
Lead Cybersecurity Engineer
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in United States.
• Direct the cybersecurity initiatives for both Cerbo and OptiMantra.
• Safeguard protected health information (PHI) and operational platforms that cater to thousands of clinicians and millions of patients.
• Design, execute, and continually enhance a cohesive security strategy for both products.
• Oversee the technical execution and ongoing management of SOC 2 Trust Services Criteria and HIPAA Security Rule requirements within AWS environments.
• Manage compliance documentation, remediation efforts, control narratives, system and data-flow documentation, scope determinations, and closure of security gaps.
• Act as the primary technical liaison for auditors and assessors, organizing audit activities and milestones.
• Fortify and secure production AWS environments, including cloud infrastructure, Kubernetes and container ecosystems, databases, networking, web application security, and disaster recovery setups.
• Implement and manage AWS security controls and tools, such as IAM, privileged access management, MFA, least-privilege access, security monitoring, encryption and key management, vulnerability management, and audit logging.
• Develop standardized protocols for access, tenant isolation, data protection, backup, and disaster recovery.
• Create and manage centralized logging, alerting, threat detection, and security response procedures.
• Oversee security incident response and vulnerability management programs, including playbooks, tabletop exercises, breach assessments, vulnerability scanning, remediation tracking, and coordination with Engineering and external security vendors.
• Conduct penetration testing, DAST, security assessments, remediation of findings, and retesting.
• Manage security policies, procedures, workforce security, security awareness initiatives, phishing simulations, HIPAA training, and compliance tracking.
• Direct identity and endpoint security practices for corporate systems, users, and sensitive data.
• Oversee third-party security and vendor risk management, which includes security assessments, business associate agreements, subprocessor due diligence, and vendor oversight.
• Serve as a technical security partner for customers and strategic partners, leading security questionnaires, architecture reviews, and discussions regarding security.
• Assist customer and partner security requirements during sales and contracting processes, covering incident notifications, data retention and export, backup and disaster recovery, AI, and subprocessors.
• Report directly to the Chief Technology Officer and collaborate with DevOps, Engineering, IT, Product, and other stakeholders.
• 5+ years of experience in cybersecurity or information security, with progressive responsibility in security engineering.
• 2+ years of experience in securing production cloud environments, preferably AWS, including cloud identity and access management, network security, logging/monitoring, and security controls.
• Proven experience with the AWS security ecosystem, encompassing IAM, CloudTrail, GuardDuty, Security Hub, KMS, VPC security, and other related AWS security services.
• Experience in implementing, maintaining, and evidencing security controls aligned with frameworks and standards such as NIST, HITRUST, ISO 27001, HIPAA, SOC 2, or analogous standards.
• Familiarity with securing Kubernetes and containerized production environments, specifically regarding identity, network security, image security, and runtime controls.
• Experience serving as a technical owner during third-party security audits, assessments, or certifications.
• Experience deploying, configuring, and operating cybersecurity tools in production, including EDR, SIEM/log management, vulnerability management, WAF, or similar technologies.
• Proven ability to lead intricate cybersecurity initiatives, establish security standards and processes, and act as a technical subject-matter expert throughout the organization.
• Bachelor's degree in cybersecurity, information security, or a relevant field (preferred).
• Experience working in a private equity-backed, high-growth, or rapidly scaling organization (preferred).
• Familiarity with healthcare technology, SaaS, or other technology-enabled B2B businesses (preferred).
• Experience securing multi-tenant SaaS environments, including tenant isolation, access controls, and shared infrastructure (preferred).
• Experience working across cloud, DevOps, SRE, or application security environments, with exposure to infrastructure as code, CI/CD, Kubernetes, secure coding practices, or vulnerability remediation (preferred).
• Competitive compensation based on experience.
• Paid Time Off and company holidays.
• Comprehensive health, dental, and vision benefits.
• Short-term and long-term disability insurance.
• 401k plan with matching company contributions.
• Genuine ownership and impact within a fast-growing health tech company.
Cummins Inc.
Tangible
GitLab
Tevora
Get handpicked remote jobs straight to your inbox weekly.