Remote job
Staff Cloud Security Engineer
Job details
About this role
Role overview A venture-backed digital health organization delivering virtual therapy services to families is hiring its first dedicated security engineer to own and build the security program across cloud infrastructure, applications, AI features, and the corporate environment. The Staff-level engineer will partner directly with engineering and executive leadership, setting strategy while performing the hands-on work that raises security maturity across the platform. Scope spans AWS, Kubernetes, application and API security, AI/ML safeguards, and regulatory compliance in a healthcare context handling regulated data.
Responsibilities - Architect and harden AWS environments spanning IAM, VPC design, KMS, CloudTrail, GuardDuty, Security Hub, Config, WAF, and EKS, with encryption, least-privilege access, network isolation, and audit logging across Lambda, S3, and PostgreSQL (RDS/Aurora) - Embed security into the SDLC through threat modeling, secure design reviews, SAST/DAST, dependency and container scanning, and CI/CD pipeline hardening, plus own Infrastructure-as-Code guardrails and policy-as-code - Secure APIs and a proprietary real-time video/WebRTC platform, covering authentication, authorization, session management, rate limiting, input validation, recording storage encryption, and OWASP Top 10/API Top 10 risks - Establish enterprise AI usage policies and governance, architect protections against OWASP LLM Top 10 threats, and enforce privacy guardrails preventing regulated data exposure in training, fine-tuning, and prompt contexts - Own SOC 2 Type I and Type II readiness, ongoing HIPAA Security Rule compliance, evidence collection automation, the risk register, vendor risk management, and customer/payer security questionnaires - Run detection and response, endpoint and identity hardening (SSO, MFA, RBAC, MDM, EDR), security awareness training, disaster recovery planning, and mentor engineers through a security champions model
Requirements - 8+ years in security engineering with hands-on production cloud hardening, ideally AWS-heavy - Deep AWS security expertise across IAM, networking, KMS, logging/detection services, and serverless security - Experience securing PostgreSQL and other data stores holding regulated or sensitive data, with strong application and API security depth and code review ability - Direct ownership of SOC 2 audits (Type I and/or Type II) and HIPAA compliance, ideally in a healthcare or health-tech environment handling protected health information - Infrastructure-as-Code experience (Pulumi, CloudFormation, or CDK) and CI/CD pipeline security, plus AI security and LLM application security knowledge - Strong incident response experience and the communication skills to explain risk to engineers, executives, auditors, and customers
Nice to have - Compliance automation platforms such as Vanta, Drata, or Secureframe - Real-time communication or WebRTC platform security experience - Familiarity with HITRUST, ISO 27001, or NIST frameworks - Startup or scale-up experience building a security program from scratch - Relevant certifications such as AWS Security Specialty, CISSP, CCSP, or OSCP - Experience with pediatric or behavioral health data and minors' privacy considerations
Benefits and work setup - Annual salary range of $151,000–$178,500 plus equity options in a venture-backed company - Comprehensive medical, dental, and vision coverage - Generous PTO and remote-first flexibility, with a US-based remote location