VB

Vaco by Highspring

5 open positions available

1 location
2 employment types
Actively hiring
Full-time
Contract

Latest Positions

Showing 5 most recent jobs
VB

Senior Security Administrator

Vaco by HighspringAnywhereFull-time
View Job
Compensation$85K - 120K a year

Lead Microsoft 365 identity and security initiatives, mentor junior staff, and improve security processes in a managed services environment. | 5+ years IT/security experience with strong Microsoft 365 identity and access management skills, leadership ability, and experience in fast-paced environments. | Senior Security Administrator About the Role We are seeking a Senior Security Administrator to serve as a hands-on technical leader within a fast-paced managed services environment. This role is focused on Microsoft 365 identity and access management, customer security operations, process improvement, and team development. It is not a traditional SOC or threat-hunting position. The ideal candidate will own complex security and identity work while serving as a trusted escalation point, mentor, and technical resource for the broader team. Strong leadership is critical. This person should be able to guide junior team members, establish consistent practices, improve processes, and help increase the overall security maturity of customer environments. What You'll Do • Serve as a senior technical leader and trusted resource for Microsoft 365 identity and security initiatives. • Own Tier 2 security and identity work within Microsoft 365 customer environments. • Act as the primary escalation point for complex security, identity, and access issues raised by the support team. • Configure and troubleshoot Entra ID, SAML, OpenID Connect, multifactor authentication, and related identity services. • Lead customer onboarding and offboarding activities from a security and identity perspective. • Mentor junior security and support resources through technical challenges, troubleshooting, and security best practices. • Help establish clear standards, documentation, repeatable processes, and a consistent quality bar across the team. • Improve and streamline identity, onboarding, offboarding, and security administration processes. • Drive process improvement, automation, and stronger security practices across customer environments. • Participate in customer calls for projects, escalations, and sales support when needed. • Balance hands-on technical execution with team leadership and knowledge sharing. Required Qualifications • Strong hands-on experience with Microsoft 365 security, Entra ID, and identity and access management concepts. • Working knowledge of SAML, OpenID Connect, multifactor authentication, and modern identity practices. • Approximately 5 or more years of IT, systems, identity, or security experience preferred. • Experience working in a fast-paced managed services environment or a similarly high-volume, customer-focused setting. • Proven ability to lead technical initiatives and serve as a trusted resource for other engineers or administrators. • Experience mentoring junior team members and helping build their technical capabilities. • Ability to operate independently, take ownership, and move work forward without close oversight. • Experience handling security incidents and escalations from support or service teams. • Ability to support customer onboarding and offboarding from a security and identity perspective. • Strong troubleshooting, communication, documentation, and decision-making skills. • Comfort working through ambiguity, adapting quickly, learning from setbacks, and managing changing priorities. • Broad systems knowledge with strong learning ability and the confidence to work across unfamiliar tools. • Collaborative, low-ego, adaptable working style with a seasoned client-facing presence. • Ability to thrive in a fast-moving MSP environment rather than a rigid or slow-paced enterprise structure. Preferred Qualifications • Experience with Duo. • Experience with Huntress. • Exposure to SharePoint. • Experience with Inky. • Experience with Keeper. • Experience with additional Microsoft 365 or managed security tools. • Interest in automation and scripting to improve future processes and scalability. Typical Responsibilities • Resolve security ticket escalations and complex identity issues. • Configure, maintain, and troubleshoot identity and access services. • Execute and oversee customer onboarding and offboarding activities. • Coach team members and provide technical guidance during escalations. • Lead process improvement and documentation initiatives. • Join occasional customer meetings tied to tickets, projects, escalations, or sales support. • Help prevent knowledge gaps by sharing expertise and building repeatable team practices. Leadership & Working Style• Leads by example while remaining actively involved in day-to-day technical work. • Provides clear direction, constructive guidance, and practical mentorship to less experienced team members. • Creates structure in ambiguous situations and helps the team move forward with confidence. • Takes accountability for execution, service quality, and follow-through. • Communicates clearly with technical teams, business partners, and customers. • Builds trust through sound judgment, consistency, humility, and a willingness to help others succeed. Work Environment This is a direct-hire individual contributor role with a strong technical leadership and mentorship component. It is best suited for someone who thrives in a high-autonomy, fast-moving environment and is comfortable balancing customer needs, escalations, process improvement, and team development. Remote or hybrid flexibility is available. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. Equal Opportunity Notice Highspring LLC (d/b/a Vaco by Highspring) and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") are committed to the full inclusion of all qualified individuals and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by applicable law. The company is also committed to ensuring that persons who need them are provided with reasonable accommodations; if an accommodation is needed to participate in the job application or interview process, please contact HR@vaco.com . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. Additionally, you agree to be included in our talent pool for future hiring for similarly qualified positions. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. Lastly, you agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada only: to the extent the position for employment is not with Highspring or not otherwise noted as vacant above, candidate should be informed that this role is to replace a presently employed person at Vaco by Highspring's client. Privacy Notice Vaco by Highspring respects your privacy and are committed to providing transparent notice of our policies. • California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. • Virginia residents may access our state specific policies here. • Residents of all other states may access our policies here. • Canadian residents may access our policies in English here and in French here. • Residents of countries governed by GDPR and UK GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (https://www.highspring.com/ai-use-notices/). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: · the individual's skill sets, experience and training; · licensure and certification requirements; · office location and other geographic considerations; and · other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses and/or participation in medical, dental, and vision benefits as well as the company's retirement plan (or similar retirement benefits).

