Senior Security Engineer

Posted Aug 24

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of application and product security through threat modeling, secure design reviews, and secure code evaluations.

• Implement and optimize GitHub Advanced Security features such as CodeQL, secret scanning, push protection, branch protection, and CODEOWNERS reviews.

• Design and manage the security architecture for Oshi’s agentic software development lifecycle.

• Establish security gates, controls for agent-generated code, and clawback procedures.

• Develop and manage non-human identity and secrets management across SaaS and AWS environments.

• Ensure the security of the AWS environment, which includes IAM/IC, network segmentation, logging, configuration baselines, encryption, S3, EKS, and Terraform.

• Assess AI and third-party vendor integrations prior to their access to PHI.

• Implement and fine-tune detection and response mechanisms utilizing behavioral baselines and anomaly detection.

• Assist with HIPAA Security Rule technical safeguards in collaboration with the Sr. Director.

• Manage vulnerability assessments and penetration testing frequency, ensuring timely resolution of findings.

• Minimize attack surface through SaaS and identity rationalization efforts.

• Create security policies, standards, runbooks, scripting, and infrastructure-as-code automation.

• Collaborate with Product & Engineering teams and the Sr. Director of Security & IT.

• Direct Oshi Health’s technical security for its SaaS and cloud-native healthcare platform.


⛳️ Requirements

• Over 6 years of experience in security engineering.

• Proven expertise in application/product security and cloud security, particularly in AWS.

• Background in healthcare, fintech, or any regulated, data-sensitive sector is highly advantageous.

• Practical experience with SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply chain/dependency security.

• Familiarity with Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and management of non-human identities and secrets.

• Knowledge of securing AI/LLM and agentic systems, addressing issues like prompt injection, agent authorization, over-permissioning, NHI sprawl, and model/supply-chain risk.

• Understanding of the HIPAA Security Rule, SOC 2, and the NIST Cybersecurity Framework.

• Proficient in Python and at least one shell scripting language.

• Bachelor’s degree in Computer Science or equivalent practical experience.

• Relevant certifications such as OSCP, GIAC, AWS Certified Security – Specialty, CISSP, or Okta Certified Professional are desirable, but not mandatory.


🏝️ Benefits

• Join a mission-driven organization dedicated to innovative digestive care.

• Embrace diversity through monthly DEIB discussions and activities.

• Enjoy a virtual-first culture: Work remotely from anywhere in the U.S.

• Receive competitive compensation along with meaningful equity options.

• Access employer-sponsored medical, dental, and vision insurance plans.

• Benefit from a “Life Concierge” service through Overalls.

• Take advantage of personalized professional development opportunities.

• Enjoy flexible paid time off.

• Benefit from 13 paid company holidays.

• Participate in team events, including virtual cooking classes, games, and more.

• Receive recognition for both professional and personal achievements.

People also viewed

WorkOS14 hours ago

Product Security Engineer

US flagUnited States, +1 more countryFull-timeCybersecurity / Security Engineer$175k – $275k/year
ApplyView job
Fortive15 hours ago

Information Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Brown and Caldwell15 hours ago

Cybersecurity, OT-IT Security Consultant

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $212k/year
ApplyView job
Galileo15 hours ago

IT and Security Generalist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $120k/year
ApplyView job
Mercor15 hours ago

Cybersecurity Practitioner – SOC, Incident Response, Detection, AppSec

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer$125 – $175/hour
ApplyView job
Peek16 hours ago

Security and Compliance Analyst

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer$80k – $90k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers