MDVIP: Transforming Primary Care, One Patient at a Time
MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work® since 2018, MDVIP is committed to excellence in patient care and employee satisfaction.
Position Summary
The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers.
This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization’s on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations — including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score — while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule.
Key Responsibilities
Security Remediation & Compliance
- Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third-party resources to ensure timely delivery.
- Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments.
- Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere).
- Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements.
- Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score.
Core Platform & Infrastructure Ownership
- Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders.
- Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non-compliant certificates, and manage key vault rotations for critical cloud-hosted applications.
- Utilize automation tools to deploy required machine certificates across the organization.
- Manage syslog retention and forwarding across on-premises and cloud infrastructure, supporting the Security team’s SIEM ingestion, correlation, and compliance reporting needs.
- Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning.
- Review and administer security tools to harden network edge security, including next generation firewalls, SD-WAN, and switching, striving for zero trust networks.
- Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass.
- Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls.
- Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices.
- Review and secure SDLC servers and hosted applications, both on-premises and in Azure, applying measures to keep all public endpoints secure.
Operational Reliability & Risk Reduction
- Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables.
- Identify and reduce single-point-of-failure risk by documenting procedures and cross-training across PKI, AD, cloud access, segmentation, and patching functions.
- Partner with the Azure DevOps and Security teams to align on-prem/hybrid remediation with broader cloud governance and security initiatives.
- Escalate emerging risks, audit exceptions, and outage-driving conflicts between operational and remediation priorities to leadership.
Key Competencies
- Analytical: synthesizes complex or diverse technical information, using intuition and experience to complement data.
- Collaboration: openly partners with security operations, DevOps, and business stakeholders, valuing diverse perspectives and building productive relationships.
- Communication: listens and responds effectively to stakeholder needs; writes and speaks clearly and persuasively.
- Initiative and personal accountability: identifies and creates solutions independently, sets and meets deadlines, and reports timely and prepared.
- Problem solving/decision making: thinks strategically, drawing on diverse sources to identify issues, risks, and trends and determine optimal, timely solutions.
- Strong troubleshooting skills and the ability to manage competing priorities between reactive operational work and scheduled remediation projects.
- Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours.
- Ability to travel periodically between the Boca Raton, FL and Atlanta (ATL) data centers as needed.
Qualifications
Required Qualifications
- Bachelor’s degree in Computer Science, Information Security, or a related field; at least five (5) years of related business experience in network security, systems engineering, or infrastructure operations in an enterprise environment, or an equivalent combination of education and professional experience.
- Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments.
- Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent).
- Experience partnering with security operations/SIEM teams to onboard new log sources and ensure reliable syslog delivery from network infrastructure.
- Working knowledge of hybrid Active Directory/Microsoft Entra ID environments and familiarity with network segmentation concepts and tools (e.g., Illumio or comparable micro-segmentation platforms).
- Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, or penetration test findings.
- Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass).
- This is a hybrid role based in Boca Raton, FL, with periodic on-site support required at the Boca Raton and Atlanta (ATL) data centers. At no time may work be performed, or computer systems accessed, from outside of the U.S.
Preferred Qualifications
- Vendor-specific certifications, Microsoft Azure, Security+, CISSP, GIAC, or an equivalent security certification.
- Scripting/automation experience (e.g., PowerShell) for remediation and hardening tasks.
Why Join MDVIP?
- Be part of a mission-driven organization leading innovation in personalized healthcare.
- Drive transformation and growth in a dynamic, fast-paced environment.
- Competitive Compensation: Attractive base salary complemented by performance-based incentives.
- Comprehensive Benefits: Health, dental, vision insurance, and retirement plans.
- Professional Development: Access to ongoing training and leadership development programs.
- Positive Work Environment: Consistently recognized as a Great Place to Work®, fostering a culture of collaboration and excellence.
MDVIP is an Equal Opportunity Employer and is committed to fostering an inclusive and diverse workplace. We welcome applicants of all backgrounds and do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected status. We believe that diversity and inclusion drive innovation and strengthen our company culture.
If you require accommodations during the application or interview process, please let us know, and we will be happy to assist.
Pay Transparency: Our compensation reflects the cost of labor across appropriate US geographic markets. Pay is based on several factors including but not limited to market location and may vary depending on job-related knowledge, skills, and education/training and a candidate's work experience. Hired applicants are offered annual incentive compensation programs, subject to applicable eligibility requirements. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance. The company offers the following benefits for this position, subject to applicable eligibility requirements. Medical/prescription drug coverage, Dental coverage, Vision coverage, Flexible Spending Account, Health Savings Account, Dependent Care Flexible Spending Account, Basic and Supplemental Life Insurance & Accidental Death and Dismemberment, Disability Income Protection Plan, Employee Assistance Program, 401(k) retirement program, Vacation, Paid Holidays and Personal time, Paid Sick and Family and Medical Leave time as required by law.