Remote job
Senior Security Engineer
Job details
About this role
Role overview
A Senior Security Engineer role on a small, senior security team responsible for hardening a cloud-native healthcare data interoperability platform. The position is a hands-on individual contributor role that partners deeply with Engineering to embed security across the SDLC, with emphasis on Kubernetes, containers, infrastructure-as-code, and translating compliance frameworks into pragmatic controls.
Responsibilities
- Own cloud security posture management, including Kubernetes and container security practices such as admission control, network policies, image integrity, and environment hardening. - Drive the full vulnerability management lifecycle, prioritizing remediation based on actual production exposure. - Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, with attention to artifact validity and pipeline integrity. - Translate HITRUST and SOC 2 requirements into actionable technical configurations and operational controls. - Evaluate and harden infrastructure-as-code across all environments. - Execute incident response duties including forensic investigation and blameless post-mortems. - Contribute to security standards through design reviews, collaborative pairing, and mentorship. - Support bug bounty triage and maintain professional engagement with external researchers.
Requirements
- At least five years of security engineering experience with a track record of hands-on delivery and peer mentorship. - Strong technical proficiency in Kubernetes security, including network policy orchestration, admission control with Kyverno, and container hardening. - Experience threat modeling applications built in Node.js, TypeScript, Python, or Go. - Hands-on experience supporting secure SDLC and CI/CD safeguards using GitHub Actions. - Direct experience hardening Terraform infrastructure-as-code and managing enterprise secrets in AWS Secrets Manager, Vault, or similar platforms. - Solid experience across the full vulnerability management lifecycle, from triage through production remediation. - Ability to apply HITRUST and SOC 2 controls in pragmatic, engineering-friendly ways. - Strong written communication skills and comfort operating in a remote, asynchronous culture. - Proficiency with AI tools and prompt engineering, with experience automating workflows across multiple large language model platforms.
Benefits and work setup
- Fully remote within the continental United States. - Unlimited flexible time off, fifteen or more observed holidays, and guaranteed three-day weekends each month. - Six-week paid sabbatical with stipend, sixteen weeks of paid parental leave, and a productivity and wellness fund. - 401(k) match, medical, dental, and vision benefits from day one, plus HSA, FSA, life, disability, and mental health support. - Company-issued MacBook, stock options, and an employee referral bonus program.