Microsoft 365 security
Identity and access management
Security incident management
Verified Source
Posted about 1 month ago
VB

Sr. Tax Manager - REMOTE

Vaco by HighspringAnywhereFull-time
View Job
Compensation$90K - 130K a year

Lead complex tax engagements, provide strategic tax planning, manage client relationships, and develop tax professionals. | CPA license, 8+ years public accounting, 6+ years tax review, 3+ years management experience, strong tax compliance and advisory skills. | Our client is seeking an experienced Tax Manager to lead complex tax engagements, provide strategic tax planning and advisory services, and serve as a trusted advisor to our clients. This role combines technical tax expertise, client relationship management, team leadership, and business development. The ideal candidate is a proactive problem solver who thrives in a collaborative environment and is passionate about delivering exceptional client service while developing others. Key Responsibilities Tax Compliance & Advisory • Lead complex tax compliance, planning, and consulting engagements for individuals, corporations, partnerships, trusts, estates, and other entity types. • Review tax returns and workpapers to ensure accuracy, quality, and compliance with applicable regulations. • Perform advanced tax research and develop practical recommendations for clients on federal, state, and specialty tax matters. • Prepare and review tax projections, planning strategies, and advisory deliverables. • Stay current on tax law changes and apply regulatory requirements and professional standards to client situations. • Identify tax risks, opportunities, and planning strategies that help clients achieve their objectives. • Represent clients during audits, notices, and other inquiries from taxing authorities. Client Relationship Management • Serve as the primary point of contact and trusted advisor for assigned clients. • Build and maintain strong client relationships through responsive communication and proactive service. • Communicate complex tax concepts in a clear, practical manner. • Identify opportunities to expand services and deliver additional value to clients. Engagement & Practice Management • Manage multiple engagements simultaneously, overseeing scope, budgets, timelines, staffing, and deliverables. • Ensure engagements are completed on time, within budget, and in accordance with firm quality standards. • Monitor workflow, utilization, realization, and overall engagement performance. • Identify and escalate engagement risks or issues as appropriate. • Collaborate with firm leadership to improve processes, efficiency, and service delivery across the tax practice. Business Development • Support proposals, presentations, and client pursuits in partnership with firm leadership. • Develop industry and market knowledge to identify advisory and growth opportunities. • Participate in networking, relationship-building, and marketing initiatives. • Contribute to the development and enhancement of service offerings. Team Leadership & Development • Mentor, coach, and develop tax professionals through training, feedback, and ongoing support. • Review team members' work to ensure quality while promoting professional growth. • Foster a collaborative, inclusive, and high-performing team culture. • Support recruiting, onboarding, retention, and staff development initiatives. • Promote accountability, respect, and equal opportunities for team members across the practice. Qualifications • Bachelor's degree in Accounting or a related field. • Active CPA license. • 8+ years of public accounting experience. • 6+ years of tax review experience. • 3+ years of supervisory or management experience. • Strong experience with tax compliance, planning, and research across multiple entity types. • Experience using tax research platforms such as RIA or similar tools. • Excellent leadership, communication, analytical, and client service skills. • Ability to manage multiple priorities and deliver results in a fast-paced environment. • Experience with CS Suite and UltraTax. • Experience working with complex entity structures. • Gift, estate, trust, and partnership tax experience. • Demonstrated success developing staff and building client relationships. • Continuous improvement mindset with a proactive and collaborative approach. Work/Life Balance & Employee Benefits Our client is committed to providing a work environment that supports both professional success and personal well-being, and to take care of their people. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. Equal Opportunity Notice Highspring LLC (d/b/a Vaco by Highspring) and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") are committed to the full inclusion of all qualified individuals and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by applicable law. The company is also committed to ensuring that persons who need them are provided with reasonable accommodations; if an accommodation is needed to participate in the job application or interview process, please contact HR@vaco.com . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. Additionally, you agree to be included in our talent pool for future hiring for similarly qualified positions. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. Lastly, you agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada only: to the extent the position for employment is not with Highspring or not otherwise noted as vacant above, candidate should be informed that this role is to replace a presently employed person at Vaco by Highspring's client. Privacy Notice Vaco by Highspring respects your privacy and are committed to providing transparent notice of our policies. • California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. • Virginia residents may access our state specific policies here. • Residents of all other states may access our policies here. • Canadian residents may access our policies in English here and in French here. • Residents of countries governed by GDPR and UK GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (https://www.highspring.com/ai-use-notices/). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: · the individual's skill sets, experience and training; · licensure and certification requirements; · office location and other geographic considerations; and · other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses and/or participation in medical, dental, and vision benefits as well as the company's retirement plan (or similar retirement benefits).

