高级助理支持工程师
Senior Associate Support Engineer
Parachute Health 正在通过作为医疗设备和用品的领先数字订购平台,重塑后急性护理。我们连接主要的医疗系统、健康计划和供应商,帮助患者在家获得救命的产品。自推出以来,我们已连接了 300,000+ 临床医生和 3,000+ 供应商地点,覆盖所有 50 个州,并帮助了 15M+ 患者。最初作为 DME 电子处方工具,现已发展为家庭医疗设备的首选订单管理平台。
加入我们的团队,为患者护理带来改变。
**职位简介**
你将加入 Parachute Health 的 IT 与安全团队,与工程师和分析师一起确保我们的医疗技术环境安全、合规且运营高效。你将在一个受 SOC 1、SOC 2 和 HITRUST CSF 管理的环境中,获得身份、端点、网络和云安全、合规以及事件响应的实际操作经验。
你不会只是坐在办公桌前。你将身处快节奏的环境中,与 IT 和安全专业人员紧密合作,参与实际项目,并参与事件响应和架构讨论。
**职责**
IT 运维与端点
- 支持日常 IT 运维:用户入职/离职、硬件配置、工单故障排除和终端用户支持。
- 协助管理我们的 macOS 笔记本电脑群,包括 MDM 注册、配置、软件部署和合规基线。
- 排查 Mac、Linux 和 Windows 环境中的连接性、硬件、软件和认证问题。
- 记录解决方案、操作手册和常见问题解答,以帮助团队扩展能力。
身份与访问
- 协助 Okta 管理,用户生命周期、组管理、SSO/MFA 配置、应用分配和访问审查。
- 协助定期访问审查并收集审计证据。
网络与安全工具
- 支持 ZScaler 运维,策略审查、绕过请求、日志分析和用户故障排除。
- 协助维护 DLP 策略并处理潜在数据外泄的警报。
- 协助 WAF 规则审查、误报调优和流量分析(AWS WAFv2 / Akamai)。
- 在 Splunk/Wazuh 中支持 SIEM 运维,包括查询日志、构建仪表板和调整警报。
脚本与自动化
- 编写和维护脚本,以自动化重复的 IT/安全任务 - 日志分析、证据收集、工单增强、账户清理和报告。
- 构建小型工具以提升团队效率(无需全栈开发)
查看英文原文
Parachute Health is transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get the life-saving products they need at home. Since launching, we've connected 300,000+ clinicians and 3,000+ supplier locations across all 50 states and helped 15M+ patients. What started as a DME ePrescribing tool has become the order management platform of choice for home medical equipment.
Join our team and make a difference in patient care.
**About the Role**
You'll join Parachute Health's IT & Security team, working alongside engineers and analysts who keep our healthcare technology environment secure, compliant, and operationally efficient. You'll gain hands-on exposure to identity, endpoint, network, and cloud security, compliance, and incident response in an environment governed by SOC 1, SOC 2, and HITRUST CSF.
You won't just sit behind a desk. You'll be a part of a fast-paced environment, work closely with IT and Security professionals on real projects and sit in on incident response and architecture discussions
**Responsibilities**
IT operations & endpoint
- Support day-to-day IT operations: user onboarding/off-boarding, hardware provisioning, troubleshooting tickets, and end-user support.
- Help manage our macOS laptop fleet, MDM enrollment, configuration, software deployment, and compliance baselines.
- Troubleshoot connectivity, hardware, software, and authentication issues across Mac, Linux, and Windows environments.
- Document fixes, runbooks, and FAQs to help the team scale.
Identity & access
- Assist with Okta administration, user lifecycle, group management, SSO/MFA configuration, application assignments, and access reviews.
- Help run periodic access reviews and collect audit evidence.
Network & security tooling
- Support ZScaler operations, policy review, bypass requests, log analysis, and user troubleshooting.
- Help maintain DLP policies and triage alerts for potential data exfiltration.
- Assist with WAF rule review, false-positive tuning, and traffic analysis (AWS WAFv2 / Akamai).
- Support SIEM operations in Splunk/Wazuh by querying logs, building dashboards, and tuning alerts.
Scripting & automation
- Write and maintain scripts to automate repetitive IT/Security tasks - log analysis, evidence collection, ticket enrichment, account hygiene, and reporting.
- Build small tools that make the team faster (no full-stack development required).
- Contribute to and use AI/agentic workflows the team has built (MCP servers, Claude-based runbooks) to accelerate investigations.
**Requirements**
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, IT Management, or a related field.
- Scripting in Python or Bash is required **.** You can independently write, read, and debug working scripts to automate IT/Security tasks — parsing logs, calling APIs, generating reports, cleaning up accounts.
- Working knowledge of the Linux command line: file system navigation, permissions, process management, and log inspection (grep, awk, sed, tail, journalctl).
- Comfort with macOS as a daily-driver OS and ability to troubleshoot common Mac issues.
- Solid IT troubleshooting fundamentals across hardware, software, and OS (Mac, Windows, Linux).
- Networking fundamentals: DNS, DHCP, VPN, TLS, and the ability to diagnose connectivity issues methodically.
- Understanding of authentication and identity concepts: SSO, SAML, OAuth/OIDC, MFA, and user lifecycle/group management in an IdP (Okta or equivalent).
- Working proficiency with Git, GitHub, and the terminal — you can clone a repo, branch, commit, and open a PR.
- Ability to read and interpret logs to answer a question or trace an issue (system logs, application logs, or SIEM output).
- Actively follows trends in IT, cybersecurity, and AI, with a strong desire to experiment with new tools.
- Strong written communication; you can document what you did so others can use it.
- Must reside in the U.S.
**Nice to have**
- Hands-on exposure to any of: Okta, ZScaler, Jamf/Kandji/Intune, CrowdStrike/SentinelOne, Splunk, Wazuh, AWS, GCP - academic labs, home labs, and personal projects all count.
- Familiarity with DLP concepts (data classification, exfiltration channels, false positives).
- Familiarity with WAF concepts (OWASP Top 10, rule tuning, rate limiting).
- Experience with SIEM querying (Splunk SPL, Wazuh rules, Sigma) or log analysis.
- Exposure to compliance frameworks (SOC 2, HIPAA, NIST CSF, ISO 27001).
- Experience with LLMs, agents, MCP servers, or prompt engineering through projects, hackathons, or coursework.
- SQL skills for querying data (Postgres, Redshift, BigQuery).
- Participation in CTFs, TryHackMe, HackTheBox, or similar.
- A public GitHub portfolio with scripts, automations, or write-ups.
- Interest in healthcare technology or working in a regulated environment.
**Benefits**
- Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
- Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
- 401(k) Retirement Plan
- Equity Incentive Plan
- Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
- Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
- Flexible Vacation Policy
- Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).
- Home Office and Wellness Stipend
- Monthly Internet Stipend
- Annual Learning and Development Stipend
**Base Salary Band (based on experience and level)**
$60,000 - $105,000
_California job applicants may access the Notice of Collection of Personal Information and Privacy Policy with information and rights required by the California Privacy Rights Act (CPRA) the link [here](https://www.parachutehealth.com/cpra)._
_We are proud to be an equal opportunity employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth related medical conditions and lactation), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, disability, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances._
**_This role is not eligible for employer visa sponsorship. Applicants must be legally authorized to work in the United States at the time of application and for the duration of employment. The Company does not sponsor employment authorization for this position._**