Back to jobs
New

Senior Cyber Security Defense Engineer

Remote

Vail Health has become the world’s most advanced mountain healthcare system. Vail Health consists of an updated 520,000-square-foot, 56-bed hospital.  This state-of-the-art facility provides exceptional care to all of our patients, with the most beautiful views in the area, located centrally in Vail. Learn more about Vail Health here.

Some roles may be based outside of our Colorado office (remote-only positions). Roles based outside of our primary office can sit in any of the following states: AZ, CO, CT, FL, GA, ID, IL, KS, MA, MD, MI, NC, NJ, OH, OR, PA, SC, TN, TX, UT, VA, WA, and WI. Please only apply if you are able to live and work primarily in one of the states listed above. State locations and specifics are subject to change as our hiring requirements shift.
 
About the opportunity:

Under the direction of the Chief Information Security Officer (CISO), the Senior Cyber Security Defense Engineer, is a high-impact, senior-level individual contributor who architects, implements, and continuously matures the technical capabilities that actively defend Vail Health from sophisticated cyber threats and measurably reduce enterprise cyber risk. The ideal candidate brings deep hands-on expertise, sound judgment, drives the strategy, execution, and continuous improvement of vulnerability management, patching, cyber threat intelligence monitoring, and incident response capabilities. The role operates at the intersection of security engineering, security operations, compliance, and risk management — influencing outcomes across Infrastructure, Cloud, Applications, and clinical business units while ensuring alignment with Health Insurance Portability and Accountability Act (HIPAA), National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), Center of Internet Security (CIS Controls v8), MITRE ATT&CK, and Health and Human Services (HHS) 405(d) Health Industry Cybersecurity Practices (HICP).

 
What you will do:
  • Own and lead the enterprise patch management and security health program across endpoints, servers, cloud platforms, network devices, and security technologies — establishing governance, SLAs, and compliance reporting that support executive risk decisions.
  • Design, implement, and continuously improve secure configuration standards, automated patch deployment workflows, and change management integration in collaboration with Infrastructure and Cloud teams.
  • Own and continuously mature the Vulnerability Management Program — governing tooling strategy, scanning cadence, risk-based prioritization (common vulnerability scoring system (CVSS), known exploited vulnerabilities(KEV), asset criticality, data sensitivity), remediation service level agreement enforcement, and validation of remediation effectiveness — while producing defensible reporting, trend analysis, and exception documentation for leadership, auditors, and governance reviews.
  • Define and maintain enterprise patch compliance metrics, configuration hygiene baselines, and vulnerability exposure dashboards with measurable key performance indicators (KPI)s tied to risk reduction outcomes.
  • Provide advanced Tier 2/Tier 3 security operations support, independently investigating and responding to complex security alerts including malware, endpoint compromise, lateral movement, privilege escalation, and anomalous behavior patterns.
  • Correlate security telemetry across security information and event management (SIEM), endpoint detection and response (EDR), email security, cloud, and network platforms to identify, prioritize, and contain active and emerging threats; systematically improve detection fidelity through alert tuning, correlation logic, and automation.
  • Develop, maintain, and continuously improve security operations runbooks, incident response playbooks, escalation procedures, and detection engineering standards that improve operational effectiveness and reduce analyst toil.
  • Lead enterprise email security operations and social engineering defense including proactive monitoring and response for phishing, smishing, spoofing, and business email compromise (BEC) campaigns.
  • Optimize email and messaging security controls — including DMARC, DKIM, SPF enforcement, anti-phishing technology configuration, and analytics — to measurably reduce user-facing risk and improve prevention posture.
  • Serve as a core incident responder and technical lead, driving containment, eradication, recovery, forensic evidence collection, log analysis, and root-cause investigation for cybersecurity incidents affecting Vail Health.
  • Author post-incident reviews and drive continuous improvement through lessons-learned integration, control enhancement recommendations, and participation in on-call incident response rotations.
  • Support enterprise risk management, audit, and compliance initiatives by independently delivering defensible security metrics, dashboards, and executive-level reporting without requiring rework or interpretation support. 
  • Identify and execute opportunities for operational efficiency and cost savings through tool optimization, automation investment, and vendor rationalization — coordinating with CISO and procurement.
    Mentor and provide technical guidance to junior engineers and IT partners; actively influence a security-first culture through standards, documentation, and cross-functional collaboration.
  • Collaborates cross-functionally and contributes to a security-first culture while supporting on-call rotations for 24/7 system needs. 
This description is not intended and should not be construed to be an exhaustive list of all responsibilities, skills and efforts or work conditions associated with the job. It is intended to be an accurate reflection of the general nature and level of the job.
 
