
Staff Cloud Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Design, secure, and continually enhance the AWS environment, encompassing IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub, Config, and WAF.
• Protect serverless and data layers, including Lambda, S3, and PostgreSQL/RDS/Aurora, through encryption, least-privilege access, network isolation, backup integrity, and audit logging.
• Implement security guardrails for Infrastructure-as-Code and policy-as-code.
• Manage secrets, key management, and the lifecycle of certificates.
• Oversee and fortify Amazon EKS infrastructure, focusing on cluster security, network policies, and container runtime security.
• Secure APIs and the application stack, addressing authentication/authorization, session management, rate limiting, input validation, and OWASP Top 10/API Top 10 risks.
• Integrate security into the SDLC via threat modeling, secure design reviews, SAST/DAST, dependency and container scanning, and CI/CD pipeline security.
• Safeguard the proprietary real-time video platform, including WebRTC/media transport, session access controls, recording storage, and encryption.
• Conduct vulnerability management and penetration testing, including vendor selection, scoping, and remediation tracking.
• Develop company-wide AI usage policies and governance frameworks.
• Architect and secure in-product AI/ML capabilities against OWASP LLM Top 10 vulnerabilities.
• Implement privacy guardrails for PHI/PII during model training, fine-tuning, and prompt contexts.
• Establish model security controls and secure artifacts, endpoints, dependencies, and access controls.
• Create monitoring, telemetry, and audit logging across AI/ML workflows.
• Manage SOC 2 Type I and Type II readiness, including control design, evidence collection, auditor management, and ongoing compliance.
• Ensure compliance with HIPAA Security Rule, involving risk assessments, policies, BAAs, breach notification procedures, and audit readiness.
• Optimize Vanta integrations, automate evidence collection, and facilitate remediation.
• Maintain security policies, risk register, and vendor risk management program.
• Assist with customer and payer security questionnaires and due diligence.
• Oversee endpoint security in collaboration with outsourced IT, including MDM, disk encryption, EDR, patching, hardening baselines, and device compliance.
• Manage identity and access, focusing on SSO, MFA, RBAC, joiner/mover/leaver processes, and periodic access reviews.
• Conduct security awareness and HIPAA training programs with People Ops.
• Establish logging, monitoring, alerting, and SIEM capabilities.
• Develop and test the incident response plan, facilitate tabletop exercises, and lead incident response efforts.
• Collaborate with engineering on disaster recovery, backup, and business continuity planning.
• Define the security roadmap and communicate risk to the CTO and executive team.
• Mentor engineers and foster a security-conscious culture, including a security champions model.
• Build the business case for tools, vendors, and future security headcount.
• 8+ years of experience in security engineering, with substantial hands-on experience securing production cloud environments, preferably AWS-heavy.
• In-depth expertise in AWS security (IAM, networking, encryption/KMS, logging and detection services, serverless security).
• Proven experience in securing PostgreSQL and other data stores with regulated or sensitive data.
• Strong background in application and API security, with the ability to review code and architecture while collaborating effectively with developers.
• Direct experience leading or managing a SOC 2 audit (Type I and/or Type II) and HIPAA compliance, ideally in healthcare or health-tech involving PHI.
• Familiarity with Infrastructure-as-Code (Pulumi, CloudFormation, or CDK) and CI/CD security.
• Knowledge of AI security, LLM application security, and OWASP LLM Top 10 vulnerabilities.
• Strong incident response experience.
• Excellent communication skills with engineers, executives, auditors, and customers.
• Experience with compliance automation platforms such as Vanta, Drata, or Secureframe (preferred).
• Experience in securing real-time communication or video platforms (WebRTC) (preferred).
• Familiarity with HITRUST, ISO 27001, or NIST frameworks (preferred).
• Background in a startup or scale-up where you built a security program from the ground up (preferred).
• Relevant certifications such as AWS Security Specialty, CISSP, CCSP, OSCP, or similar (preferred).
• Experience with pediatric or behavioral health data and privacy considerations for minors' information (preferred).
• Legally authorized to work in the United States.
• Equity options in a high-growth, venture-backed company.
• Comprehensive medical, dental, and vision coverage.
• Generous paid time off (PTO).
• Remote-first work flexibility.
Cloudiax
BLUVIT GmbH
Eli Lilly and Company
S + S Regeltechnik GmbH
Get handpicked remote jobs straight to your inbox weekly.