OnMed

OnMed

2 open positions available

2 locations
1 employment type
Actively hiring
Full-time

Latest Positions

Showing 2 most recent jobs
OnMed

Senior Security Engineer

OnMedWhite Plains, New YorkFull-time
View Job
Compensation$85K - 130K a year

Design, deploy, and manage security controls across cloud, application, and network environments focusing on Azure and Entra ID, lead incident response, tune security stacks, and maintain compliance evidence. | 7+ years information security experience with 5+ years hands-on Azure cloud security engineering, bachelor's degree, scripting proficiency, and compliance knowledge. | Who We Are and Why Join Us At OnMed our purpose is simple but powerful...to improve the quality of life and sense of well-being in our communities by bringing access to healthcare to everyone, everywhere. Our path to everywhere has already begun, with our innovative CareStation, a small but mighty, Clinic-in-a-Box, bringing #healthcareaccess anywhere with an outlet to plug it in. Poised to become a key component in America’s public health infrastructure, the OnMed CareStation is the only tech-enabled, human-led, hybrid care solution that combines the comprehensive experience, trust and outcomes of a clinic, with the rapid scalability of virtual care. At OnMed, every role, everyday, is directly impacting the communities we serve. You’ll join a high-performing purpose-driven team, innovating to break down the barriers that keep people from the care they need. This is not just a job...it's a movement to bring access to healthcare where and when people need it most. It’s healthcare that shows up. Who You Are You are a hands-on, deeply technical Security Engineer who designs, builds, deploys, and operates security across cloud, application, network, and physical infrastructure— not from the sidelines, but with your hands on the tools. You are fluent in the Microsoft Azure and Entra ecosystem, you understand networking and firewall rules cold, and you are just as comfortable reviewing application code as you are tuning detections in an XDR/SIEM console and running an incident to ground. You stay current with emerging threats and technologies, you automate what should be automated, and you have enough compliance grounding to translate technical controls into evidence auditors trust. You thrive in a new, fast-paced, high-demand environment and take direct ownership of the security and resilience of the systems that protect our patients’ healthcare data. Role's Responsibilities Designing, building, deploying, and managing security controls hands-on across OnMed’s cloud, application, and network environments— owning the outcomes directly rather than overseeing them from a distance. Architecting and hardening the Microsoft Azure and M365/Entra environment—identity, network security groups, firewall rules, and encryption at-rest and in-transit— along with corporate and CareStation field-device endpoints. Operating and tuning the security stack day to day: XDR/MDR, SIEM, and SOC workflows—building and refining detections, triaging alerts, and working them hands-on. Leading incident response end to end: triage, containment, eradication, root cause analysis, and documentation. Designing, reviewing, and maintaining network and firewall architecture—segmentation, rule sets, VPN, and Zero Trust access for the remote workforce and field devices. Reviewing application code, integrations, and system designs (in-house and vendor-built) for security gaps, and partnering with engineering on remediation. Automating security operations and repetitive tasks through scripting where it strengthens detection, response, or hardening. Administering identity and access in Entra ID— quarterly access reviews, privileged account audits, and MFA/SSO enforcement. Maintaining control evidence for SOC 2, HITRUST, FedRAMP, HIPAA, and related frameworks, supporting