NeoGenomics logo
NeoGenomics · Life sciences

Information Security Engineer

NeoGenomics Posted Aug 21, 2026
Workplace
On-site / per employer
Posted
Aug 21, 2026

Description

Are you motivated to participate in a dynamic, multi-tasking environment? Do you want to join a company that invests in its employees? Are you seeking a position where you can use your skills while continuing to be challenged and learn? Then we encourage you to dive deeper into this opportunity.

We believe in career development and empowering our employees. Not only do we provide career coaches internally, but we offer many training opportunities to expand your knowledge base! We have highly competitive benefits with a variety HMO and PPO options.

We have company 401k match along with an Employee Stock Purchase Program. We have tuition reimbursement, leadership development, and even start employees off with 16 days of paid time off plus holidays. We offer wellness courses and have highly engaged employee resource groups.

Come join the Neo team and be part of our amazing World Class Culture!

NeoGenomics is looking for an Information Security Engineer who wants to continue to learn in order to allow our company to grow. This is a hybrid in office position with Monday - Friday schedule to work out of either Ramsey, NJ or Fort Myers, FL locations.

Now that you know what we're looking for in talent, let us tell you why you'd want to work at NeoGenomics:

As an employer, we promise to provide you with a purpose driven mission in which you have the opportunity to save lives by improving patient care through the exceptional work you perform. Together, we will become the world's leading cancer reference laboratory.

Position Summary

As a Information Security Engineer you support the execution and continuous improvement of NeoGenomics’ enterprise information security program This hands-on role

partners across Security Operations, Governance, Risk and Compliance (GRC), Identity and Access Management (IAM), and Security Architecture to maintain effective security controls and support regulatory and audit requirements. You will manage the day-to-day configuration, monitoring, and optimization of core security tools; supports vulnerability remediation, incident response, and threat-hunting activities; and maintains technical documentation and evidence for audits, customer requests, and regulatory reviews The position requires practical information security experience and the ability to work cross-functionally within a regulated life sciences environment

Responsibilities

Operate and tune enterprise security platforms including Microsoft Defender, Varonis,

Mimecast, Zscaler, and Cisco Umbrella Maintain baseline configurations, tune

  • detections, and coordinate updates with the managed security services provider

Execute the vulnerability management program on Rapid7 with Active Risk Score

prioritization Partner with Infrastructure, Application, and Lab Operations teams to drive

  • remediation of critical and high-risk findings within SLA

Support privileged access operations in CyberArk, conditional access policies in Okta

and Azure AD/Entra ID, and MFA coverage across critical applications Assist with

  • quarterly access reviews and joiner/mover/leaver automation

Serve as a technical responder during security incidents Perform triage, containment

actions, evidence collection, and root cause analysis under the direction of Security

  • Operations leadership
  • Contribute to detection engineering activities across the SIEM and endpoint tooling

Build, test, and tune correlation rules aligned to MITRE ATT&CK techniques relevant to

  • healthcare and life sciences

Produce technical evidence artifacts for SOX ITGC, HIPAA, SOC 2 Type 2, and

CAP/CLIA audits Maintain screenshots, exports, and configuration snapshots aligned to

  • the control library

Education, Experience & Qualifications

Bachelor's Degree in Computer Science, Information Security, Information Technology, or

  • related field required; equivalent work experience considered

2+ years of hands-on experience in information security engineering, security operations,

  • or a closely related technical security role
  • Must be authorized to work in the United States without the need for current or future employer sponsorship.

One or more of the following industry certifications preferred: Security+, CySA+, GCIH, GCIA,

GSEC, or vendor certifications on primary security platforms (Microsoft SC series, Rapid7,

  • CyberArk)

Demonstrated experience operating enterprise security tooling in at least three of the

following categories: EDR/XDR, SIEM, vulnerability management, DLP, email security,

  • PAM, or identity governance

Working knowledge of NIST CSF 20, MITRE ATT&CK, and common security

  • frameworks (HIPAA, SOX ITGC, SOC 2)
  • Practical scripting or automation experience with PowerShell, Python, or Power Platform
  • Familiarity with cloud security concepts in Azure and AWS environments

Solid understanding of networking fundamentals, endpoint protection, and identity

  • protocols (SAML, OAuth, OIDC)

All qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status.

Originally posted by NeoGenomics. View original posting