Search Remote Jobs

Staff Cloud Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

đź’µ $151k - $178.5k / year

⏰ Full Time

đź”´ Lead

👮‍♂️ Cybersecurity / Security Engineer

đź‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of AnswersNow

AnswersNow

11 - 50 employees

🏥 Healthcare

đź’Ľ Consulting

⚕️ Healthcare Insurance

đź’° $11M Series A on 2023-02

Healthcare • Consulting • Healthcare Insurance

AnswersNow is a company dedicated to providing virtual autism support for families everywhere. They offer ABA therapy on an engaging virtual platform, aiming to make support accessible without a waitlist, and they work with all major insurance carriers including Medicaid. The company tailors their evidence-based care to address the specific needs and priorities of each family. Their team includes board-certified behavior analysts (BCBAs) with extensive training, who provide one-on-one expert support through their proprietary digital platform, allowing for therapy sessions to be conducted in a family-friendly environment. AnswersNow's mission is to empower families with flexible, quality care and to make the world more inclusive for individuals with autism.

đź“‹ Description

• Architect, secure, and continuously harden the AWS environment, including IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub, Config, and WAF • Secure serverless and data layers including Lambda, S3, and PostgreSQL/RDS/Aurora through encryption, least-privilege access, network isolation, backup integrity, and audit logging • Implement Infrastructure-as-Code security guardrails and policy-as-code • Own secrets management, key management, and certificate lifecycle • Manage and harden Amazon EKS infrastructure, including cluster security, network policies, and container runtime security • Secure APIs and application stack, including authentication/authorization, session management, rate limiting, input validation, and OWASP Top 10/API Top 10 risks • Embed security into the SDLC through threat modeling, secure design reviews, SAST/DAST, dependency and container scanning, and CI/CD pipeline security • Secure the proprietary real-time video platform, including WebRTC/media transport, session access controls, recording storage, and encryption • Run vulnerability management and penetration testing, including vendor selection, scoping, and remediation tracking • Establish company-wide AI usage policies and governance frameworks • Architect and secure in-product AI/ML capabilities against OWASP LLM Top 10 vulnerabilities • Implement privacy guardrails for PHI/PII in model training, fine-tuning, and prompt contexts • Define model security controls and secure artifacts, endpoints, dependencies, and access controls • Build monitoring, telemetry, and audit logging across AI/ML workflows • Own SOC 2 Type I and Type II readiness, control design, evidence collection, auditor management, and ongoing compliance • Own HIPAA Security Rule compliance, including risk assessments, policies, BAAs, breach notification procedures, and audit readiness • Tune Vanta integrations, automate evidence collection, and drive remediation • Maintain security policies, risk register, and vendor risk management program • Support customer and payer security questionnaires and due diligence • Manage endpoint security with outsourced IT, including MDM, disk encryption, EDR, patching, hardening baselines, and device compliance • Own identity and access management, including SSO, MFA, RBAC, joiner/mover/leaver processes, and periodic access reviews • Run security awareness and HIPAA training programs with People Ops • Build logging, monitoring, alerting, and SIEM capabilities • Develop and test the incident response plan, run tabletop exercises, and lead incident response • Partner with engineering on disaster recovery, backup, and business continuity planning • Define the security roadmap and communicate risk to the CTO and executive team • Mentor engineers and build a security-conscious culture, including a security champions model • Build the business case for tools, vendors, and future security headcount

🎯 Requirements

• 8+ years in security engineering, with significant hands-on experience securing production cloud environments, ideally AWS-heavy • Deep AWS security expertise (IAM, networking, encryption/KMS, logging and detection services, serverless security) • Experience securing PostgreSQL and other data stores containing regulated or sensitive data • Strong application and API security background, with ability to review code and architecture and work effectively with developers • Direct experience owning or leading a SOC 2 audit (Type I and/or Type II) and HIPAA compliance, ideally in healthcare or health-tech handling PHI • Experience with Infrastructure-as-Code (Pulumi, CloudFormation, or CDK) and CI/CD security • Experience with AI security, LLM application security, and OWASP LLM Top 10 vulnerabilities • Strong incident response experience • Excellent communication with engineers, executives, auditors, and customers • Experience with compliance automation platforms such as Vanta, Drata, or Secureframe (nice to have) • Experience securing real-time communication or video platforms (WebRTC) (nice to have) • Familiarity with HITRUST, ISO 27001, or NIST frameworks (nice to have) • Experience at a startup or scale-up where you built a security program from scratch (nice to have) • Relevant certifications such as AWS Security Specialty, CISSP, CCSP, OSCP, or similar (nice to have) • Experience with pediatric or behavioral health data and privacy considerations for minors' information (nice to have) • Legally authorized to work in the United States

🏖️ Benefits

• Equity options in a high-growth, venture-backed company • Comprehensive medical, dental, and vision • Generous PTO • Remote-first flexibility

Apply Now

Similar Jobs

🔥 3 hours ago

CDW

10,000+ employees

đź’Ľ Consulting

🏥 Healthcare

📚 Education

Principal AI Security Engineer securing CDW’s enterprise AI systems, identities, and infrastructure. Defining assessments, guardrails, architecture, and detections for a technology solutions provider.

🔥 3 hours ago

Cotiviti

5001 - 10000

🏥 Healthcare

đź’Ľ Consulting

📦 Logistics

AI Security Architect designing secure frameworks for Cotiviti’s AI systems. Leading threat modeling, testing, compliance, and data protection across the AI lifecycle.

🔥 18 hours ago

GuidePoint Security

201 - 500

đź’Ľ Consulting

🏥 Healthcare

📦 Logistics

Security Architect designing and securing Active Directory and Entra ID environments. GuidePoint Security delivers cybersecurity expertise, solutions, and services to organizations and government agencies.

🔥 22 hours ago

Eli Lilly and Company

10,000+ employees

đź’Š Pharmaceuticals

🏥 Healthcare

🧬 Biotechnology

Enterprise AI Security Advisor securing agents, models, and AI infrastructure for Lilly’s global pharmaceutical business. Setting enterprise controls, testing standards, and security strategy.

🇺🇸 United States – Remote

đź’µ $129k - $231k / year

đź’° $6.5M Post-IPO Debt - Eli Lilly on 2024-02

⏰ Full Time

đźź  Senior

đź”´ Lead

👮‍♂️ Cybersecurity / Security Engineer

đź•’ Yesterday

OpenLoop

201 - 500

đź’Ľ Consulting

⚖️ Legal

📦 Logistics

Staff Security Engineer securing OpenLoop’s telehealth infrastructure across all 50 states. Engineering endpoint, email, compliance, and automation controls protecting patient health information.