documentation in a rapidly growing, fast-paced, high-demand environment.
  • Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • 7+ years of hands-on experience across IT infrastructure and information security, preferably in a regulated industry.
  • 5+ years operating and securing cloud (Azure preferred) and on-prem environments hands-on.

Nice To Haves

  • Experience securing IoT, embedded devices, or infrastructure deployed in unattended public settings.
  • Application security exposure — reviewing integrations, code, or system designs for vulnerabilities, with familiarity with the OWASP Top 10 and SAST/DAST tooling.
  • Direct experience carrying an organization through a SOC 2, HITRUST, or FedRAMP audit or authorization cycle.
  • Hands-on experience with Palo Alto NGFW, Azure Firewall administration, and Cloudflare security services.
  • Advanced security operations automation (e.g., leveraging Elastic).
  • Experience with ITSM platforms and endpoint/RMM tooling (e.g., ServiceNow, Jira Service Management, Freshservice, Microsoft Intune).
  • Experience implementing and managing cloud service provider, SaaS, and PaaS security.
  • Infrastructure-as-code experience (e.g., Terraform, Bicep, ARM).
  • Familiarity with securing AI tools and platforms in use across an organization, or with GRC and compliance tracking platforms.
  • Prior healthcare or other regulated-industry experience.
  • AZ-104, AZ-500, Security+, or CySA+ preferred; GSEC, GCIH, ITIL Foundation, or CISSP/CISM are good nice-to-haves.

Responsibilities

  • Owning day-to-day Microsoft Azure operations hands-on — resource configuration, patching, backup and recovery, monitoring, and cost and capacity hygiene.
  • Building and maintaining infrastructure across cloud and on-prem, and automating provisioning and routine administration through scripting.
  • Administering identity and access in Entra ID — provisioning and deprovisioning, access reviews, privileged account audits, MFA/SSO enforcement, and vendor access processes.
  • Managing endpoint administration and device hardening across corporate laptops, mobile, and field-deployed customer-facing systems.
  • Maintaining and documenting network architecture in partnership with the Head of Security and Infrastructure — segmentation, firewall rule sets, VPN, and Zero Trust access for the remote workforce and field devices.
  • Running IT service management end to end: ticket intake, triage, assignment, escalation coordination, and resolution tracking across OnMed, its managed service providers, and other vendors — with clear SLAs and no dropped handoffs.
  • Serving as the technical escalation point for infrastructure and security issues, including after-hours events affecting internal systems and patient-facing endpoints.
  • Building the runbooks, documentation, and self-service that reduce repeat tickets over time.
  • Deploying, configuring, and managing security controls hands-on across cloud, network, and endpoint environments — implementing the architecture, not just monitoring it.
  • Hardening the Azure and M365/Entra environment — network security groups, firewall rules, conditional access, and encryption at-rest and in-transit across corporate, field, and customer-facing endpoints.
  • Operating and tuning the security stack day to day: XDR/MDR, SIEM, and SOC workflows — refining detections, triaging alerts, and working them hands-on.
  • Executing incident response: triage, containment, eradication, root cause analysis, and documentation, escalating to the Head of Security and Infrastructure as severity warrants.
  • Running vulnerability management — scanning, prioritization, patch and configuration remediation, and tracking exceptions to closure.
  • Contributing to security review of integrations, vendor systems, and system designs, and partnering with engineering on remediation.
  • Owning the operational and security posture of customer- and public-facing endpoints deployed in unattended settings — device identity, network isolation, remote access, telemetry, physical tamper considerations, and secure update and recovery paths.
  • Partnering with product and field operations teams so that manageability and security are designed into new endpoint deployments rather than retrofitted after they ship.
  • Producing and maintaining control evidence for SOC 2, HITRUST, FedRAMP, HIPAA, and related frameworks in support of the compliance program — refreshing evidence on cadence, responding to auditor and assessor requests, and tracking assigned findings through to remediation.
  • Implementing HIPAA-scoped PHI handling practices: data classification, Security Rule technical safeguards, minimum necessary access, and breach notification readiness.
  • Serving as the day-to-day technical point of contact for managed service and managed security providers — coordinating work, escalating issues, and validating that deliverables actually landed.
  • Supporting vendor and third-party risk assessment, security awareness training, and responses to customer and vendor security questionnaires.
  • Taking over the operational work currently covered by an interim vendor engagement, working alongside the Head of Security and Infrastructure through the handoff.
  • Building out the asset, identity, and network documentation the environment is missing, and establishing the operating cadence for tickets, patching, access reviews, and evidence collection.

Benefits

  • unlimited PTO
  • paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service