auditor and assessor requests, and tracking findings through to remediation. Where a managed security services provider is used, directing and holding them accountable as an extension of the in-house team—while retaining direct ownership of security outcomes. Maintaining security policies, supporting security awareness training, and responding to customer and vendor security questionnaires. Knowledge, Skills & Abilities Must Have: Deep, hands-on experience designing, developing, deploying, and managing security across multiple technology stacks—engineering the controls yourself, not only directing others. Strong hands-on expertise with Microsoft Azure cloud security and the M365/Entra ID stack—identity, network security, and workload protection. Excellent understanding of networking and firewall rules—segmentation, NGFW and Azure Firewall rule design and administration, VPN, IDS/IPS, and Zero Trust Network Access across remote users and field devices. Application security depth—reviewing code, integrations, and system designs for vulnerabilities, with familiarity with the OWASP Top 10 and SAST/DAST tooling. Hands-on experience operating XDR/MDR, SIEM, and SOC environments—building and tuning detections and working alerts directly. Hands-on incident response experience—triage, containment, root cause analysis, and documentation. Scripting and automation ability (e.g., PowerShell, Python, KQL) to automate detection, response, and hardening—a strong plus where the role calls for it. A working compliance background—practical knowledge of one or more of SOC 2, NIST, CIS, HITRUST, and FedRAMP, including producing control evidence and working with external auditors or assessors. Working knowledge of HIPAA-scoped PHI handling, data classification, Security Rule requirements, and breach notification. Endpoint and device hardening, with encryption at-rest and in-transit across cloud, corporate, and field-deployed devices. Familiarity with AI security: securing AI tools and platforms in use across the organization, and evaluating AI-driven security tooling to defend against AI-enabled threats. Strong written communication—this role writes for engineering peers, auditors, vendors, and non-technical leadership regularly. Comfort supporting and working in a rapidly growing, fast-paced, high-demand environment. Nice-to-Have: Advanced Security Operations automation (e.g., leveraging Elastic). Hands-on experience with Palo Alto NGFW, Azure Firewall administration, and Cloudflare security services. Experience implementing and managing cloud service provider, SaaS, and PaaS security. Experience securing IoT, embedded devices, and infrastructure deployed in public settings. Vendor risk assessment experience—due diligence, tiering, and ongoing third-party risk tracking—and experience managing an MSSP or MSP relationship. Familiarity with GRC or compliance tracking platforms. Exposure to agentic AI tooling or AI governance programs. Prior healthcare or other regulated-industry experience. Education & Experience Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent practical experience. 7+ years of experience in information security with substantial hands-on engineering, preferably in a regulated industry. 5+ years securing cloud (Azure preferred) and on-prem environments hands-on. AZ-500, Security+, GSEC, or CySA+ preferred; OSCP, GCIH, or CISSP/CISM are good nice-to-haves. OnMed provides a competitive salary and benefits package, including unlimited PTO and paid holidays. The base salary for this role is $130,000 - $140,000 commensurate with the candidate's experience. OnMed is a proud equal opportunity employer. All qualified applicants will be considered without regard to race, color, creed, religion, gender, sexual orientation, national origin, genetic information, disability, age, marital status, veteran status, or any other category protected by law. #LI-HYBRID

Microsoft Azure Security
Entra ID
Network Security
Firewall Administration
Incident Response
Application Security
XDR/MDR
SIEM
SOC Operations
Scripting
Compliance Frameworks
HIPAA
Zero Trust Network Access
Vulnerability Management
Identity and Access Management
AI Security
Direct Apply
Posted about 2 months ago
OnMed

Senior Data Engineer

OnMedAnywhereFull-time
View Job
Compensation$90K - 140K a year

Design and maintain scalable enterprise data solutions and pipelines with a focus on healthcare interoperability. | Bachelor's degree and 7+ years in data engineering with expertise in Databricks, Azure, Python, SQL, and healthcare standards. | Who We Are and Why Join Us At OnMed our purpose is simple but powerful...to improve the quality of life and sense of well-being in our communities by bringing access to healthcare to everyone, everywhere. Our path to everywhere has already begun, with our innovative CareStation, a small but mighty, Clinic-in-a-Box, bringing #healthcareaccess anywhere with an outlet to plug it in. Poised to become a key component in America’s public health infrastructure, the OnMed CareStation is the only tech-enabled, human-led, hybrid care solution that combines the comprehensive experience, trust and outcomes of a clinic, with the rapid scalability of virtual care. At OnMed, every role, every day, is directly impacting the communities we serve. You’ll join a high-performing purpose-driven team, innovating to break down the barriers that keep people from the care they need. This is not just a job… it’s a movement to bring healthcare where and when people need it most. It’s healthcare that shows up. Who You Are You are a senior-level Data Engineer and integration architect experienced in designing and scaling enterprise data platforms in cloud-first environments. You bring deep expertise in Databricks and Microsoft Azure and have led the architecture, optimization, and governance of modern data ecosystems. You think beyond pipelines – you design resilient, scalable data platforms that power analytics, interoperability, and operational systems. You are comfortable operating at both the strategic architecture level and the hands-on engineering level. You thrive in high-growth environments and are motivated by leveraging data to expand access to quality healthcare. Role Responsibilities Enterprise Data Architecture & Platform Ownership Architect, design, and scale enterprise-grade data solutions using Databricks and Azure cloud services. Own and evolve the Databricks environment, including performance optimization, cost management, governance, and security controls. Define long-term data architecture strategy aligned to business growth and healthcare compliance, and the evolution of OnMed’s CareStation and HomeStation platforms. Establish data modeling standards, metadata management practices, and scalable ETL/ELT frameworks. Integration Architecture & Interoperability Serve as lead integration architect across all system interfaces and API-driven data exchanges. Design and optimize integration patterns using Azure Data Factory, Azure API Management, and event-driven architectures. Ensure reliable, secure, and scalable interoperability between internal systems, third-party platforms, and healthcare data sources – including HL7/FHIR-based integrations with EHR and clinical systems. Oversee monitoring, observability, and fault tolerance across all integration touchpoints. Data Engineering & Pipeline Development Build and optimize high-performance, scalable data pipelines in Databricks using Python and SQL. Design and implement advanced data transformations and complex query optimization. Implement automated testing, validation frameworks, and data quality controls to ensure pipeline reliability. Drive CI/CD practices and infrastructure-as-code principles for data platform management. Governance, Security & Compliance Establish and enforce data governance standards using Databricks Unity Catalog, including lineage tracking, auditing, and role-based access controls. Ensure compliance with healthcare data privacy and security regulations including HIPAA, HITRUST, and SOC 2 requirements. Implement role-based access, encryption standards, and secure API management, and access controls for PHI/PII data handling. Cross-Functional Leadership Partner with BI, analytics, product, and engineering teams to translate business needs into scalable data solutions. Provide architectural guidance and mentorship to junior engineers and analysts. Influence data strategy at the leadership level through proactive recommendations and roadmap planning. Communicate technical concepts clearly to non-technical stakeholders including clinical, operational, and executive audiences. Knowledge, Skills & Abilities Experience operating in regulated industries; healthcare (HIPAA, HITRUST, SOC 2) strongly preferred. Deep expertise in Databricks: Delta Lake, Unity Catalog, performance tuning, cost optimization, job orchestration. Advanced knowledge of Azure services including Azure Data Factory, Azure API Management, Azure Storage, and related cloud infrastructure. Strong proficiency in SQL (complex query optimization, performance tuning, indexing strategies) and Python; working knowledge of C# a plus. Extensive experience designing scalable ETL/ELT frameworks and data warehousing solutions. Experience implementing event-driven or API-based integration architectures. Familiarity with healthcare interoperability standards (HL7, FHIR) is a strong advantage. Proven ability to balance architectural vision with hands-on execution. Strong communication skills with the ability to influence technical and non-technical stakeholders at all levels. Demonstrated ability to mentor engineers and drive engineering best practices across a team. Education & Experience Bachelor's degree in Computer Science, Information Technology, or a related field. 7+ years of progressive experience in data engineering, data architecture, or enterprise integration. Bachelor’s degree in Computer Science or a related technical field. Experience with Databricks and Azure. Strong experience designing data models, data pipelines, and integration architectures. Advanced SQL and Python skills for ETL, APIs, and workflow automation. Hands-on expertise with Azure Data Factory and Azure API Management. Experience working with internal system owners, external integration partners, and cross-functional teams around data architecture and API integrations. Eligibility to work in the United States. Healthcare knowledge is a plus. OnMed provides a competitive salary and benefits package, including unlimited PTO and paid holidays. The base salary range for this role is up to $170,000 commensurate with the candidate's experience, plus an annual discretionary performance bonus. OnMed is a proud equal opportunity employer. All qualified applicants will be considered without regard to race, color, creed, religion, gender, sexual orientation, national origin, genetic information, disability, age, marital status, veteran status, or any other category protected by law. #LI-HYBRID

API Design
System Architecture
JavaScript
TypeScript
REST API
Terraform
Direct Apply
Posted 3 months ago

Ready to join OnMed?

Create tailored applications specifically for OnMed with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt