XO Health believes healthcare is fixable. Become part of the community changing the face of the industry.
XO Health is the first health plan designed by and for self-insured employers that delivers a more unified health experience for everyone – from those who receive care, to those who deliver it, to those who pay for it.
We are growing a multi-disciplinary team of diverse and digitally empowered employees ready to rebuild trust in healthcare through comprehensive and unified transformation.
CyberSecurity & Infrastructure Engineer - India (Remote)
About the Role:
The Cybersecurity & Infrastructure Engineer is responsible for designing, implementing, monitoring, and securing the organization's hybrid cloud and infrastructure environments. This role serves as a technical leader for cybersecurity operations, cloud security, compliance initiatives, infrastructure engineering, and incident response.
The position combines hands-on infrastructure administration with cybersecurity engineering responsibilities across Microsoft Azure, Microsoft Sentinel, Microsoft 365, Entra ID, AWS, networking, endpoints, and security platforms. Engineering plays a key role in maintaining compliance with SOC 2 Type II controls, improving cyber resilience, supporting audits, and advancing the organization's security maturity.
Responsibilities:
SOC2 Audit
- Support organization's annual SOC 2 Type II audit program, including control design, evidence collection, remediation management, auditor coordination, and continuous compliance monitoring.
- Partner with business and technology stakeholders to ensure security, availability, confidentiality, and change management controls are effectively implemented and operating throughout the audit period.
- Drive successful completion of SOC 2 Type II examinations with minimal findings by maintaining an audit-ready environment, strengthening internal controls, and promoting a culture of security and compliance.
- Develop and maintain policies, procedures, risk assessments, and control documentation necessary to support ongoing compliance and future audit readiness.
Cybersecurity Operations
- Administer and optimize Microsoft Sentinel SIEM platform.
- Develop and maintain security monitoring, analytics rules, alerting, dashboards, and automation workflows.
- Investigate security incidents and coordinate containment, remediation, and recovery activities.
- Monitor and respond to threats identified through Microsoft Defender, Sentinel, AWS security services, and third-party platforms.
- Conduct threat hunting, vulnerability management, and security assessments.
- Lead incident response activities and coordinate forensic investigations as needed.
- Maintain security documentation, playbooks, and response procedures.
- Support penetration testing, tabletop exercises, and disaster recovery testing.
Cloud Security & Architecture
- Design and maintain secure Microsoft Azure environments.
- Implement Azure security best practices utilizing:
- Microsoft Entra ID
- Conditional Access
- Privileged Identity Management (PIM)
- Defender for Cloud
- Azure Security Center
- Microsoft Purview
- Secure AWS cloud environments including:
- IAM
- CloudTrail
- GuardDuty
- Security Hub
- Config
- CloudWatch
- Implement zero-trust security principles across cloud platforms.
Infrastructure Engineering
- Maintain and support hybrid infrastructure environments including:
- Microsoft Azure
- AWS
- Active Director