Security Engineer III

🕒 vor 1 Monat

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Aspirion

Aspirion

1001 - 5000 Mitarbeiter

Gegründet 2006

⚕️ Krankenversicherung

🤖 Künstliche Intelligenz

☁️ SaaS

💰 Series unknown im 2012-02

Healthcare Insurance • Artificial Intelligence • SaaS

Aspirion ist ein Unternehmen für das Management des Gesundheitskostenzyklus, das Krankenhäusern hilft, Einnahmen aus abgelehnten und komplexen Forderungen zurückzugewinnen. Das Unternehmen setzt KI-Automatisierung und eine proprietäre Compass-Plattform ein, besetzt mit in den USA ansässigen Anwälten, Klinikern und KI-Ingenieuren, um klinische Ablehnungen zu überwinden, die Erstattung von außerhalb des Netzwerks zu maximieren, Null-Saldo-Bewertungen durchzuführen und Zahlungsabweichungen über Dienstleistungen wie Ablehnungsmanagement, AR-Management, komplexe Forderungen, Kraftfahrzeugunfälle, Arbeitnehmerentschädigung, TRICARE und Medicaid außerhalb des Staates zu beheben. Aspirion betont messbare Wiederherstellungseffekte (über 6 Milliarden Dollar erfasst), erhöhte Sammlungen für Kunden, HITRUST-Zertifizierung, Best in KLAS-Auszeichnungen und Partnerschaften mit großen Gesundheitssystemen.

Beschreibung

• Own cloud security engineering for AWS by defining guardrails and configuration baselines (e.g., IAM least privilege, network segmentation, encryption, logging), partnering on implementation, and driving remediation of cloud posture findings to closure. • Engineer security controls and governance for Kubernetes and containerized workloads (e.g., EKS): define and enforce admission policies, Pod Security standards, network policies, image governance, runtime protections, and secrets management patterns; partner with platform teams on implementation within clusters and supporting IAM. • Drive secure SDLC controls and engineering governance: integrate and operate scanning and policy gates for application code (SAST), dependencies (SCA), secrets, containers/images, and Infrastructure as Code (IaC); define practical remediation SLAs and exception/waiver workflows aligned to risk. • Define security policies, standards, and best practices for cloud and containerized environments, and translate them into implementable guardrails and reference patterns (policy-as-code, reference configurations, and developer guidance), including encryption/key management (e.g., KMS), secrets storage, and secure workload access patterns; validate adoption and baseline compliance in partnership with Infrastructure/Platform teams. • Partner with Compliance to align technical controls to HIPAA requirements and produce audit-ready evidence (configurations, screenshots/exports, control narratives, and remediation tracking) for cloud and container platforms. • Improve security visibility and detection in AWS and Kubernetes: define requirements, ensure high-quality logging, and create actionable detections/alerts in partnership with the SOC/SIEM owners. • Run vulnerability management across the stack for cloud and containerized applications: triage and prioritize findings for application code, Infrastructure as Code, container images, third-party dependencies, and OS packages; coordinate fixes with engineering/platform teams, validate remediation, and track risk-based exceptions. • Support incident response for cloud and container security events: perform technical triage, containment support, root cause analysis, and deliver preventative engineering changes. • Develop and maintain security-as-code standards and reusable guardrails (e.g., Terraform modules/policies) and automated checks/policy gates to enforce baseline compliance across AWS accounts and Kubernetes clusters; partner with Infrastructure/Platform teams to roll out and operationalize these controls at scale. • Independently manage security engineering deliverables from intake through delivery: clarify requirements, design solutions, document decisions/runbooks, and communicate status/risks to stakeholders. • Translate HITRUST MyCSF/HIPAA and internal security policies into measurable cloud and SDLC control requirements; validate control effectiveness through testing and evidence collection. • Contribute to security tool administration and continuous improvement (e.g., cloud posture management, vulnerability scanning, CI/CD scanning tools) by tuning rules, reducing false positives, and improving developer usability. • Participate in on-call/escalation processes as needed; maintain runbooks and support post-incident reviews and corrective actions. • Serve as a technical resource for peers through code/config reviews, pairing, and clear documentation; help raise the security bar through pragmatic standards and guidance. • Perform other duties as assigned.

🎯 Anforderungen

• 5+ years in security engineering, cloud infrastructure, DevOps, or related technical roles, with significant hands-on responsibility securing production AWS environments. • Demonstrated experience implementing and improving cloud security posture (guardrails, standards, continuous compliance, vulnerability management) with measurable remediation outcomes. • Strong AWS IAM skills (roles/policies, least privilege design, identity federation, service roles) and experience implementing secure access patterns for humans and workloads. • Hands-on Kubernetes/container security experience, including implementing secure cluster/workload configuration and image governance in a production containerized environment. • Experience implementing and evidencing security controls in regulated environments (HIPAA required), including encryption/key management, logging retention, and change/audit trails. • Experience supporting incident response for cloud/workload security events, including investigation support, containment actions, and post-incident remediation. • Automation and IaC experience (e.g., Python/Bash; Terraform) and familiarity with implementing policy-as-code and continuous compliance checks. • Experience assessing and improving security for application code and IaC (e.g., Terraform/CloudFormation/Kubernetes manifests), including code review support, scanning, and remediation guidance. • Experience managing container security vulnerabilities end-to-end, including image scanning, base image/OS package patching strategies, rebuild processes, and validation of remediations in deployment pipelines. • Demonstrated experience implementing secure SDLC controls in CI/CD (e.g., GitHub Actions/Jenkins/GitLab), including SAST/SCA, container image scanning, secrets scanning, pipeline gates, and actionable remediation workflows. • Experience operating in regulated environments (HIPAA required); familiarity with NIST and/or HITRUST is strongly preferred. • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field preferred (or equivalent practical experience). • Security and cloud certifications preferred: AWS Certified Security – Specialty or AWS Solutions Architect, Certified Kubernetes Security Specialist (CKS) or equivalent, and/or CISSP/CCSP (or ability to obtain within an agreed timeframe).

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 1 Monat

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

Senior Technical Account Manager responsible for API Security solutions at Akamai. Engaging with large enterprise customers to ensure effective implementations and drive impactful results.

🇺🇸 Vereinigte Staaten – Remote

💵 $112.500 - $202.500 / Jahr

💰 Post-IPO Equity im 2001-07

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

CTI

501 - 1000

🏢 Unternehmen

📱 Medien

📡 Telekommunikation

Cyber Security Instructor teaching online courses via Microsoft Teams for CIAT. Responsible for student engagement and curriculum development while supporting diverse student needs.

🇺🇸 Vereinigte Staaten – Remote

💵 $75.000 - $80.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

CTI

501 - 1000

🏢 Unternehmen

📱 Medien

📡 Telekommunikation

Cyber Security Instructor teaching synchronous online courses at CIAT. Preparing students for professional success in technology fields and providing curriculum development support.

🇺🇸 Vereinigte Staaten – Remote

💵 $75.000 - $80.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

CTI

501 - 1000

🏢 Unternehmen

📱 Medien

📡 Telekommunikation

Cyber Security Instructor teaching synchronous online courses via Microsoft Teams. Empowering students through practical training at California Institute of Applied Technology.

🇺🇸 Vereinigte Staaten – Remote

💵 $75.000 - $80.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 1 Monat

CTI

501 - 1000

🏢 Unternehmen

📱 Medien

📡 Telekommunikation

Cyber Security Instructor teaching synchronous online courses at CIAT. Focusing on student engagement and curriculum development for practical technology training.

🇺🇸 Vereinigte Staaten – Remote

💵 $75.000 - $80.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich