Remotery

Senior Staff Security Engineer

Posted Aug 12

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of and continually enhance OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems.

• Lead threat modeling efforts for product, engineering, and infrastructure projects, focusing on PHI data flows, patient-facing interfaces, and virtual care delivery systems.

• Mentor engineers to execute threat modeling for their own projects.

• Conduct architecture assessments for both new and existing systems, providing actionable recommendations.

• Design and refine the architecture review process, incorporating self-service patterns, risk-tiered review pathways, and criteria for comprehensive reviews.

• Collaborate with the CTO and enterprise architecture team to integrate security reviews into technical governance.

• Define and advocate for application security standards, including API security, authentication and authorization protocols, and data protection controls.

• Establish and uphold a zero trust architecture strategy across identity, network, endpoint, and data layers.

• Architect and oversee key management, secrets management, and certificate lifecycle practices.

• Own the security architecture for third-party integrations and manage supply chain risks at the design phase.

• Act as the primary security advisor for product and engineering leadership.

• Maintain security architecture documentation, including ADRs, reference designs, and control frameworks.

• Convert security and compliance requirements into tangible architectural controls, particularly focusing on HIPAA Security Rule technical safeguards for PHI architecture.

• Collaborate with the CISO and security leadership on long-term architecture planning, metrics, and executive-ready reporting.

• Mentor and uplift the broader security team.

• Investigate emerging threats and attack techniques that target the healthcare sector.


⛳️ Requirements

• Bachelor's degree in Computer Science, Information Security, or a related discipline, or equivalent professional experience.

• Over 10 years of progressive security experience, including a minimum of 5 years concentrated on security architecture within enterprise and cloud environments.

• Extensive expertise in application security, cloud security, identity and access management, network security, and data protection.

• Practical experience in architecting cloud security solutions, encompassing network security design, IAM, key and secrets management, encryption, and cloud-native security services.

• Demonstrated experience in leading threat modeling initiatives using STRIDE, PASTA, or similar methodologies at various scales.

• Experience in evaluating others' threat models and training engineers to develop their own.

• Strong understanding of SSDLC, OWASP principles, and application security design patterns.

• Proficient in OAuth 2.0, OIDC, and SAML, including multi-tenant and patient-facing applications.

• Experience in architecting key management, secrets management, and PKI/certificate lifecycle controls in cloud-native settings.

• Familiarity with HIPAA, HITRUST CSF, NIST CSF, and SOC 2 sufficient for designing compliant controls.

• Ability to convey complex architectural risks to both technical and executive audiences.

• Preferred: Experience in healthcare, digital health, or another highly regulated sector.

• Preferred: Experience in designing and evaluating zero trust architectures in production environments.

• Preferred: Experience in designing or scaling an architecture review process.

• Preferred: Knowledge of API security architecture and HL7/FHIR.

• Preferred: Familiarity with SABSA or TOGAF security extensions.

• Preferred: Experience mentoring senior engineers or developing architecture practices from the ground up.


🏝️ Benefits

• Medical, Dental, and Vision plans

• Flexible Spending/Health Savings Accounts

• Flexible PTO

• 401(k) + Company Match

• Life Insurance

• Pet insurance

People also viewed

ASG Technologies1 day ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike1 day ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International1 day ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape1 day ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity1 day ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist1 day ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers