
Senior Staff Security Engineer
Posted Aug 12

Posted Aug 12
This is a fully remote position, open to applicants in United States.
• Take ownership of and continually enhance OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems.
• Lead threat modeling efforts for product, engineering, and infrastructure projects, focusing on PHI data flows, patient-facing interfaces, and virtual care delivery systems.
• Mentor engineers to execute threat modeling for their own projects.
• Conduct architecture assessments for both new and existing systems, providing actionable recommendations.
• Design and refine the architecture review process, incorporating self-service patterns, risk-tiered review pathways, and criteria for comprehensive reviews.
• Collaborate with the CTO and enterprise architecture team to integrate security reviews into technical governance.
• Define and advocate for application security standards, including API security, authentication and authorization protocols, and data protection controls.
• Establish and uphold a zero trust architecture strategy across identity, network, endpoint, and data layers.
• Architect and oversee key management, secrets management, and certificate lifecycle practices.
• Own the security architecture for third-party integrations and manage supply chain risks at the design phase.
• Act as the primary security advisor for product and engineering leadership.
• Maintain security architecture documentation, including ADRs, reference designs, and control frameworks.
• Convert security and compliance requirements into tangible architectural controls, particularly focusing on HIPAA Security Rule technical safeguards for PHI architecture.
• Collaborate with the CISO and security leadership on long-term architecture planning, metrics, and executive-ready reporting.
• Mentor and uplift the broader security team.
• Investigate emerging threats and attack techniques that target the healthcare sector.
• Bachelor's degree in Computer Science, Information Security, or a related discipline, or equivalent professional experience.
• Over 10 years of progressive security experience, including a minimum of 5 years concentrated on security architecture within enterprise and cloud environments.
• Extensive expertise in application security, cloud security, identity and access management, network security, and data protection.
• Practical experience in architecting cloud security solutions, encompassing network security design, IAM, key and secrets management, encryption, and cloud-native security services.
• Demonstrated experience in leading threat modeling initiatives using STRIDE, PASTA, or similar methodologies at various scales.
• Experience in evaluating others' threat models and training engineers to develop their own.
• Strong understanding of SSDLC, OWASP principles, and application security design patterns.
• Proficient in OAuth 2.0, OIDC, and SAML, including multi-tenant and patient-facing applications.
• Experience in architecting key management, secrets management, and PKI/certificate lifecycle controls in cloud-native settings.
• Familiarity with HIPAA, HITRUST CSF, NIST CSF, and SOC 2 sufficient for designing compliant controls.
• Ability to convey complex architectural risks to both technical and executive audiences.
• Preferred: Experience in healthcare, digital health, or another highly regulated sector.
• Preferred: Experience in designing and evaluating zero trust architectures in production environments.
• Preferred: Experience in designing or scaling an architecture review process.
• Preferred: Knowledge of API security architecture and HL7/FHIR.
• Preferred: Familiarity with SABSA or TOGAF security extensions.
• Preferred: Experience mentoring senior engineers or developing architecture practices from the ground up.
• Medical, Dental, and Vision plans
• Flexible Spending/Health Savings Accounts
• Flexible PTO
• 401(k) + Company Match
• Life Insurance
• Pet insurance
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.