Staff Security Engineer

RemoteFull-timePosted Jul 21, 2026

Lyric is an AI-first, platform-based healthcare technology company, committed to simplifying the business of care by preventing inaccurate payments and reducing overall waste in the healthcare ecosystem, enabling more efficient use of resources to reduce the cost of care for payers, providers, and patients. Lyric, formerly ClaimsXten, is a market leader with 35 years of pre-pay editing expertise, dedicated teams, and top technology. Lyric is proud to be recognized as 2025 Best in KLAS for Pre-Payment Accuracy and Integrity and is HI-TRUST and SOC2 certified, and a recipient of the 2025 CandE Award for Candidate Experience. Interested in shaping the future of healthcare with AI? Explore opportunities at lyric.ai/careers and drive innovation with #YouToThePowerOfAI.

Applicants must already be legally authorized to work in the U.S.  Visa sponsorship/sponsorship assumption and other immigration support are not available for this position.

The Staff Security Engineer will design, implement, and operate the security technologies that protect Lyric’s intellectual property and customer data across cloud ecosystems (Azure and AWS), corporate infrastructure, and endpoints. This role spans identity and access management (IAM), endpoint detection and response (EDR), security information and event management (SIEM), data loss prevention (DLP), network security, and vulnerability management. The position partners with technology and business teams to deliver secure, scalable solutions aligned with Lyric’s security roadmap.

ESSENTIAL JOB RESPONSIBILITIES

  • Design, build, deploy, and operate security controls and tooling across AWS, Azure, corporate networks, and endpoints
  • Engineer, tune, and maintain SIEM content – log onboarding, parsing, correlation rules, and detections – and develop automation and orchestration (SOAR) playbooks to reduce response times
  • Administer and optimize the endpoint detection and response (EDR) platform, including sensor deployment, policy tuning, threat hunting support, and endpoint hardening
  • Engineer and maintain identity and access management capabilities, including single sign-on (SSO), multi-factor authentication (MFA), conditional access, privileged identity/access management (PIM/PAM), and role lifecycle automation
  • Partner with Security Architecture to translate reference architectures and design principles into implemented, measurable technical controls, providing feedback that improves future designs
  • Serve as a technical lead during security incidents – building and maintaining containment tooling, forensics readiness, and response runbooks, and participating in post-incident reviews
  • Operate the vulnerability management lifecycle: scanning, risk-based prioritization, and partnering with application and infrastructure teams to drive remediation to closure
  • Implement and enforce baseline security configuration standards (e.g., CIS benchmarks, OS hardening, network segmentation, web application firewall) through infrastructure-as-code and policy-as-code where possible
  • Evaluate, proof-of-concept, and recommend security technologies, tools, and services to the broader security team based on security policy, threat drivers, and operational fit
  • Mentor junior engineers, maintain high-quality documentation and runbooks, and participate in an on-call rotation for security escalations

REQUIRED QUALIFICATIONS

  • Minimum of seven (7) years of experience in hands-on security engineering and/or security operations
  • Minimum of three (3) years of experience engineering and operating security controls within Amazon Web Services (AWS) and Microsoft (MS) Azure

PREFERRED QUALIFICATIONS

  • Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience
  • CISSP, CCSP, GIAC (e.g., GSEC, GCIH, GCIA), or other relevant security-related designation(s)
  • AWS Security Specialty Certification, Azure Security Engineer Certification
  • Experience engineering identity platforms such as Microsoft Entra ID, including conditional access, privileged identity management (PIM), and identity governance
  • Experience administering endpoint detection and response (EDR) platforms (e.g., CrowdStrike Falcon) and engineering SIEM detections, including detection-as-code practices
  • Proficiency with scripting and automation – Python, PowerShell, and infrastructure-as-code tooling such as Terraform – to deliver security capabilities at scale
  • Experience in DevSecOps, container and Kubernetes security, CI/CD pipeline security, and securing SaaS, IaaS, and PaaS workloads
  • Experience with network security technologies, including WAF/CDN/DDoS services, intrusion detection/prevention systems (IDS/IPS), network segmentation, and zero trust access patterns
  • Working knowledge of security frameworks and standards such as the NIST Cybersecurity Framework, HITRUST, CIS benchmarks, and the MITRE ATT&CK framework
  • Experience with data protection, including data loss prevention (DLP), cryptography, key management, and public key infrastructure (PKI)
  • Experience operating security tooling in healthcare or other regulated environments subject to HIPAA or similar data protection requirements


***The US base salary range for this full-time position is:

$125,241.00 - $187,862.00

The specific salary offered to a candidate may be influenced by a variety of factors including but not limited to the candidate’s relevant experience, education, and work location. Please note that the compensation details listed in US role postings reflect the base salary only, and does not reflect the value of the total rewards compensation. ***

Lyric is an Equal Opportunity Employer that strives to create an inclusive environment, empower employees and embrace collaborative success.

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free