Cyber Security & Infrastructure Engineer
XO Health believes healthcare is fixable. Become part of the community changing the face of the industry.
XO Health is the first health plan designed by and for self-insured employers that delivers a more unified health experience for everyone โ from those who receive care, to those who deliver it, to those who pay for it.
We are growing a multi-disciplinary team of diverse and digitally empowered employees ready to rebuild trust in healthcare through comprehensive and unified transformation.
CyberSecurity & Infrastructure Engineer - India (Remote)
About the Role :
The Cybersecurity & Infrastructure Engineer is responsible for designing, implementing, monitoring, and securing the organization's hybrid cloud and infrastructure environments. This role serves as a technical leader for cybersecurity operations, cloud security, compliance initiatives, infrastructure engineering, and incident response.
The position combines hands-on infrastructure administration with cybersecurity engineering responsibilities across Microsoft Azure, Microsoft Sentinel, Microsoft 365, Entra ID, AWS, networking, endpoints, and security platforms. Engineering plays a key role in maintaining compliance with SOC 2 Type II controls, improving cyber resilience, supporting audits, and advancing the organization's security maturity.
Responsibilities:
SOC2 Audit
- Support organization's annual SOC 2 Type II audit program, including control design, evidence collection, remediation management, auditor coordination, and continuous compliance monitoring.
- Partner with business and technology stakeholders to ensure security, availability, confidentiality, and change management controls are effectively implemented and operating throughout the audit period.
- Drive successful completion of SOC 2 Type II examinations with minimal findings by maintaining an audit-ready environment, strengthening internal controls, and promoting a culture of security and compliance.
- Develop and maintain policies, procedures, risk assessments, and control documentation necessary to support ongoing compliance and future audit readiness.
Cybersecurity Operations
- Administer and optimize Microsoft Sentinel SIEM platform.
- Develop and maintain security monitoring, analytics rules, alerting, dashboards, and automation workflows.
- Investigate security incidents and coordinate containment, remediation, and recovery activities.
- Monitor and respond to threats identified through Microsoft Defender, Sentinel, AWS security services, and third-party platforms.
- Conduct threat hunting, vulnerability management, and security assessments.
- Lead incident response activities and coordinate forensic investigations as needed.
- Maintain security documentation, playbooks, and response procedures.
- Support penetration testing, tabletop exercises, and disaster recovery testing.
Cloud Security & Architecture
- Design and maintain secure Microsoft Azure environments.
- Implement Azure security best practices utilizing:
- Microsoft Entra ID
- Conditional Access
- Privileged Identity Management (PIM)
- Defender for Cloud
- Azure Security Center
- Microsoft Purview
- Secure AWS cloud environments including:
- IAM
- CloudTrail
- GuardDuty
- Security Hub
- Config
- CloudWatch
- Implement zero-trust security principles across cloud platforms.
Infrastructure Engineering
- Maintain and support hybrid infrastructure environments including:
- Microsoft Azure
- AWS
- Active Directory
- Microsoft Entra ID
- Windows Server
- Virtualization platforms
- Microsoft 365
- Network and security appliances
- Design and implement high-availability and disaster recovery solutions.
- Manage identity lifecycle and privileged access controls.
- Support cloud migrations and infrastructure modernization initiatives.
Governance, Risk & Compliance
- Lead technical compliance activities supporting SOC 2 Type II audits.
- Collaborate with external auditors and internal s