tax compliance
tax planning
team leadership
Verified Source
Posted about 1 month ago
Vaco by Highspring

Sr. Manager, Security Operations & Governance

Vaco by HighspringAnywhereContract
View Job
Compensation$146K - 166K a year

Lead and manage security remediation programs, coordinate technical teams and stakeholders, and oversee security operations and governance. | Requires 8+ years managing enterprise security operations and remediation programs, strong practical security knowledge, leadership skills, and healthcare or regulated environment experience. | Hiring a SENIOR MANAGER, SECURITY OPERATIONS & GOVERNANCE with prior experience in healthcare industry, Microsoft environment (365,InTune, Azure Security) and coordinating remediation across technical teams, vendors, business owners, and compliance stakeholders. Location: 100% remote in US Duration: 6-12 month contract Pay: $70-80/hr W2 This role will serve as the primary owner for security findings, remediation plans, vulnerability items, audit actions, risk exceptions, and enterprise security obligations. The position requires a hands-on leader who can translate security findings into practical action plans, assign ownership, track execution, validate evidence, escalate blockers, and drive closure across IT, compliance, vendors, and business stakeholders. The ideal candidate is not only able to organize and execute a security program but is also a security-minded operator who can work directly with technical teams on identity, endpoint, cloud, network, application, infrastructure, SaaS, and healthcare system risks. Core Responsibilities • Own the security remediation backlog, including enterprise security findings, IOPs, vulnerability items, audit actions, risk assessments, control gaps, exceptions, and assessment findings. • Drive remediation from intake through closure by creating clear action plans with owners, due dates, dependencies, evidence requirements, risks, and escalation paths. • Maintain a centralized remediation tracker, risk register, exception log, evidence repository, and executive status reporting for open security obligations. • Lead recurring remediation reviews with infrastructure, cloud, endpoint, application, network, data, compliance, and vendor teams to ensure progress and accountability. • Challenge unclear ownership, stalled work, weak evidence, missed deadlines, and incomplete remediation plans. • Escalate blockers and risks to IT leadership, Enterprise Security, Compliance, and business owners when remediation is delayed or requires risk acceptance. • Validate remediation evidence before closure, including screenshots, configuration exports, tickets, logs, reports, policy updates, testing results, and vendor attestations. • Translate technical findings into practical, prioritized work that operational teams can execute without unnecessary complexity. • Lead security operations activities, including alert triage, investigation, containment, escalation, recovery, and post-incident review. • Serve as incident commander or technical lead for security events affecting clinical operations, patient data, business continuity, or critical applications. • Maintain incident documentation, evidence, playbooks, tabletop exercises, and after-action tracking. • Partner with Compliance/Privacy on PHI related investigations, documentation, and reporting requirements. • Lead vulnerability lifecycle management, including intake, validation, prioritization, ticketing, remediation follow-up, SLA adherence, aging reporting, and closure evidence. • Coordinate with application, infrastructure, cloud, network, and vendor owners to remediate application, website, domain, certificate, configuration, cloud, server, endpoint, and external exposure findings. • Manage and improve security practices across identity, endpoint, email, cloud, network, server, SaaS, and application environments. • Oversee operational use of Microsoft 365 security, Entra ID, Intune, Defender, Sentinel, Azure security, EDR/XDR, SIEM, vulnerability management tools, and related logging or investigation capabilities. • Partner with infrastructure, cloud, and network teams on secure administration, segmentation, firewall standards, NAC, remote access, vendor access, and external exposure management. • Drive endpoint and workstation security improvements, including EDR coverage, encryption, patching, device compliance, configuration baselines, and exception