Preferred Qualifications
- Associated certifications: CISSP, AWS Advanced Networking – Specialty, AZ-700, CCNP/CCIE Security, PCNSE
- Healthcare data standards: HL7 v2, FHIR R4, X12 EDI (837, 835, 834, 270/271, 278)
- Familiarity with CMS interoperability regulations (CMS-9115-F, CMS-0057-F)
- Infrastructure as Code: Terraform, CloudFormation, or Bicep
- HITRUST or NIST 800-53 control framework experience
- Diagramming and modeling tools: Lucidchart, Visio, draw.io, C4/ArchiMate
This role combines hands-on cloud networking with architecture and documentation ownership: you will design secure connectivity across AWS, Azure, and Snowflake, and produce the architecture, data flow, and process flow documentation that business, compliance, and audit stakeholders depend on. All work is performed under HIPAA, with PHI protection treated as a first-order design constraint.
Job Title: Network Security Lead Engineer
Location: NJ/NYC
Work Authorization: USC. GC & H1B
Experience : 13+ Years
Domain: Health Care
Job Description:
- Designs and owns enterprise network security architecture across cloud, on-premises, and hybrid environments
- Defines standards for firewalls, VPNs, zero-trust, network segmentation, and perimeter controls
- Conducts threat modelling, architecture reviews, and risk assessments to identify and remediate security gaps
- Evaluates and selects network security technologies including SASE, SD-WAN, IDS/IPS, and NAC solutions
- Embeds security into infrastructure and cloud design from the outset through cross-functional collaboration
- Ensures compliance with ISO 27001, SOC 2, HIPAA, NIST, and applicable regulatory frameworks
- Provides technical governance and mentors junior security engineers across network security projects
- 8+ years of hands-on experience with Cisco, Palo Alto, Zscaler, or equivalent platforms
- Strong knowledge of TCP/IP, BGP, routing protocols, and cloud networking (AWS / Azure)
- Associated certifications preferred.
Key Responsibilities
Architecture & Governance
- Design and own enterprise network security architecture across cloud, on-premise, and hybrid environments
- Define standards for firewalls, VPNs, zero-trust, network segmentation, and perimeter controls
- Conduct threat modeling, architecture reviews, and risk assessments to identify and remediate security gaps
- Evaluate and select network security technologies including SASE, SD-WAN, IDS/IPS, and NAC
- Embed security into infrastructure and cloud design from the outset through cross-functional collaboration
- Provide technical governance and mentor junior security engineers across network security projects
Documentation & Blueprints
- Review, validate, and recreate business blueprint documentation where source material is outdated or incomplete
- Produce secure architecture diagrams covering topology, segmentation, trust boundaries, and control points
- Develop end-to-end data flow diagrams tracing PHI movement across systems and organizational boundaries, including encryption state at each hop
- Create process flow diagrams for operational and integration workflows, and keep all documentation synchronized with the deployed environment
Cloud & Connectivity Engineering
- Design, configure, and troubleshoot IPsec site-to-site VPN tunnels, AWS Transit Gateway, Azure Virtual WAN, VPC/VNet peering, and private connectivity (AWS Private Link, Azure Private Link, Snowflake PrivateLink)
- Secure data ingress/egress paths into Snowflake, including network policies and storage integrations
- Support hybrid connectivity between on-premises data centers and cloud (Direct Connect, ExpressRoute, VPN)
- Design and support secure file transfer using SFTP, FTPS, and HTTPS/TLS, including certificate and key lifecycle management
Compliance
- Ensure compliance with ISO 27001, SOC 2, HIPAA, NIST, and applicable regulatory frameworks
- Partner with Security, Privacy, and Compliance teams on control mapping and audit evidence
- Enforce encryption in transit and at rest across all PHI-bearing data paths
Required Qualifications
- 8+ years of hands-on experience with Cisco, Palo Alto, Zscaler, or equivalent platforms
- Strong knowledge of TCP/IP, BGP, routing protocols, and cloud networking (AWS / Azure)
- Production experience designing and troubleshooting VPN tunnels, including IPsec/IKEv2 and BGP routing
- Practical experience with secure transmission protocols: SFTP, FTPS, HTTPS/TLS, mTLS, SSH key and certificate management
- Proven track record producing architecture, data flow, and process flow diagrams for technical and compliance audiences
- Working knowledge of HIPAA and HITECH, particularly the Security Rule's transmission security and access control provisions
- Healthcare domain experience — payer, provider, HIE, or health tech — with familiarity handling PHI
- Excellent written communication: documentation that stands up to audit scrutiny
Thanks & Regards
Shruteesh Kumar A
Senior Recruitment Specialist
Email: shrutee...@stiorg.com | Web: www.stiorg.com
LinkedIn: linkedin.com/in/shruteesh
100 Overlook Center, Suite 200 | Princeton, NJ 08540
C2C Open Groups: Please feel free to join and share these groups with others who may find them useful. Kindly share the link with your contacts as well.
https://www.linkedin.com/groups/39200005/
https://chat.whatsapp.com/IvUfxmmchFd6xrD9dpjgqC?s=cl&p=a&ilr=0