
Senior Security Engineer
Posted Aug 24

Posted Aug 24
This is a fully remote position, open to applicants in United States.
• Take ownership of application and product security through threat modeling, secure design reviews, and secure code evaluations.
• Implement and optimize GitHub Advanced Security features such as CodeQL, secret scanning, push protection, branch protection, and CODEOWNERS reviews.
• Design and manage the security architecture for Oshi’s agentic software development lifecycle.
• Establish security gates, controls for agent-generated code, and clawback procedures.
• Develop and manage non-human identity and secrets management across SaaS and AWS environments.
• Ensure the security of the AWS environment, which includes IAM/IC, network segmentation, logging, configuration baselines, encryption, S3, EKS, and Terraform.
• Assess AI and third-party vendor integrations prior to their access to PHI.
• Implement and fine-tune detection and response mechanisms utilizing behavioral baselines and anomaly detection.
• Assist with HIPAA Security Rule technical safeguards in collaboration with the Sr. Director.
• Manage vulnerability assessments and penetration testing frequency, ensuring timely resolution of findings.
• Minimize attack surface through SaaS and identity rationalization efforts.
• Create security policies, standards, runbooks, scripting, and infrastructure-as-code automation.
• Collaborate with Product & Engineering teams and the Sr. Director of Security & IT.
• Direct Oshi Health’s technical security for its SaaS and cloud-native healthcare platform.
• Over 6 years of experience in security engineering.
• Proven expertise in application/product security and cloud security, particularly in AWS.
• Background in healthcare, fintech, or any regulated, data-sensitive sector is highly advantageous.
• Practical experience with SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply chain/dependency security.
• Familiarity with Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and management of non-human identities and secrets.
• Knowledge of securing AI/LLM and agentic systems, addressing issues like prompt injection, agent authorization, over-permissioning, NHI sprawl, and model/supply-chain risk.
• Understanding of the HIPAA Security Rule, SOC 2, and the NIST Cybersecurity Framework.
• Proficient in Python and at least one shell scripting language.
• Bachelor’s degree in Computer Science or equivalent practical experience.
• Relevant certifications such as OSCP, GIAC, AWS Certified Security – Specialty, CISSP, or Okta Certified Professional are desirable, but not mandatory.
• Join a mission-driven organization dedicated to innovative digestive care.
• Embrace diversity through monthly DEIB discussions and activities.
• Enjoy a virtual-first culture: Work remotely from anywhere in the U.S.
• Receive competitive compensation along with meaningful equity options.
• Access employer-sponsored medical, dental, and vision insurance plans.
• Benefit from a “Life Concierge” service through Overalls.
• Take advantage of personalized professional development opportunities.
• Enjoy flexible paid time off.
• Benefit from 13 paid company holidays.
• Participate in team events, including virtual cooking classes, games, and more.
• Receive recognition for both professional and personal achievements.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.