Remote job
Cyber Engineer
Job details
About this role
Role overview Secure web applications, APIs, and databases that handle HIPAA-protected patient data. The role spans threat modeling, security monitoring, and incident response, building protective controls into every layer of a healthcare-adjacent platform.
Responsibilities - Conduct threat modeling and security assessments for new features and systems. - Implement and maintain security controls supporting HIPAA compliance and data protection. - Monitor systems for vulnerabilities, anomalies, and potential incidents. - Build and maintain security tooling for authentication, authorization, and audit logging. - Respond to security incidents and lead post-incident analysis to harden the platform.
Requirements - 4+ years of experience in cybersecurity, application security, or DevSecOps. - Strong understanding of web application security, including the OWASP Top 10. - Experience with HIPAA, SOC 2, or other compliance frameworks. - Proficiency with security tools such as SIEM platforms and vulnerability scanners. - Ability to communicate security risks clearly to both technical and non-technical audiences.
Nice to have - Experience securing Next.js, Node.js, or React applications. - Background in healthcare or other regulated industries. - Familiarity with cloud security on AWS, GCP, or Azure. - Experience with penetration testing or red team operations.