Information Technology Security Engineer

1 day ago


Oakland, California, United States Promaxo Full time

Position

We are looking for a hands-on and highly motivated IT and Security Engineer to own and shape our corporate IT, security, and compliance landscape. This is a unique opportunity to build our systems from the ground up - establishing the infrastructure, governance practices, and operational controls necessary for a secure, compliant, and efficient medical device company.

You will be our go-to expert for employee devices, cloud services, SOC 2, HIPAA, and overall security governance, driving compliance across all Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. The ideal candidate has significant experience owning SOC 2 programs end-to-end and thrives in an environment where security, compliance, and operational excellence are critical.

Key Responsibilities

IT Infrastructure & Operations

  • Build, manage, and maintain our corporate IT environment, ensuring high levels of availability, performance, and compliance with SOC 2 operational requirements.
  • Administer and support all employee devices (laptops, peripherals) using modern MDM solutions; ensure secure configurations, baselines, and monitoring aligned with SOC 2 controls.
  • Manage our core SaaS applications and identity lifecycle processes, RBAC, SSO, MFA, and least-privilege policies.
  • Oversee cloud infrastructure (AWS/GCP/Azure), implementing guardrails, logging, monitoring, and access governance consistent with SOC 2, HIPAA, and industry best practices.
  • Provide exceptional on-site IT support, ensuring timely and compliant handling of incidents, change requests, and asset tracking.

Compliance and Governance

  • Own the end-to-end SOC 2 Type I and Type II compliance program, including annual planning, evidence gathering, auditor coordination, remediation management, and continuous control monitoring.
  • Develop, document, and maintain a comprehensive library of policies, procedures, and technical standards covering all SOC 2 Trust Services Criteria.
  • Build and manage a governance framework, including: Risk assessments, Internal controls testing, Access reviews, Change management processes, Disaster recovery and business continuity planning, Third-party/vendor risk management
  • Conduct ongoing SOC 2 gap analyses and drive cross-functional remediation initiatives.
  • Manage security and compliance training programs across the organization, ensuring measurable improvement in security awareness.
  • Maintain HIPAA-aligned safeguards for PHI, including administrative, technical, and physical controls.

Security & Threat Management

  • Lead the company's threat modeling program for systems, applications, cloud services, and data flows; partner with engineering to identify threats, validate mitigations, and track closure.
  • Manage security tools and programs, including: Endpoint detection & response (EDR), Vulnerability scanning and patch management, Log management and SIEM, Configuration monitoring, Data loss prevention (DLP)
  • Own the penetration testing lifecycle, including scoping, vendor coordination, remediation tracking, and executive reporting.
  • Maintain security incident response procedures, perform incident triage, and lead coordination with internal stakeholders and external partners.
  • Ensure compliance with SOC 2 security controls, including: Audit logging, Network security, Access control, Encryption at rest and in transit, System hardening, Backup and recovery
  • Protect the confidentiality, integrity, and availability of company data, intellectual property, and PHI.

Additional Security Experience Requirements (Urology Groups, BAAs, and Mid-Market Client Expectations)

  • Serve as the primary technical point of contact for security related questions from mid-size urology groups and other healthcare practices evaluating our security posture.
  • Demonstrate deep knowledge of business associate agreements (BAAs), including how SOC 2 controls map to HIPAA requirements.
  • Clearly articulate whether BAAs, security controls, and vendor practices meet SOC 2 and HIPAA standards in external discussions.
  • Own the process of responding to external security questionnaires, RFPs, and due diligence reviews from healthcare clients and partners.
  • Prepare and maintain standardized security documentation, including security whitepapers, SOC 2 control summaries, and HIPAA safeguard explanations.
  • Lead patch management and vulnerability remediation programs, ensuring timely rollout, risk prioritization, and audit-ready documentation.
  • Manage vulnerability testing schedules, reporting, and remediation workflows across cloud services, endpoints, and third-party vendors.
  • Collaborate with compliance and legal teams to ensure BAAs, DPAs, and vendor contracts accurately reflect required security obligations.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent practical experience.
  • 3+ years of experience owning SOC 2 audits, including evidence collection, control implementation, remediation plans, auditor relationships, and continuous monitoring.
  • Experience speaking with external customers or partners about security posture, compliance, and IT controls.
  • Strong understanding of SOC 2 Trust Services Criteria and how to operationalize controls across IT, security, and engineering teams.
  • Demonstrated experience with threat modeling frameworks (STRIDE, LINDDUN, PASTA, etc.).
  • Hands-on experience with penetration testing processes, vulnerability management, SIEM, EDR, and cloud security controls.
  • Technical proficiency managing modern IT environments, with expertise in: MDM, IAM/SSO, Cloud security, SaaS administration, Endpoint hardening
  • Strong understanding of incident response, secure system design, network security, and compliance frameworks.
  • Excellent documentation and communication skills.
  • Ability to work full-time and onsite in our Oakland, CA office.

