Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Information Security Engineer image - Rise Careers
Job details

Staff Information Security Engineer

About N-Power Medicine

N-Power Medicine aims to establish a new paradigm in drug development by reinventing the ‘how’ and transforming clinical trials through better integration with clinical practice, ensuring broader participation by physicians and patients.  We are building an exceptional multi-disciplinary team with diverse expertise spanning healthcare, engineering, technology and regulatory, and with people who share our core value of Empowering Community through generosity, curiosity and humility.  We are working with urgency to bring better therapies to patients faster. 


Position Overview

N-Power Medicine is hiring a Staff Information Security Engineer reporting to the Senior Manager, Security & Privacy. This position will be responsible for designing, implementing, and optimizing security solutions to protect critical systems and sensitive patient data, ensure compliance with industry regulations, and mitigate cybersecurity risks. The ideal candidate has deep expertise in cloud security, security architecture, risk management, and hands-on experience implementing security technologies within a healthcare environment.


This position is remote within the United States.


Role Objectives and Responsibilities

-Design, implement, and manage security controls in accordance with HIPAA, HITRUST, ISO 27001, NIST, and other industry -standard security frameworks to protect N-Power systems and sensitive data.

-Conduct periodic threat modeling and security risk assessments to identify and remediate security risks.

-Perform vulnerability scans for N-Power Medicine systems and software and apply patches and upgrades as required. 

-Coordinate and oversee the execution of regular third-party penetration testing efforts and lead remediation for identified findings.

-Support N-Power’s security audits through preparation of evidence, participation in interviews with auditors, and remediation of audit findings.

-Lead security incident response efforts, including detection, containment, investigation, root cause analysis, and remediation of security incidents.

-Implement continuous monitoring, threat intelligence and alerting through implementation and oversight of log aggregation and security information and event management (SIEM) solutions.

-Collaborate with Data & Technology, Quality, and IT teams to integrate security requirements and best practices into in-house developed software products, data platforms, and proof of concept initiatives.

-Integrate security best practices into CI/CD pipelines and conduct secure code reviews.

-Develop and maintain security policies, procedures, and technical documentation.

-Evaluate and recommend security technologies, tools, and practices to continuously enhance the organization’s security posture.

-Assess and monitor the security posture of third-party vendors and partners.

-Provide guidance and training to internal teams to promote a strong security culture.

-Develop and enforce security configurations for firewalls, IDS/IPS, SIEM, and endpoint protection platforms.

-Develop and test strategies to support high availability, business continuity, and disaster recovery of key platforms, tools and sensitive data.


Education, Experience, Behavioral Competencies, & Skills

-8+ years experience in Information Security with a focus on healthcare security solutions 

-BS/BA, Computer Science, Cybersecurity, or equivalent relevant experience.

-Relevant certifications such as CISSP, CISM, CISA, CEH, etc. preferred.

-Strong knowledge of HIPAA, HITRUST, ISO 27001, NIST, and other healthcare security regulations.

-Experience configuring and managing security technologies such as SIEM, EDR, firewalls, IDS/IPS, and cloud security tools.

-Strong understanding of cryptographic principles, IAM, and endpoint security.

-Expertise in securing cloud environments (AWS preferred) and in-house developed software applications. 

-Hands-on experience with DevSecOps practices and secure SDLC methodologies.

-Strong interpersonal and communication skills with ability to effectively collaborate with cross-functional teams is a must.

-Generous, Curious, and Humble.


Travel Requirements 

This position is mostly a remote position, however, ability to travel to Redwood City, CA for periodic meetings may be required. 


Pay Information

The expected salary range for this position is $145,000 and $183,000. Actual pay will be determined based on experience, qualifications, geographic location, and other job-related factors permitted by law. N-Power Medicine (NPM) offers equity at hire as well as a discretionary annual bonus which may be available based on Company performance. This position is eligible for company benefits. 


More About Us:

We are a mission-driven, well-funded, rapidly growing company, eager to attract passionate professionals offering a highly attractive compensation package with a balanced and flexible work environment, competitive industry benefits as well as a 401K plan and other great company “perks.”


We are an Equal Opportunity Employer and value diversity at our company. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.


Covid-19 Policy –  The Company is committed to providing and maintaining a safe workplace, and to safeguard the health and well-being of our employees, families, visitors, and the community. While vaccination remains one of the most important tools in advancing the health and safety of employees and promoting the efficiency of workplaces, we are now in a different phase of our response when these measures are no longer necessary. We currently do not have mandatory COVID-19 vaccination requirements for our employees and contractors, as the COVID-19 public health emergency has ended. However, there are certain N-Power Medicine employees and contractors who, based on their role, will be required to continue to follow our 2021 COVID-19 vaccination and other requirements as mandated by N-Power Medicine’s partners they serve. We reserve the right to modify or amend our corporate policy at any time.


