Senior Security Engineer

Posted 7 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership and advance AgelessRx's technical security roadmap.

• Develop and implement repeatable security programs, controls, reporting, and documentation.

• Perform security and architecture evaluations for systems, vendors, integrations, and technology modifications.

• Ensure visibility into risks, vulnerabilities, remediation priorities, owners, and timelines.

• Conduct and assist with HIPAA Security Rule risk assessments.

• Maintain documentation and evidence that is ready for audits.

• Organize and lead security and incident-response exercises.

• Present security posture, priorities, open risks, and remediation progress to leadership.

• Establish standards for identity, authentication, authorization, privileged access, cloud, endpoint, and email security.

• Collaborate with IT on SSO, MFA, privileged access management, endpoint controls, access reviews, and device security.

• Oversee vulnerability management across infrastructure, endpoints, applications, and other technologies.

• Integrate security into the software development lifecycle.

• Assess architecture, authentication flows, sensitive data handling, payments, and security-sensitive product areas.

• Create threat models for products, features, services, and integrations involving PHI or sensitive information.

• Implement and enhance SAST, SCA, dependency scanning, and software supply chain controls.

• Establish processes for remediating application security findings and provide secure development guidance.

• Coordinate penetration testing, vulnerability disclosure, and triage efforts.

• Partner with Engineering to identify risks prior to production.

• Assist with HIPAA audits, investigations, incident responses, and compliance activities.

• Evaluate vendors and partners handling PHI or sensitive information.

• Act as the technical security lead for AI governance.

• Maintain oversight of AI systems accessing PHI or sensitive data.

• Assess AI tools and vendors, including data flows, retention, model training, access controls, subprocessors, and other risks.

• Expand threat modeling to AI-enabled products, addressing prompt injection, model access, data leakage, output handling, and PHI exposure.

• Convert evolving healthcare and AI requirements into technical controls.

• Align AI risk management with a recognized framework and uphold evidence.

• Review and implement approved MCPs and other AI integrations.

• Support policies governing employee use of AI tools.


⛳️ Requirements

• Minimum of 5 years of experience in security engineering, cybersecurity, or a related technical security role.

• Hands-on experience in at least two significant security domains, such as application/product security, cloud and identity security, vulnerability management, security operations, or security governance.

• Familiarity with securing environments subject to HIPAA or similar regulatory requirements and the ability to translate regulatory obligations into technical controls.

• Strong working knowledge of at least one major cloud provider and relevant IAM and security practices.

• Solid understanding of identity and access management, including SSO, SAML/OIDC, MFA, privileged access, and least-privilege principles.

• Experience with application security tools and practices, including SAST, SCA, dependency management, threat modeling, and secure software development.

• Background in establishing or managing recurring security programs such as vulnerability management, access reviews, penetration testing, security assessments, or incident-response exercises.

• Expertise in assessing and prioritizing vulnerabilities based on exploitability, business impact, sensitive data exposure, and practical risk.

• Working knowledge of AI/LLM security risks and managing AI systems in regulated environments.

• Excellent written communication and documentation skills.

• Ability to work independently and create structure in a dynamic environment.

• Preferred: direct experience with HIPAA Security Rule risk analyses, OCR audits, healthcare security investigations, or breach response.

• Preferred: experience with healthcare technology, telehealth, EHR integrations, or HL7/FHIR systems.

• Preferred: experience building or enhancing a security program as an early or first dedicated security hire.

• Preferred: familiarity with AI governance or AI risk management programs, including NIST AI RMF, ISO/IEC 42001, or similar frameworks.

• Preferred: assessing AI vendors or systems that process PHI or regulated data.

• Preferred: knowledge of emerging healthcare and AI regulatory requirements.

• Preferred: experience with Docker.

• Relevant security certifications such as OSCP, HCISPP, CISSP, or cloud security certifications are valued but not mandatory.


🏝️ Benefits

• Comprehensive health, dental, and vision insurance.

• Flexible work hours and the option for remote work.

• Professional development opportunities and training.

• Generous paid time off and holiday schedule.

People also viewed

MRO7 hours ago

Information Security Assurance Advisor

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$104k – $140k/year
ApplyView job
Xcelerate Solutions7 hours ago

Security Engineer – Intrusion Prevention Monitoring

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$94k – $149k/year
ApplyView job
OnePay9 hours ago

Security and Threat Operations Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $190k/year
ApplyView job
Halcyon9 hours ago

Senior Information Security Specialist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$120k – $160k/year
ApplyView job
Optiv11 hours ago

Security Advisor – Threat Exposure Management

US flagMinnesota, +3 more statesFull-timeCybersecurity / Security Engineer$200k – $250k/year
ApplyView job
Accenture Federal Services11 hours ago

Security Engineer – Vulnerability Management

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer$106.3k – $221.1k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers