Hoag logo
Cyber Security Systems Engineer - Lead: Corporate Information Security
full-timeCosta Mesa

Summary

Location

Costa Mesa

Type

full-time

Claim this Company

Are you the employer? Manage your company page directly.

Explore Jobs

About this role

The Lead Offensive Security Engineer leads the design, execution, and continuous improvement of Hoag's offensive security program. This role proactively identifies, validates, and assesses vulnerabilities by simulating advanced adversary tactics, techniques, and procedures (TTPs). Provides expert guidance and mentorship, ensuring the organization's security posture is rigorously tested against real-world threats and fully aligned with healthcare regulatory requirements.

  • Leads and conducts advanced, objective-based penetration tests and red team engagements against corporate networks, cloud environments (AWS/Azure), web applications, and mobile applications.
  • Designs and executes security assessments of critical healthcare infrastructure, including the Internet of Medical Things (IoMT), operational technology (OT), and other clinical systems, to identify vulnerabilities affecting patient care and data integrity.
  • Performs targeted social engineering (phishing, vishing, physical) simulations to test and improve human- and process-level security controls.
  • Develops and maintains a modern offensive security toolset; automates engagement tasks and TTP simulation using scripting (Python, PowerShell, etc.).
  • Partners with defensive (Blue Team) and engineering teams to conduct 'Purple Team' exercises, testing and enhancing the effectiveness of defensive controls (SIEM, EDR, CASB).
  • Develops detailed, high-quality reports with actionable remediation recommendations and presents findings to both technical and executive leadership.
  • Mentors junior engineers and provides offensive security subject matter expertise across the organization.
  • Continuously researches emerging adversary TTPs, new vulnerabilities, and exploitation techniques, integrating this intelligence into the testing methodology.
  • Provides technical validation for compliance and risk management (HIPAA, NIST, CIS), demonstrating the real-world impact of identified risks.
  • Assist with advanced incident response and forensic investigations by providing an attacker's perspective and root cause analysis.

 


Hoag Memorial Hospital Presbyterian is a nonprofit regional health care delivery network in Orange County, California, consisting of three acute-care hospitals with sixteen urgent care centers, eleven health centers and a network of more than1,800 physicians, 100 allied health members, 8,000 employees, and 2,000 volunteers. More than 30,000 inpatients and 550,000 outpatients choose Hoag each year.

For over 70 years, Hoag has delivered a level of personalized care that is unsurpassed among Orange County’s health care providers. Since 1952, Hoag has served the local communities and continues its mission to provide the highest quality health care services through the core strategies of quality and service, people, physician partnerships, strategic growth, financial stewardship, community benefit and philanthropy.

Hoag offers a comprehensive blend of health care services including six institutes providing specialized care in the areas of cancer, heart and vascular, neurosciences, women's health, orthopedics, and digestive health through our institutes.

Hoag was the highest ranked hospital in Orange County in the 2024-2025 U.S. News &World Report, the only Orange County hospital ranked in the top 10 for California. The organization was ranked the #5 hospital in the Los Angeles Metro Area and the #10 hospital in California.

To learn more about Hoag’s awards and accreditations, visit: https://www.hoag.org/about-hoag/awards-accreditations/.

Hoag is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. Hoag is committed to the principle of equal employment opportunity for all employees and providing employees with a work environment free of discrimination and harassment. Hoag hires a diverse group of people in a manner that allows them to reach their full potential in the pursuit of organizational objectives.

Other facts

Tech stack
Offensive Security,Penetration Testing,Red Team Engagements,Cloud Security,Web Application Security,Mobile Application Security,Social Engineering,Security Assessments,Vulnerability Assessment,Scripting,Python,PowerShell,Incident Response,Forensic Investigations,Compliance,Risk Management

About Hoag

Hoag is a nonprofit, regional health care delivery system in Orange County, California. Delivering world-class, comprehensive, personalized care, Hoag consists of 1,800 top physicians, 17 urgent care facilities, 12 health & wellness centers, and two award-winning hospitals. Hoag offers a comprehensive blend of health care services that includes seven institutes providing specialized services in the following areas: cancer, digestive health, heart and vascular, neurosciences, spine, women’s health, and orthopedics through Hoag’s affiliate, Hoag Orthopedic Institute, which consists of an orthopedic hospital and four ambulatory surgical centers. Hoag is the highest ranked hospital in Orange County by U.S. News & World Report and the only OC hospital ranked in the Top 10 in California, as well as a designated Magnet® hospital by the American Nurses Credentialing Center (ANCC). For more information, visit hoag.org.

Team size: 5,001-10,000 employees
LinkedIn: Visit
Industry: Hospitals and Health Care

What you'll do

  • The Lead Offensive Security Engineer leads the design and execution of Hoag's offensive security program, identifying and assessing vulnerabilities through advanced simulations. This role also involves mentoring junior engineers and developing detailed reports with actionable recommendations.

Join Clera's Talent Pool

Get matched with similar opportunities at top startups

This role is hosted on Hoag's careers site.
Join our talent pool first to get notified about similar roles that match your profile.

Frequently Asked Questions

What does a Cyber Security Systems Engineer - Lead: Corporate Information Security do at Hoag?

As a Cyber Security Systems Engineer - Lead: Corporate Information Security at Hoag, you will: the Lead Offensive Security Engineer leads the design and execution of Hoag's offensive security program, identifying and assessing vulnerabilities through advanced simulations. This role also involves mentoring junior engineers and developing detailed reports with actionable recommendations..

Why join Hoag as a Cyber Security Systems Engineer - Lead: Corporate Information Security?

Hoag is a leading Hospitals and Health Care company.

Is the Cyber Security Systems Engineer - Lead: Corporate Information Security position at Hoag remote?

The Cyber Security Systems Engineer - Lead: Corporate Information Security position at Hoag is based in Costa Mesa, California, United States. Contact the company through Clera for specific work arrangement details.

How do I apply for the Cyber Security Systems Engineer - Lead: Corporate Information Security position at Hoag?

You can apply for the Cyber Security Systems Engineer - Lead: Corporate Information Security position at Hoag directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Hoag on their website.