Logo for Lyric  - Clarity in motion.

Staff Security Engineer

Role overview

Qualifications

  • Minimum of seven (7) years of experience in hands-on security engineering and/or security operations
  • Minimum of three (3) years of experience engineering and operating security controls within Amazon Web Services (AWS) and Microsoft (MS) Azure
  • Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience
  • CISSP, CCSP, GIAC (e.g., GSEC, GCIH, GCIA), or other relevant security-related designation(s)

Responsibilities

  • Design, build, deploy, and operate security controls and tooling across AWS, Azure, corporate networks, and endpoints
  • Engineer, tune, and maintain SIEM content – log onboarding, parsing, correlation rules, and detections
  • Administer and optimize the endpoint detection and response (EDR) platform
  • Partner with Security Architecture to translate reference architectures and design principles into implemented, measurable technical controls

About the company

Lyric  - Clarity in motion. logo

Lyric - Clarity in motion.

Digital Health & Health Tech

Welcome. Let us help bring your health plan's payment accuracy programs into the next era. Learn more by visiting Lyric.AI Welcome to Lyric. Building on the legacy of ClaimsXten, we bring over 35 years of expertise to deliver unmatched value to our clients, including 9 of the top 10 health payers nationwide. Our cutting-edge solutions streamline complex claims processes, ensuring precision and efficiency for over 185 million lives under our care. We've earned to the 2025 Best in KLAS award for our partnership excellence and value, we lead with top customer satisfaction scores and recommendation rates. Apart from our market-leading pre-pay claim editing services, Lyric is at the forefront of integrating advanced technologies to drive greater savings and administrative cost savings through the payment integrity value chain. This includes strategic partnerships with leaders in the areas of genetic testing claims accuracy, coordination of benefits, and more. Whether you are a current valued customer or new to Lyric, we are investing in helping health plans simplify the business of care. Visit us at Lyric.AI

Company details

IndustryDigital Health & Health Tech
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Lyric is an AI-first, platform-based healthcare technology company, committed to simplifying the business of care by preventing inaccurate payments and reducing overall waste in the healthcare ecosystem, enabling more efficient use of resources to reduce the cost of care for payers, providers, and patients. Lyric, formerly ClaimsXten, is a market leader with 35 years of pre-pay editing expertise, dedicated teams, and top technology. Lyric is proud to be recognized as 2025 Best in KLAS for Pre-Payment Accuracy and Integrity and is HI-TRUST and SOC2 certified, and a recipient of the 2025 CandE Award for Candidate Experience. Interested in shaping the future of healthcare with AI? Explore opportunities at lyric.ai/careers and drive innovation with #YouToThePowerOfAI.

Applicants must already be legally authorized to work in the U.S.  Visa sponsorship/sponsorship assumption and other immigration support are not available for this position.

The Staff Security Engineer will design, implement, and operate the security technologies that protect Lyric’s intellectual property and customer data across cloud ecosystems (Azure and AWS), corporate infrastructure, and endpoints. This role spans identity and access management (IAM), endpoint detection and response (EDR), security information and event management (SIEM), data loss prevention (DLP), network security, and vulnerability management. The position partners with technology and business teams to deliver secure, scalable solutions aligned with Lyric’s security roadmap.

ESSENTIAL JOB RESPONSIBILITIES

  • Design, build, deploy, and operate security controls and tooling across AWS, Azure, corporate networks, and endpoints
  • Engineer, tune, and maintain SIEM content – log onboarding, parsing, correlation rules, and detections – and develop automation and orchestration (SOAR) playbooks to reduce response times
  • Administer and optimize the endpoint detection and response (EDR) platform, including sensor deployment, policy tuning, threat hunting support, and endpoint hardening
  • Engineer and maintain identity and access management capabilities, including single sign-on (SSO), multi-factor authentication (MFA), conditional access, privileged identity/access management (PIM/PAM), and role lifecycle automation
  • Partner with Security Architecture to translate reference architectures and design principles into implemented, measurable technical controls, providing feedback that improves future designs
  • Serve as a technical lead during security incidents – building and maintaining containment tooling, forensics readiness, and response runbooks, and participating in post-incident reviews
  • Operate the vulnerability management lifecycle: scanning, risk-based prioritization, and partnering with application and infrastructure teams to drive remediation to closure
  • Implement and enforce baseline security configuration standards (e.g., CIS benchmarks, OS hardening, network segmentation, web application firewall) through infrastructure-as-code and policy-as-code where possible
  • Evaluate, proof-of-concept, and recommend security technologies, tools, and services to the broader security team based on security policy, threat drivers, and operational fit
  • Mentor junior engineers, maintain high-quality documentation and runbooks, and participate in an on-call rotation for security escalations

REQUIRED QUALIFICATIONS

  • Minimum of seven (7) years of experience in hands-on security engineering and/or security operations
  • Minimum of three (3) years of experience engineering and operating security controls within Amazon Web Services (AWS) and Microsoft (MS) Azure

PREFERRED QUALIFICATIONS

  • Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience
  • CISSP, CCSP, GIAC (e.g., GSEC, GCIH, GCIA), or other relevant security-related designation(s)
  • AWS Security Specialty Certification, Azure Security Engineer Certification
  • Experience engineering identity platforms such as Microsoft Entra ID, including conditional access, privileged identity management (PIM), and identity governance
  • Experience administering endpoint detection and response (EDR) platforms (e.g., CrowdStrike Falcon) and engineering SIEM detections, including detection-as-code practices
  • Proficiency with scripting and automation – Python, PowerShell, and infrastructure-as-code tooling such as Terraform – to deliver security capabilities at scale
  • Experience in DevSecOps, container and Kubernetes security, CI/CD pipeline security, and securing SaaS, IaaS, and PaaS workloads
  • Experience with network security technologies, including WAF/CDN/DDoS services, intrusion detection/prevention systems (IDS/IPS), network segmentation, and zero trust access patterns
  • Working knowledge of security frameworks and standards such as the NIST Cybersecurity Framework, HITRUST, CIS benchmarks, and the MITRE ATT&CK framework
  • Experience with data protection, including data loss prevention (DLP), cryptography, key management, and public key infrastructure (PKI)
  • Experience operating security tooling in healthcare or other regulated environments subject to HIPAA or similar data protection requirements


***The US base salary range for this full-time position is:

$125,241.00 - $187,862.00

The specific salary offered to a candidate may be influenced by a variety of factors including but not limited to the candidate’s relevant experience, education, and work location. Please note that the compensation details listed in US role postings reflect the base salary only, and does not reflect the value of the total rewards compensation. ***

Lyric is an Equal Opportunity Employer that strives to create an inclusive environment, empower employees and embrace collaborative success.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Lyric - Clarity in motion.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.