Search Remote Jobs

Senior Security Engineer

Job not on LinkedIn

🔥 9 hours ago

🇺🇸 United States – Remote

💵 $155k - $170k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of AgelessRx

AgelessRx

11 - 50 employees

🏥 Healthcare

🍽️ Food & Beverage

⚕️ Healthcare Insurance

Healthcare • Food & Beverage • Healthcare Insurance

AgelessRx is a company that specializes in providing expert-curated sleep solutions and treatments aimed at promoting a healthier, longer life. They offer a range of treatments and health monitoring solutions designed for general longevity, energy and fatigue, weight management, heart health, cognitive function, and more. Relying on cutting-edge research and a team of US-licensed medical providers, they aim to help individuals achieve their health goals through personalized, science-backed therapies. Patients can complete simple online assessments, receive fast and free shipping, and ongoing online or phone support for their prescribed treatments. AgelessRx also emphasizes ongoing research and community involvement to make the science of longevity more accessible.

📋 Description

• Own and evolve AgelessRx's technical security roadmap • Establish and operate repeatable security programs, controls, reporting, and documentation • Conduct security and architecture reviews for systems, vendors, integrations, and technology changes • Maintain visibility into risks, vulnerabilities, remediation priorities, owners, and timelines • Conduct and support HIPAA Security Rule risk assessments • Maintain audit-ready evidence and documentation • Plan and facilitate security and incident-response exercises • Report security posture, priorities, open risks, and remediation progress to leadership • Define identity, authentication, authorization, privileged-access, cloud, endpoint, and email-security standards • Partner with IT on SSO, MFA, privileged access management, endpoint controls, access reviews, and device security • Own vulnerability management across infrastructure, endpoints, applications, and other technology • Embed security into the software development lifecycle • Review architecture, authentication flows, sensitive-data handling, payments, and security-sensitive product areas • Develop threat models for products, features, services, and integrations involving PHI or sensitive information • Deploy and improve SAST, SCA, dependency-scanning, and software-supply-chain controls • Establish application-security finding remediation processes and secure-development guidance • Coordinate penetration testing and vulnerability disclosure and triage • Partner with Engineering to identify risks before production • Support HIPAA audits, investigations, incident response, and compliance activities • Evaluate vendors and partners handling PHI or sensitive information • Serve as technical security owner for AI governance • Maintain visibility into AI systems accessing PHI or sensitive data • Assess AI tools and vendors, including data flows, retention, model training, access controls, subprocessors, and other risks • Extend threat modeling to AI-enabled products, addressing prompt injection, model access, data leakage, output handling, and PHI exposure • Translate evolving healthcare and AI requirements into technical controls • Align AI risk management with a recognized framework and maintain evidence • Review and implement approved MCPs and other AI integrations • Support policies governing employee use of AI tools

🎯 Requirements

• 5+ years of experience in security engineering, cybersecurity, or a related technical security role • Hands-on depth across at least two major security domains, such as application/product security, cloud and identity security, vulnerability management, security operations, or security governance • Experience securing environments subject to HIPAA or comparable regulatory requirements and translating regulatory obligations into technical controls • Strong working knowledge of at least one major cloud provider and associated IAM and security practices • Strong understanding of identity and access management, including SSO, SAML/OIDC, MFA, privileged access, and least-privilege principles • Experience with application-security tooling and practices, including SAST, SCA, dependency management, threat modeling, and secure software development • Experience establishing or operating recurring security programs such as vulnerability management, access reviews, penetration testing, security assessments, or incident-response exercises • Experience assessing and prioritizing vulnerabilities based on exploitability, business impact, sensitive-data exposure, and practical risk • Working understanding of AI/LLM security risks and governing AI systems in regulated environments • Strong written communication and documentation skills • Ability to operate autonomously and establish structure in an evolving environment • Preferred: direct HIPAA Security Rule risk analyses, OCR audits, healthcare security investigations, or breach response • Preferred: healthcare technology, telehealth, EHR integrations, or HL7/FHIR systems experience • Preferred: building or maturing a security program as an early or first dedicated security hire • Preferred: AI governance or AI risk-management programs, including NIST AI RMF, ISO/IEC 42001, or similar frameworks • Preferred: evaluating AI vendors or systems processing PHI or regulated data • Preferred: emerging healthcare and AI regulatory requirements • Preferred: Docker experience • Relevant security certifications such as OSCP, HCISPP, CISSP, or cloud-security certifications are valued but not required

Apply Now

Similar Jobs

🔥 10 hours ago

Xcelerate Solutions

1001 - 5000

💼 Consulting

🔒 Cybersecurity

🏢 Enterprise

Security Engineer monitoring and tuning intrusion-prevention systems for U.S. government cybersecurity programs. Analyzing IPS events, automating threat response, and supporting incident response.

🔥 11 hours ago

OnePay

501 - 1000

💳 Fintech

🏦 Banking

₿ Crypto

Security and Threat Operations Engineer protecting OnePay’s consumer fintech platform. Building detections, automating investigations, and managing vulnerability response across cloud and application environments.

🔥 12 hours ago

Halcyon

51 - 200

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Senior Information Security Specialist advancing Halcyon’s ransomware-defense cybersecurity and GRC programs. Managing third-party risk, compliance controls, security testing, and incident preparedness.

🔥 13 hours ago

MRO

1001 - 5000

🏥 Healthcare

☁️ SaaS

📋 Compliance

Information security advisor managing HITRUST and SOC 2 assurance for MRO. Driving Vanta-based audits, risk management, incident response, and compliance readiness.

🔥 13 hours ago

Optiv

1001 - 5000

Optiv cybersecurity advisor designing threat management solutions for client security programs. Driving security services sales, client strategy, and scalable defensive architectures.