handling. • Ensure security telemetry from endpoints, identity, email, cloud, EHR, Salesforce, and critical infrastructure is available for monitoring, investigation, and audit evidence. • Support access management governance, including onboarding/offboarding controls, periodic access reviews, privileged access, service accounts, vendor access, and remote access. • Coordinate vendor security reviews and remediation for third parties with access to PHI, patient data, or critical systems. • Document compensating controls and risk acceptance where immediate remediation is not feasible. • Support HIPAA Security Rule safeguards, PHI/PII protection, secure email, DLP, data classification, application inventory, and evidence management activities. • Partner with clinical, operations, IT, and compliance stakeholders to reduce risk to patient data and clinical operations. • Support business continuity and disaster recovery planning, including recovery procedures, system dependencies, testing evidence, and remediation of gaps. • Coordinate security work related to medical devices, telecom, specialty systems, hosted environments, and healthcare-specific technology risks. • Maintain practical security policies, standards, procedures, and evidence that can be followed by operational teams. Required Qualifications • Bachelor's degree and 8+ years of experience managing enterprise IT, cybersecurity, security operations, or security remediation programs. Additional years of relevant experience may be considered in lieu of degree. • Experience owning remediation programs where findings, vulnerabilities, audit actions, or risk items had to be driven to closure across multiple technical and business teams. • Ability to operate as an execution owner, not only a coordinator, including assigning work, challenging status, escalating blockers, validating evidence, and holding teams accountable. • Strong practical understanding of vulnerability management, security operations, incident response, identity security, endpoint protection, cloud security, logging, and control evidence. • Experience working with enterprise security, audit, compliance, or corporate security teams on remediation plans, exceptions, evidence requests, and recurring status reporting. • Experience engaging multidisciplinary technical teams across cloud, cybersecurity, infrastructure, endpoint, network, application, SaaS, and hybrid environments. • Experience managing scope, schedule, priority, risk, and dependencies for enterprise security initiatives. • Working knowledge of Microsoft 365 security, Entra ID, Intune, Defender, Sentinel, Azure security, EDR/XDR, SIEM, IAM, vulnerability management tools, and logging concepts. • Experience coordinating remediation across technical teams, vendors, business owners, and compliance stakeholders. • Ability to review findings, determine practical next steps, assign ownership, track progress, collect evidence, and escalate blockers. • Familiarity with HIPAA, PHI/PII handling, NIST CSF, CIS benchmarks, and modern identity and endpoint security practices. • Strong written and verbal communication skills, including the ability to explain technical risk and remediation status to non-technical stakeholders. • Healthcare experience or experience supporting regulated environments with sensitive data. • Relevant certifications such as PMP, CISSP, CISM, CRISC, Security+, or similar are preferred. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company’s 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. Vaco by Highspring values a diverse workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact HR@vaco.com . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries (“we,” “our,” or “Vaco by Highspring”) respects your privacy and are committed to providing transparent notice of our policies. • California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. • Virginia residents may access our state specific policies here. • Residents of all other states may access our policies here. • Canadian residents may access our policies in English here and in French here. • Residents of countries governed by GDPR may access our policies here. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: • the individual’s skill sets, experience and training; • licensure and certification requirements; • office location and other geographic considerations; • other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.

Security Operations Leadership
Incident Response
Vulnerability Management
Verified Source
Posted 2 months ago
Vaco by Highspring

Sr. Manager, Security Operations & Governance

Vaco by HighspringAnywhereContract
View Job
Compensation$146K - 166K a year

Lead and manage security remediation, operations, and governance programs ensuring closure of security findings and coordination across technical and business teams. | Requires 8+ years managing enterprise security operations and remediation programs with strong Microsoft security environment experience and healthcare or regulated environment knowledge. | Hiring a SENIOR MANAGER, SECURITY OPERATIONS & GOVERNANCE with prior experience in healthcare industry, Microsoft environment (365,InTune, Azure Security) and coordinating remediation across technical teams, vendors, business owners, and compliance stakeholders. Location: 100% remote in US Duration: 6-12 month contract Pay: $70-80/hr W2 This role will serve as the primary owner for security findings, remediation plans, vulnerability items, audit actions, risk exceptions, and enterprise security obligations. The position requires a hands-on leader who can translate security findings into practical action plans, assign ownership, track execution, validate evidence, escalate blockers, and drive closure across IT, compliance, vendors, and business stakeholders. The ideal candidate is not only able to organize and execute a security program but is also a security-minded operator who can work directly with technical teams on identity, endpoint, cloud, network, application, infrastructure, SaaS, and healthcare system risks.Core Responsibilities • Own the security remediation backlog, including enterprise security findings, IOPs, vulnerability items, audit actions, risk assessments, control gaps, exceptions, and assessment findings. • Drive remediation from intake through closure by creating clear action plans with owners, due dates, dependencies, evidence requirements, risks, and escalation paths. • Maintain a centralized remediation tracker, risk register, exception log, evidence repository, and executive status reporting for open security obligations. • Lead recurring remediation reviews with infrastructure, cloud, endpoint, application, network, data, compliance, and vendor teams to ensure progress and accountability. • Challenge unclear ownership, stalled work, weak evidence, missed deadlines, and incomplete remediation plans. • Escalate blockers and risks to IT leadership, Enterprise Security, Compliance, and business owners when remediation is delayed or requires risk acceptance. • Validate remediation evidence before closure, including screenshots, configuration exports, tickets, logs, reports, policy updates, testing results, and vendor attestations. • Translate technical findings into practical, prioritized work that operational teams can execute without unnecessary complexity. • Lead security operations activities, including alert triage, investigation, containment, escalation, recovery, and post-incident review. • Serve as incident commander or technical lead for security events affecting clinical operations, patient data, business continuity, or critical applications. • Maintain incident documentation, evidence, playbooks, tabletop exercises, and after-action tracking. • Partner with Compliance/Privacy on PHI related investigations, documentation, and reporting requirements. • Lead vulnerability lifecycle management, including intake, validation, prioritization, ticketing, remediation follow-up, SLA adherence, aging reporting, and closure evidence. • Coordinate with application, infrastructure, cloud, network, and vendor owners to remediate application, website, domain, certificate, configuration, cloud, server, endpoint, and external exposure findings. • Manage and improve security practices across identity, endpoint, email, cloud, network, server, SaaS, and application environments. • Oversee operational use of Microsoft 365 security, Entra ID, Intune, Defender, Sentinel, Azure security, EDR/XDR, SIEM, vulnerability management tools, and related logging or investigation capabilities. • Partner with infrastructure, cloud, and network teams on secure administration, segmentation, firewall standards, NAC, remote access, vendor access, and external exposure management. • Drive endpoint and workstation security improvements, including EDR coverage, encryption, patching, device compliance, configuration baselines, and exception handling. • Ensure security telemetry from endpoints, identity, email, cloud, EHR, Salesforce, and critical infrastructure is available for monitoring, investigation, and audit evidence. • Support access management governance, including onboarding/offboarding controls, periodic access reviews, privileged access, service accounts, vendor access, and remote access. • Coordinate vendor security reviews and remediation for third parties with access to PHI, patient data, or critical systems. • Document compensating controls and risk acceptance where immediate remediation is not feasible. • Support HIPAA Security Rule safeguards, PHI/PII protection, secure email, DLP, data classification, application inventory, and evidence management activities. • Partner with clinical, operations, IT, and compliance stakeholders to reduce risk to patient data and clinical operations. • Support business continuity and disaster recovery planning, including recovery procedures, system dependencies, testing evidence, and remediation of gaps. • Coordinate security work related to medical devices, telecom, specialty systems, hosted environments, and healthcare-specific technology risks. • Maintain practical security policies, standards, procedures, and evidence that can be followed by operational teams. Required Qualifications • Bachelor''s degree and 8+ years of experience managing enterprise IT, cybersecurity, security operations, or security remediation programs. Additional years of relevant experience may be considered in lieu of degree. • Experience owning remediation programs where findings, vulnerabilities, audit actions, or risk items had to be driven to closure across multiple technical and business teams. • Ability to operate as an execution owner, not only a coordinator, including assigning work, challenging status, escalating blockers, validating evidence, and holding teams accountable. • Strong practical understanding of vulnerability management, security operations, incident response, identity security, endpoint protection, cloud security, logging, and control evidence. • Experience working with enterprise security, audit, compliance, or corporate security teams on remediation plans, exceptions, evidence requests, and recurring status reporting. • Experience engaging multidisciplinary technical teams across cloud, cybersecurity, infrastructure, endpoint, network, application, SaaS, and hybrid environments. • Experience managing scope, schedule, priority, risk, and dependencies for enterprise security initiatives. • Working knowledge of Microsoft 365 security, Entra ID, Intune, Defender, Sentinel, Azure security, EDR/XDR, SIEM, IAM, vulnerability management tools, and logging concepts. • Experience coordinating remediation across technical teams, vendors, business owners, and compliance stakeholders. • Ability to review findings, determine practical next steps, assign ownership, track progress, collect evidence, and escalate blockers. • Familiarity with HIPAA, PHI/PII handling, NIST CSF, CIS benchmarks, and modern identity and endpoint security practices. • Strong written and verbal communication skills, including the ability to explain technical risk and remediation status to non-technical stakeholders. • Healthcare experience or experience supporting regulated environments with sensitive data. • Relevant certifications such as PMP, CISSP, CISM, CRISC, Security+, or similar are preferred. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company’s 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products.

Security operations leadership
Incident response
Vulnerability management
Microsoft 365 security
SOAR automation
OT/ICS security
Verified Source
Posted 2 months ago
Vaco by Highspring

