All open roles

Senior Security Engineer

Engineering · Posted 20 days ago

We are looking for a Senior Security Engineer with 5+ years of experience to be the first dedicated security hire at a high-growth digital health company. You'll own the technical security of a fully remote, cloud-native healthcare platform – acting as a hands-on builder, not a policy desk. You will set security archit...

Way of working
Remote
Location
USA
Pay range
$170,000 to $200,000
Level
Senior
Experience
6+ years
Type
Full time
Visa sponsorship
Not offered for this role
The company
Hospitals and Health Care · 50 to 200 people

Skills that matter here

AWSGitHub Advanced SecurityCodeQLSASTDASTOktaOAuthOIDCSAMLAWS Secrets ManagerTerraformPythonEKS

The full description

We are looking for a Senior Security Engineer with 5+ years of experience to be the first dedicated security hire at a high-growth digital health company. You'll own the technical security of a fully remote, cloud-native healthcare platform – acting as a hands-on builder, not a policy desk. You will set security architecture standards for our product and AWS environments, harden identity and secrets management, and design the guardrails for our transition to an agentic SDLC where AI agents help plan, build, and deploy code against regulated data. This is a uniquely forward-looking role where your fingerprints will be on the foundation.

What you will be doing

- Owning application and product security – threat modeling, secure design review, and secure code review focused on authorization and access-control flaw classes for a member-facing healthcare app and its APIs

- Designing and owning the security architecture for an agentic SDLC – building phase-gate criteria, deterministic out-of-band controls for agent-written code, and lifecycle management for non-human identities

- Securing the AWS environment – IAM, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS, and Terraform

- Building and running non-human identity and secrets management at scale – service accounts, scoped tokens, OAuth grants, and machine credentials with provisioning, rotation, and least privilege

- Enforcing and tuning GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks and building automation so a small security function operates with outsized leverage

Interested in this one?

There is no apply button here on purpose. Tell us about yourself, we book a short call, and if this role fits we walk you through the company and ask before anything is sent. Always free for you.

Tell us about you
Tell us about you