Preferred Qualifications

  • Experience building compliance programs for medical device, healthcare, or similarly regulated environments.
  • Familiarity with BAAs, HIPAA Security Rule requirements, and vendor security assessments.
  • Experience scaling an IT/security program in a fast-paced startup.
  • Familiarity with additional frameworks such as HIPAA, NIST 800-53/800-171, ISO 27001, HITRUST, FDA cybersecurity, and CIS Controls.


  • Oakland, California, United States Blue Shield of California Full time

    DescriptionYour RoleThe Principal Information Security Engineer, Principal – Network Protection is a strategic technical leader within the Information Asset Protection team, responsible for designing, implementing, and evolving enterprise-wide network security solutions. This role ensures the confidentiality, integrity, and availability of corporate and...


  • Oakland, California, United States BSC Full time

    Your RoleThe Principal Information Security Engineer, Principal – Network Protection is a strategic technical leader within the Information Asset Protection team, responsible for designing, implementing, and evolving enterprise-wide network security solutions. This role ensures the confidentiality, integrity, and availability of corporate and personal data...


  • Oakland, California, United States Pacific Gas And Electric Company Full time $136,000 - $232,000

    Requisition ID # Job Category: Engineering / Science Job Level: Individual ContributorBusiness Unit: Information TechnologyWork Type: HybridJob Location: OaklandDepartment OverviewAs an Expert Cloud Security Engineer on the Cybersecurity Services COE team, you will be responsible for support of the secure design and delivery of technology tasks to protect...


  • Oakland, California, United States E.L.F. BEAUTY Full time

    About The Companye.l.f. Beauty, Inc. stands with every eye, lip, face and paw. Our deep commitment to clean, cruelty free beauty at an incredible value has fueled the success of our flagship brand e.l.f. Cosmetics since 2004 and driven our portfolio expansion. Today, our multi-brand portfolio includes e.l.f. Cosmetics, e.l.f. SKIN, pioneering clean beauty...


  • Oakland, California, United States Finezi Inc. Full time

    Department OverviewThe Digital Workplace Team, part of the Infrastructure & Cloud Services organization, delivers the technologies and support that power a best-in-class Digital Employee Experience—enhancing joy at work through reliable devices, seamless collaboration tools, and responsive services that drives productivity.Position SummaryThe Digital...


  • Oakland, California, United States Diligence Security Group Full time

    Security Operations Manager - Events & TechnologyJob Type: Salaried, ExemptLocation: In-person | Oakland, CA (Greater Bay Area)Reports To: Chief Executive OfficerCompensation: $90,000 – $100,000 annually (based on experience and qualifications)Availability Required: Open availability — with preference for Swing and Grave shifts, including weekends and...


  • Oakland, California, United States Jobs via Dice Full time

    Dice is the leading career destination for tech experts at every stage of their careers. Our client, Cynet Systems, is seeking the following. Apply via Dice todayJob Title: Technology Architect, PrincipalJob Location: Oakland, CAJob Type: Full Time / Perm / Direct HireJob Description:Pay Range: $147000hr - $147000hrThe Technology Architect, Principal is...


  • Oakland, California, United States Rose International Full time

    Date Posted: 12/17/2025Hiring Organization: Rose InternationalPosition Number: 494762Industry: UtilityJob Title: Principal Technology ArchitectJob Location: Oakland, CA, USA, 94612Work Model: HybridWork Model Details: Hybrid Role - will decide days in offce as pr needShift: Standard work week - 8 hours per day, 5 days per weekEmployment Type: PermanentFT/PT:...


  • Oakland, California, United States Jobs via Dice Full time

    Dice is the leading career destination for tech experts at every stage of their careers. Our client, BayOne Solutions, is seeking the following. Apply via Dice todayDepartment OverviewCompany s Information Technology (IT) organization is a unified organization comprised of various departments which collaborate effectively to deliver high quality technology...

  • Security Guard

    1 day ago


    Oakland, California, United States INTER-CON SECURITY SYSTEMS INC Full time

    Job Details Job Location: Oakland Oakland, CA 94612 Salary Range: $22.00 Hourly Job Category: FieldOverviewFounded in 1973, Inter-Con Security Systems, Inc. is a leading US-owned security company, providing integrated security solutions to government and commercial customers on four continents. Inter-Con remains under family ownership and control and...