
Senior Security Engineer
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership and advance AgelessRx's technical security roadmap.
• Develop and implement repeatable security programs, controls, reporting, and documentation.
• Perform security and architecture evaluations for systems, vendors, integrations, and technology modifications.
• Ensure visibility into risks, vulnerabilities, remediation priorities, owners, and timelines.
• Conduct and assist with HIPAA Security Rule risk assessments.
• Maintain documentation and evidence that is ready for audits.
• Organize and lead security and incident-response exercises.
• Present security posture, priorities, open risks, and remediation progress to leadership.
• Establish standards for identity, authentication, authorization, privileged access, cloud, endpoint, and email security.
• Collaborate with IT on SSO, MFA, privileged access management, endpoint controls, access reviews, and device security.
• Oversee vulnerability management across infrastructure, endpoints, applications, and other technologies.
• Integrate security into the software development lifecycle.
• Assess architecture, authentication flows, sensitive data handling, payments, and security-sensitive product areas.
• Create threat models for products, features, services, and integrations involving PHI or sensitive information.
• Implement and enhance SAST, SCA, dependency scanning, and software supply chain controls.
• Establish processes for remediating application security findings and provide secure development guidance.
• Coordinate penetration testing, vulnerability disclosure, and triage efforts.
• Partner with Engineering to identify risks prior to production.
• Assist with HIPAA audits, investigations, incident responses, and compliance activities.
• Evaluate vendors and partners handling PHI or sensitive information.
• Act as the technical security lead for AI governance.
• Maintain oversight of AI systems accessing PHI or sensitive data.
• Assess AI tools and vendors, including data flows, retention, model training, access controls, subprocessors, and other risks.
• Expand threat modeling to AI-enabled products, addressing prompt injection, model access, data leakage, output handling, and PHI exposure.
• Convert evolving healthcare and AI requirements into technical controls.
• Align AI risk management with a recognized framework and uphold evidence.
• Review and implement approved MCPs and other AI integrations.
• Support policies governing employee use of AI tools.
• Minimum of 5 years of experience in security engineering, cybersecurity, or a related technical security role.
• Hands-on experience in at least two significant security domains, such as application/product security, cloud and identity security, vulnerability management, security operations, or security governance.
• Familiarity with securing environments subject to HIPAA or similar regulatory requirements and the ability to translate regulatory obligations into technical controls.
• Strong working knowledge of at least one major cloud provider and relevant IAM and security practices.
• Solid understanding of identity and access management, including SSO, SAML/OIDC, MFA, privileged access, and least-privilege principles.
• Experience with application security tools and practices, including SAST, SCA, dependency management, threat modeling, and secure software development.
• Background in establishing or managing recurring security programs such as vulnerability management, access reviews, penetration testing, security assessments, or incident-response exercises.
• Expertise in assessing and prioritizing vulnerabilities based on exploitability, business impact, sensitive data exposure, and practical risk.
• Working knowledge of AI/LLM security risks and managing AI systems in regulated environments.
• Excellent written communication and documentation skills.
• Ability to work independently and create structure in a dynamic environment.
• Preferred: direct experience with HIPAA Security Rule risk analyses, OCR audits, healthcare security investigations, or breach response.
• Preferred: experience with healthcare technology, telehealth, EHR integrations, or HL7/FHIR systems.
• Preferred: experience building or enhancing a security program as an early or first dedicated security hire.
• Preferred: familiarity with AI governance or AI risk management programs, including NIST AI RMF, ISO/IEC 42001, or similar frameworks.
• Preferred: assessing AI vendors or systems that process PHI or regulated data.
• Preferred: knowledge of emerging healthcare and AI regulatory requirements.
• Preferred: experience with Docker.
• Relevant security certifications such as OSCP, HCISPP, CISSP, or cloud security certifications are valued but not mandatory.
• Comprehensive health, dental, and vision insurance.
• Flexible work hours and the option for remote work.
• Professional development opportunities and training.
• Generous paid time off and holiday schedule.
MRO
Xcelerate Solutions
OnePay
Halcyon
Get handpicked remote jobs straight to your inbox weekly.