Search Remote Jobs

Senior Staff Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OpenLoop

OpenLoop

201 - 500 employees

Founded 2020

💼 Consulting

⚖️ Legal

📦 Logistics

💰 $15M Series A - OpenLoop Health on 2023-03

Consulting • Legal • Logistics

OpenLoop is a white-label telehealth platform and managed services provider that helps organizations launch and scale virtual care programs. It combines SaaS-based, brandable technology (scheduling, booking, payments, EHR/API integrations) with clinical staffing, credentialing, payer coverage and RCM, regulatory/legal support, and 24/7 patient support. OpenLoop serves health plans, hospitals and health systems, retailers, employers and digital health companies with AI-powered operations, a nationwide clinician network and broad insurance coverage including Medicare and Medicaid.

📋 Description

• Own and continuously evolve OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems. • Lead threat modeling across product, engineering, and infrastructure initiatives, with attention to PHI data flows, patient-facing interfaces, and virtual care delivery systems. • Coach engineers to threat model their own work. • Conduct architecture reviews for new and existing systems and produce actionable recommendations. • Design and improve the architecture review process, including self-service patterns, risk-tiered review paths, and criteria for full review. • Partner with the CTO and enterprise architecture function to embed security review within technical governance. • Define and champion application security standards, API security, authentication and authorization patterns, and data protection controls. • Establish and maintain a zero trust architecture strategy across identity, network, endpoint, and data layers. • Architect and govern key management, secrets management, and certificate lifecycle practices. • Own the security architecture for third-party integrations and control supply chain risk at the design stage. • Serve as the primary security partner for product and engineering leaders. • Maintain security architecture documentation, including ADRs, reference designs, and control frameworks. • Translate security and compliance requirements into concrete architectural controls, especially HIPAA Security Rule technical safeguards for PHI architecture. • Partner with the CISO and security leadership on the long-term architecture roadmap, metrics, and executive-ready reporting. • Mentor and elevate the broader security team. • Research emerging threats and attack techniques targeting healthcare.

🎯 Requirements

• Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience. • 10+ years of progressive security experience, including at least 5 years focused on security architecture across enterprise and cloud environments. • Deep expertise across application security, cloud security, identity and access management, network security, and data protection. • Hands-on experience architecting cloud security solutions, including network security design, IAM, key and secrets management, encryption, and cloud-native security services. • Proven experience leading threat modeling using STRIDE, PASTA, or equivalent methodologies at varying scales. • Experience evaluating others' threat models and training engineers to produce their own. • Strong command of SSDLC, OWASP principles, and application security design patterns. • Proficiency in OAuth 2.0, OIDC, and SAML, including multi-tenant and patient-facing applications. • Experience architecting key management, secrets management, and PKI/certificate lifecycle controls in cloud-native environments. • Working knowledge of HIPAA, HITRUST CSF, NIST CSF, and SOC 2 sufficient to design compliant controls. • Ability to communicate complex architectural risk to technical and executive audiences. • Preferred: experience in healthcare, digital health, or another highly regulated industry. • Preferred: experience designing and evaluating zero trust architectures in production. • Preferred: experience designing or scaling an architecture review process. • Preferred: familiarity with API security architecture and HL7/FHIR. • Preferred: familiarity with SABSA or TOGAF security extensions. • Preferred: experience mentoring senior engineers or establishing architecture practices from scratch.

🏖️ Benefits

• Medical, Dental, and Vision plans • Flexible Spending/Health Savings Accounts • Flexible PTO • 401(k) + Company Match • Life Insurance • Pet insurance

Apply Now

Similar Jobs

🔥 2 hours ago

CDW

10,000+ employees

💼 Consulting

🏥 Healthcare

📚 Education

Lead security engineering, IAM, compliance, and infrastructure protection for CDW’s managed-services platforms. Providing technical leadership across hybrid cloud environments, risk mitigation, and secure-by-design initiatives.

🔥 3 hours ago

Oxfam America

201 - 500

🤲 Charity

🤝 Non-profit

🌍 Social Impact

Cybersecurity and Infrastructure Manager securing Oxfam’s technology systems supporting global poverty and injustice initiatives. Leading infrastructure, incident response, helpdesk, vendors, and IT asset management.

🔥 4 hours ago

CADRE GOVERNMENT SOLUTIONS

11 - 50

🏛️ Government

💼 Consulting

🔒 Cybersecurity

Salesforce Security Engineer building secure, high-volume Salesforce–AWS integrations for CADRE’s government communications initiatives. Supporting DevSecOps delivery, compliance, monitoring, and automated security testing.

🔥 5 hours ago

AlertMedia

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Engineer securing AlertMedia’s risk intelligence and response SaaS platform. Improving AWS, application, compliance, monitoring, and customer security capabilities.

🔥 5 hours ago

NetCov

201 - 500

🔒 Cybersecurity

🤝 B2B

💼 Consulting

Security Engineer deploying and monitoring managed cybersecurity solutions for NetCov’s client environments. Conducting vulnerability scans, remediation, and incident-response escalation.