Senior Security Engineer

Posted 2ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Engineer securing Redox’s cloud-native healthcare data interoperability platform. Hardening Kubernetes, containers, infrastructure, and application security across U.S.-based remote engineering teams.

Responsibilities:

  • Own Cloud Security Posture Management including Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening
  • Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure
  • Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity
  • Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls
  • Evaluate and secure infrastructure-as-code across all environments
  • Execute incident response duties, including forensic investigation and blameless post-mortem analyses
  • Contribute to security standards within Engineering through design reviews, collaborative pairing, and mentorship of peers
  • Support bug bounty triage and maintain professional engagement with external security researchers
  • Take ownership of cloud-native and application security across the Redox platform
  • Perform code reviews and translate control gaps into engineering proposals that drive production impact
  • Embed security into the SDLC through container security, Kubernetes hardening, and architecture reviews

Requirements:

  • 5+ years in security engineering with a track record of hands-on delivery across system hardening, security engineering projects, and peer mentorship
  • Strong technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols
  • Experience with threat modeling for applications built using Node.js, TypeScript, Python or Go
  • Hands-on experience supporting secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity
  • Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms
  • Solid experience across the vulnerability management lifecycle, from initial triage to production remediation
  • Ability to apply compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows
  • Strong written communication skills, with the ability to clearly document decisions and collaborate effectively within a remote, asynchronous organizational culture
  • Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI

Benefits:

  • 100% remote first culture (must be based in the US)
  • Unlimited Flexible Time Off
  • 15+ Observed Holidays
  • Rest & R^Charge days (guaranteed a 3-day weekend each month)
  • R^Charge (6 weeks paid sabbatical + stipend)
  • 401k match 50% for up to 8% on Day 1
  • Medical/Dental/Vision Benefits on Day 1
  • HSA & FSA, Life, Disability, Medical Travel & Employee Assistance Program
  • Paid Parental Leave (16 weeks)
  • Productivity Stipend & Wellness Fund
  • Redox Issued MacBook
  • Virtual and/or in-person Team & Company Events
  • Stock Options
  • Employee Referral Bonus Program