Applicants must be currently authorized to work in the U.S. on a full-time basis. The Company will not sponsor applicants for work visas.



Average salary estimate

$164000 / YEARLY (est.)
min
max
$145000K
$183000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Information Security Engineer, N-Power Medicine

At N-Power Medicine, we're on a mission to redefine drug development and enhance clinical trials' efficiency with a robust and integrated approach. We’re currently looking for a Staff Information Security Engineer to join our dynamic team! In this remote position, you'll have a significant role in safeguarding sensitive patient data and ensuring compliance with various healthcare regulations. Reporting directly to the Senior Manager of Security & Privacy, you’ll design and implement key security solutions, ensuring our systems are protected from cyber threats. With your more than 8 years of experience in Information Security, particularly in healthcare solutions, you’ll be conducting risk assessments, vulnerability scans, and leading incident response efforts to tackle any security issues that arise. Your expertise in cloud security and security architecture will shine as you collaborate with cross-functional teams to enhance our security protocols. If you thrive in a community-driven environment where curiosity and generosity guide our innovations, this could be the perfect opportunity for you to contribute to life-saving therapies and work alongside talented professionals who share your commitment to making a meaningful impact. Join N-Power Medicine and empower communities through the best healthcare practices!

Frequently Asked Questions (FAQs) for Staff Information Security Engineer Role at N-Power Medicine
What are the main responsibilities of a Staff Information Security Engineer at N-Power Medicine?

As a Staff Information Security Engineer at N-Power Medicine, your main responsibilities include designing and managing security controls compliant with industry standards such as HIPAA and NIST, conducting threat modeling, carrying out vulnerability assessments, and leading incident response. You’ll also collaborate with various teams to integrate security practices into software development, ensuring a secure environment for sensitive patient data.

Join Rise to see the full answer
What qualifications are needed for the Staff Information Security Engineer position at N-Power Medicine?

To qualify for the Staff Information Security Engineer position at N-Power Medicine, candidates should possess a Bachelor's degree in Computer Science or Cybersecurity, along with over 8 years of experience in Information Security focused on healthcare solutions. Professional certifications like CISSP, CISM, or CEH are preferred, along with strong knowledge of security regulations like HIPAA and IS027001.

Join Rise to see the full answer
What makes N-Power Medicine's Staff Information Security Engineer position unique?

N-Power Medicine stands out with its commitment to transforming healthcare through innovation. The Staff Information Security Engineer position offers the chance to be involved in leading-edge security practices within a flexible remote work environment, enabling you to directly impact patient safety and company-wide security posture.

Join Rise to see the full answer
How does N-Power Medicine implement security practices in cloud environments?

At N-Power Medicine, the Staff Information Security Engineer will leverage their expertise in cloud security to evaluate and enhance security measures effectively. You'll utilize security technologies like SIEM and work closely with teams to ensure that cloud environments are secure, meeting all compliance requirements while protecting sensitive data.

Join Rise to see the full answer
What role does collaboration play for a Staff Information Security Engineer at N-Power Medicine?

Collaboration is crucial for a Staff Information Security Engineer at N-Power Medicine. You'll be working alongside cross-functional teams to integrate security requirements into software advancements, sharing best practices, and promoting a strong security culture, which is integral to the company's core values of community empowerment and innovation.

Join Rise to see the full answer
Common Interview Questions for Staff Information Security Engineer
Can you explain how you would approach a security incident as a Staff Information Security Engineer?

In approaching a security incident, I would follow a structured process: first, quickly assess and contain the incident to prevent further damage. Then, I would investigate the root cause, document the findings meticulously, and collaborate with teams for remediation, while also communicating transparently with stakeholders about the steps taken to mitigate future risks.

Join Rise to see the full answer
Describe your experience with HIPAA compliance in previous roles.

In my past roles, I have conducted regular audits to ensure that all systems comply with HIPAA regulations. I’ve implemented training sessions for staff about data handling, developed policies that reflect HIPAA guidelines, and regularly reviewed processes to identify areas for improvement, thereby reducing compliance risks.

Join Rise to see the full answer
What tools and technologies are you proficient in that are essential for a Staff Information Security Engineer?

I am proficient in various security tools, including SIEM for monitoring, EDR for endpoint protection, and cloud security solutions like AWS security configurations. My experience also includes vulnerability scanning tools and experience with secure coding practices, helping to ensure robust application security throughout the development lifecycle.