What you will need:
 
Experience:
  • Eight years of progressive experience in cybersecurity engineering, threat detection, vulnerability management, or incident response — with demonstrated expertise across multiple domains.
  • Proven record of accomplishment of standing up or significantly maturing enterprise patch management and vulnerability management programs, including governance frameworks, SLA development, operational cadence, and stakeholder reporting.
  • Hands-on expertise with enterprise patch management platforms such as Tanium, HCL BigFix, Automox, SCCM/Intune, WSUS, or JAMF — including deployment automation and change workflow integration.
  • Deep experience with enterprise security tooling including Tenable, Qualys, or Rapid7 (vulnerability management) and Microsoft Defender, CrowdStrike, or Sentinel One (EDR/endpoint protection).
  • Demonstrated proficiency with SIEM platforms (Microsoft Sentinel, Splunk, LogRhythm, or equivalent) including advanced log analysis, detection authoring, alert tuning, and threat correlation at scale.
  • Strong command of security frameworks and methodologies — NIST CSF, CIS Controls v8, MITRE ATT&CK, and ISO 27001 — with the ability to directly map technical work to control outcomes and audit evidence.
  • Experience operating in regulated, audit-intensive environments with direct accountability for audit support and compliance evidence production; healthcare experience strongly preferred.
  • Demonstrated ability to independently influence cross-functional stakeholders, prioritize remediation in complex distributed environments, and communicate technical risk in business-impact terms without requiring translation support.
Education:
  • Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical discipline — or equivalent professional experience demonstrating the same depth of competency.
License(s) and Certification(s):
  • Certified Information Systems Security Professional (CISSP), Security+, CySA+, CEH, GCIH, GCIA, GMON, or cloud security certifications (Azure, AWS, M365).
  • Other IT Security Certifications Desired: CISM, CISA, Microsoft, Cisco 

 

 

 

Benefits at Vail Health (Full Time) Include:

  • Competitive Wages & Family Benefits:
    • Competitive wages
    • Parental leave (4 weeks paid)
    • Housing programs
    • Childcare reimbursement 
  • Comprehensive Health Benefits: 
    • Medical
    • Dental 
    • Vision
  • Educational Programs: 
    • Tuition Assistance 
    • Existing Student Loan Repayment
    • Specialty Certification Reimbursement
    • Annual Supplemental Educational Funds
  • Paid Time Off:
    • Up to five weeks in your first year of employment and continues to grow each year.
  • Retirement & Supplemental Insurance:
    • 403(b) Retirement plan with immediate matching 
    • Life insurance
    • Short and long-term disability
  • Recreation Benefits, Wellness & More:
    • Up to $1,000 annual wellbeing reimbursement
    • Recreation discounts
    • Pet insurance

 

The posted salary range for this position is the anticipated hiring range in Colorado and will be adjusted based on geographic location. Vail Health considers a variety of factors in making compensation decisions which influence the offer a candidate receives.

Yearly pay:

$104,208 - $143,811.20 USD

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...
Select...
Do you hold any other IT Security Certifications Desired: *
Select...
Select...
Select...
Select...
Select...
Select...
Read carefully and acknowledge. *

I certify that all the information provided in this employment application is true and complete. I understand that any false information or omission may disqualify me from further consideration for employment and may result in my dismissal if discovered at a later date. I understand that Vail Health may request an investigative consumer report from a consumer reporting agency. I understand I have the right to make a written request within a reasonable time for the disclosure of the name and address of the consumer reporting agency so that I may obtain a complete disclosure of the nature and scope of the investigation. Vail Health may request information as to my character, reputation, personal characteristics and mode of living from my neighbors, friends, former employers, school and other. I authorize that investigation of any or all statements contained in this application and also authorizes whether listed or not, any person, school, current employers (except as previously noted), past employers and organizations to provide relevant information and opinions that may be useful in making a hiring decision. I consent to the release of any or all medical information as may be deemed necessary to judge my capability to do the work for which I am applying. I agree to immediately disclose to Vail Health any debarment, suspension, exclusion, conviction of a criminal offence, or other event that may make me ineligible to participate in federally funded healthcare programs. I understand and I will be required to successfully pass a drug screening examination. I hereby consent to a drug screening as a condition of employment.

I UNDERSTAND THAT THIS APPLICATION OR SUBSEQUENT EMPLOYMENT DOES NOT CREATE A CONTRACT OF EMPLOYMENT NOR GUARANTEE EMPLOYMENT FOR ANY DEFINITE PERIOD OF TIME. IF EMPLOYED , I UNDERSTAND THAT I HAVE BEEN HIRED AT THE WILL OF VAIL HEALTH OR ONE OF ITS OUTREACH FACILITIES AND MY EMPLOYMENT MAY BE TERMINATED AT ANY TIME, WITH OUT WITHOUT CAUSE AND WITH OR WITHOUT NOTICE.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Vail Health Private’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.