Remote job
Senior Security Engineer, Cloud and Infrastructure Security
Job details
About this role
Role overview A senior cloud and infrastructure security role on a healthcare-focused engineering team building patient-facing digital health products. The position partners across infrastructure, engineering, compliance, and security teams to design secure-by-default cloud architecture while pioneering AI-native security tooling and autonomous response agents.
Responsibilities - Design and implement cloud security architecture for a large AWS-based infrastructure footprint. - Improve cloud security posture management and partner with engineering, infrastructure, and compliance teams to deliver secure products. - Lead the design and deployment of AI-native security capabilities, including autonomous agents for threat detection, alert triage, vulnerability management, and incident response. - Research emerging threats and attack vectors affecting cloud and application infrastructure. - Establish defense-in-depth through secure-by-default frameworks, architectures, and processes. - Detect and respond to security incidents, participating in an on-call rotation for both critical and non-critical alerts. - Define and track KPIs that measure the health of the cloud and infrastructure security program.
Requirements - Hands-on experience with SIEM, EDR, and CSPM tools such as Wiz, CrowdStrike, or similar scanners. - Deep cloud security experience on AWS, covering IAM, service configuration, and native services including CloudTrail, Service Control Policies, AWS Organizations, and Config. - Strong Kubernetes security expertise, including network policies, service-to-service authentication and authorization, RBAC, workload identity, admission controllers, and runtime security. - Proven experience responding to complex incidents across endpoint, network, and cloud environments, including acting as an Incident Commander. - Experience with Infrastructure as Code, particularly Terraform. - Ability to reason about unfamiliar systems quickly during incident response and to think across the full lifecycle of a problem, not just the immediate technical fix.
Nice to have Experience designing and shipping AI agents in production security contexts, and a patient-centered mindset when balancing security tradeoffs against user experience.