Join Rise to see the full answer
How do you stay updated with the latest security threats and mitigation strategies?

I regularly participate in online courses, attend cybersecurity conferences, and follow reputable security blogs and forums. Networking with industry professionals also helps me stay aware of emerging threats and effective mitigation strategies, which I diligently apply to my work to maintain a proactive security posture.

Join Rise to see the full answer
Can you illustrate how you have handled a vulnerability assessment?

In a previous position, I led a vulnerability assessment by first identifying and cataloging all assets. Then, I utilized various scanning tools to detect vulnerabilities, prioritized them based on risk levels, and coordinated the patching process with the IT team. Finally, I prepared a report detailing findings and action plans for management and stakeholders.

Join Rise to see the full answer
What is your experience with secure software development life cycle (SDLC) practices?

I have extensive experience with integrating security into the SDLC by conducting secure code reviews, collaborating with development teams to establish security requirements, and implementing security checkpoints in CI/CD pipelines. Ensuring security is baked into the development process is a crucial aspect of my approach.

Join Rise to see the full answer
What strategies do you use for risk management in cybersecurity?

My risk management strategies include performing regular risk assessments to identify potential threats and vulnerabilities, categorizing risks based on impact, and implementing controls to mitigate those risks. I also believe in fostering a culture of security awareness across the organization to proactively identify and address risks.

Join Rise to see the full answer
Discuss a time when you discovered a critical security issue. What did you do?

In a previous role, I discovered a critical misconfiguration in our cloud settings that exposed sensitive data. I immediately escalated the issue, worked with the cloud architecture team to implement the necessary configurations, and informed affected stakeholders. I also initiated a review process to enhance our security guidelines to prevent future occurrences.

Join Rise to see the full answer
How would you evaluate the security posture of third-party vendors?

Evaluating third-party vendors involves conducting thorough security assessments, which includes reviewing their compliance certifications, security policies, and incident response plans. I also recommend ongoing monitoring and regular audits to ensure that vendors maintain appropriate security standards and effectively manage any risks associated with their services.

Join Rise to see the full answer
What is your philosophy on building a strong security culture within an organization?

My philosophy centers around education and collaboration. I believe in investing in regular training for employees to understand security principles, shared responsibilities, and an open-door policy for discussing security concerns. Creating a culture where everyone feels empowered to contribute to security initiatives is key to an organization's resilience.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Experian Remote Geo MilevMladost, Boulevard "Tsarigradsko shose" 86, 1113 Sofia, Bulgaria
Posted 4 days ago
Photo of the Rise User
Weekday Remote No location specified
Posted 13 days ago
Photo of the Rise User
Parafin Remote San Francisco
Posted 9 days ago
Photo of the Rise User
CodeHunter Remote No location specified
Posted 6 days ago
Photo of the Rise User
Varonis Hybrid No location specified
Posted 2 days ago
Photo of the Rise User
Arista Networks Hybrid Santa Clara, CA, USA
Posted 6 days ago
Photo of the Rise User
Visa Remote Warsaw, Poland
Posted 4 days ago

n-power medicine, a venture-backed startup, aims to transform clinical trials by reinventing the ‘how’. we are empowering community oncology sites to become high-performing clinical trial centers by providing resources and staff to increase the ...

16 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 21, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Internship: Talent at Hylant
C
Someone from OH, Cincinnati just viewed Senior Instructional Designer at CXG
Photo of the Rise User
Someone from OH, Youngstown just viewed Compliance Specialist, Anti-Corruption Program at ServiceNow
Photo of the Rise User
Someone from OH, Cleveland just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Cleveland just viewed QC Engineer at QODE
Photo of the Rise User
34 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Westerville just viewed Data analyst | Mid at Nord Security
Photo of the Rise User
7 people applied to SOC Analyst at Prosegur
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, Lakewood just viewed Culture and Programs Analyst at City of Philadelphia
Photo of the Rise User
Someone from OH, Olmsted Falls just viewed Customer Service - Representative at Waterway Carwash
M
Someone from OH, Strongsville just viewed Technical Writer (Contract) at Mintlify
Photo of the Rise User
Someone from OH, Cincinnati just viewed Inside Sales Co-Op at VEGA Americas
S
Someone from OH, Cleveland just viewed Senior JavaScript Developer at SuperDial
Photo of the Rise User
Someone from OH, Columbus just viewed Environmental Science Intern at Kimley-Horn
Photo of the Rise User
Someone from OH, Dayton just viewed Sr Renewal Analyst 1730 at MeridianLink
Photo of the Rise User
Someone from OH, Canton just viewed Communications Manager at Shearer's Foods