Sr. Security Engineer, Cloud Infrastructure

Vaco by HighspringAnywhereContract
View Job
Compensation$90K - 130K a year

Implement and support security controls across Microsoft cloud and endpoint platforms in a regulated healthcare environment. | 6+ years cybersecurity or related experience with hands-on Microsoft security platform expertise and strong knowledge of identity, endpoint, cloud, and network security controls. | The ideal candidate is a hands-on security engineer with strong Microsoft cloud and infrastructure security experience who can configure, troubleshoot, document, and improve security controls in a regulated healthcare environment. Core Responsibilities • Implement and support security controls across Microsoft cloud services, endpoint platforms, identity systems, infrastructure, SaaS applications, and network environments. • Support vulnerability management activities, including validation, prioritization, remediation coordination, patching support, and closure documentation. • Configure and improve Microsoft security capabilities across Microsoft 365, Entra ID, Intune, Defender, Sentinel, Purview, Azure, and related security platforms. • Support endpoint security improvements, including endpoint protection, device compliance, encryption, patching, configuration baselines, and secure administration practices. • Support identity and access security controls, including MFA, Conditional Access, privileged access, service accounts, vendor access, and access review processes. • Support Azure security controls, including RBAC, policy enforcement, logging, secure networking, resource configuration, and cloud security posture improvements. • Support Microsoft Purview and data protection capabilities, including DLP, sensitivity labels, data classification, audit support, eDiscovery support, and policy tuning. • Support web security controls, including web proxy, secure web gateway, URL filtering, browser controls, internet access logging, and related policy enforcement. • Configure, validate, and improve security logging to support monitoring, investigation, reporting, and audit evidence. • Investigate security alerts and incidents, perform technical analysis, support containment and recovery actions, and document findings. • Partner with infrastructure, cloud, network, application, compliance, vendor, and business teams to implement practical security improvements. • Produce technical documentation, including implementation notes, runbooks, standards, evidence, and operational procedures. • Support security reviews and remediation activities for third-party platforms, hosted systems, applications, and infrastructure services. • Support business continuity and disaster recovery security activities, including technical validation, documentation, and remediation support. • Recommend practical security improvements that are achievable in an operational healthcare environment. Required Qualifications • Bachelor’s degree and 6+ years of experience in cybersecurity, cloud security, infrastructure security, systems engineering, network security, endpoint security, or data protection. Additional relevant experience may be considered in lieu of degree. • Hands-on experience implementing, configuring, and supporting security controls in Microsoft Azure, Microsoft 365, Entra ID, Intune, Defender, Sentinel, Purview, and related Microsoft security platforms. • Strong practical understanding of identity security, endpoint protection, cloud security, data protection, network security, server hardening, logging, vulnerability management, and incident response. • Hands-on experience with Microsoft Purview, DLP, sensitivity labels, data classification, eDiscovery support, audit logging, or related data protection controls. • Experience supporting web proxy, secure web gateway, URL filtering, CASB, browser controls, SSL inspection, or internet access security controls. • Experience working with vulnerability management tools, EDR/XDR platforms, SIEM/logging platforms, IAM tools, endpoint management platforms, DLP tools, web proxy platforms, and cloud security posture tools. • Ability to review technical findings, determine practical remediation steps, implement improvements, validate results, and produce clear evidence. • Working knowledge of Microsoft 365 security, Entra ID, Conditional Access, Intune, Defender for Endpoint, Defender for Cloud, Sentinel, Purview, Azure Policy, RBAC, and cloud logging concepts. • Practical understanding of data loss prevention, PHI/PII protection, cloud app access, file movement controls, web activity monitoring, and data protection practices. • Experience supporting endpoint security improvements, including patching, encryption, EDR coverage, device compliance, configuration baselines, application control, and local administrator controls • Experience supporting network security controls, including firewalls, segmentation, VPN, remote access, DNS, certificates, and secure administration practices. • Familiarity with HIPAA, PHI/PII handling, NIST CSF, CIS benchmarks, Microsoft security baselines, and security evidence requirements. • Ability to work with infrastructure, cloud, network, application, compliance, vendor, and business teams to complete security improvement activities. • Strong troubleshooting, documentation, and communication skills. • Healthcare experience or experience supporting regulated environments with sensitive data is preferred. • Microsoft security and cloud certifications such as AZ-500, SC-200, SC-300, SC-400, SC-100, MS-102, or MD-102 are strongly preferred. Security+, CySA+, CISSP, CCSP, CCNA Security, or similar certifications are also preferred. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company’s 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products.

Microsoft Azure Security
Endpoint Security
Identity and Access Management
Verified Source
Posted 2 months ago

Ready to join Vaco by Highspring?

Create tailored applications specifically for Vaco by Highspring with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt