
Senior Security Engineer
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States, +2 more states.
• Take charge of AxisCare Engineering's security program as an individual contributor.
• Continuously enhance security standards, reinforce enforcement systems, and collaborate with engineers to address vulnerabilities.
• Manage the engineering team's responsibilities for SOC 2 Type II compliance, including control design, evidence gathering, audit preparation, and gap remediation.
• Develop a roadmap for achieving HITRUST certification.
• Conduct threat modeling for both the application and infrastructure.
• Enhance security across the PHP/React, AWS, Terraform, Docker, and MySQL/RDS technology stack.
• Oversee and refine the security scanning program, calibrate findings, minimize false positives, and encourage developer engagement.
• Evaluate and mitigate risks associated with AI products, including prompt injection, data leakage, model output filtering, and abuse scenarios.
• Establish guardrails for AI-assisted development workflows.
• Strengthen logging, alerting, detection, and incident response protocols.
• Organize penetration tests, monitor findings, and facilitate remediation efforts.
• Keep security policies clear, up-to-date, and concise.
• Educate developers on secure practices.
• Over 5 years of experience in application security, infrastructure security, or security engineering within a SaaS environment.
• Practical experience with AWS security components, including IAM, VPC, Security Groups, KMS, CloudTrail, and GuardDuty.
• Proven track record of owning or significantly contributing to the engineering aspect of SOC 2 Type II compliance.
• Knowledge of container security, Docker, Kubernetes, and infrastructure-as-code practices using Terraform.
• Strong understanding of web application security principles, OWASP Top 10, and secure Software Development Life Cycle (SDLC).
• Experience securing AI/ML systems or products powered by large language models (LLMs).
• Tangible examples of leveraging AI to enhance security efforts.
• Capability to work remotely from Eastern, Central, or Mountain time zones.
• Eligibility to work in the United States or Canada.
• Excellent written communication abilities.
• Manual dexterity necessary for the use of a desktop computer and peripherals.
• Comprehensive medical insurance coverage for the employee, including Medical, Dental, and Vision.
• The company will supply a laptop and other essential computer equipment.
• Fully remote work setup.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.