Sr. Information Security Engineer

location_onUnited Statespayments$140,000 – $160,000/yrschedule11 hours ago
homeWork style:Remote
trending_upExperience level:Senior
badgeEmployment:Full-time
historyMinimum experience:5+ years
schoolEducation:Bachelor’s degree
Apply Nowopen_in_new

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Information Security Engineer based in the United States.

This is a senior, hands-on security engineering role focused on protecting cloud-based healthcare SaaS platforms, AI/ML environments, infrastructure, and sensitive customer data.

You will design and implement enterprise-grade security controls across cloud, application, identity, endpoint, and AI environments.

The role has a particularly strong focus on securing AI and large language model workflows that process protected health information and personally identifiable information.

You will collaborate closely with engineering, data science, compliance, legal, and operations teams to embed security throughout the technology lifecycle.

The position combines architecture, threat modeling, security automation, incident response, DevSecOps, and regulatory compliance.

You will also help shape emerging AI security practices while strengthening defenses against evolving cyber threats.

This is an ideal opportunity for a technically strong security professional who enjoys solving complex problems in a highly regulated healthcare technology environment.

Accountabilities

  • Design, implement, and maintain secure architectures across AWS, Azure, and GCP, including infrastructure-as-code and policy-as-code security controls.
  • Deploy and manage cloud security capabilities such as Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls.
  • Operate CSPM/CNAPP platforms to identify cloud misconfigurations, exposed data stores, toxic combinations, and other security risks.
  • Secure containerized and serverless environments, including EKS, ECS, Lambda, image scanning, admission controls, runtime protection, and least-privilege access.
  • Establish strong network segmentation, encryption, centralized key management, secrets management, and secure workload configurations.
  • Partner with AI and data teams to secure model development, training, fine-tuning, inference, and retrieval-augmented generation pipelines handling sensitive data.
  • Apply AI security frameworks and threat-modeling practices to address prompt injection, data poisoning, model exfiltration, insecure outputs, excessive agency, and other AI-specific threats.
  • Implement AI gateways, guardrails, content filtering, validation, rate limiting, and logging controls while supporting responsible enterprise use of generative AI.
  • Evaluate third-party and foundation-model providers, including security controls, data residency, retention, contractual protections, and appropriate coverage for sensitive healthcare data.
  • Secure the machine-learning supply chain through artifact provenance, signed models, dependency scanning, and hardened MLOps environments.
  • Embed security into CI/CD pipelines through SAST, DAST, SCA, secrets scanning, infrastructure-as-code scanning, threat modeling, and secure design reviews.
  • Protect APIs and machine-to-machine integrations using secure authorization standards such as OAuth 2.0, OIDC, mTLS, and scoped service tokens.
  • Manage software supply-chain security, including SBOMs, dependency governance, artifact signing, penetration testing, vulnerability remediation, and bug-bounty processes.
  • Strengthen PHI and PII protection through data classification, tokenization, de-identification, DLP, and appropriate access controls.
  • Manage endpoint and identity security using EDR/XDR, Microsoft Entra ID, Conditional Access, privileged identity management, phishing-resistant MFA, and risk-based authentication.
  • Govern service accounts, workload identities, service principals, AI agent credentials, and other non-human identities through least privilege and short-lived credentials.
  • Monitor and investigate security alerts, coordinate incident response, and work with SOC and managed detection and response partners.
  • Develop SIEM detection content, detection-as-code, log coverage, MITRE ATT&CK mappings, SOAR workflows, and automated response capabilities using Python and PowerShell.
  • Develop incident response runbooks and forensic procedures covering both conventional cyber incidents and AI-specific scenarios such as model misuse, prompt-based data leakage, and compromised AI integrations.
  • Participate in tabletop exercises, purple-team activities, post-incident reviews, and continuous security improvement initiatives.
  • Support HIPAA, HITRUST, SOC 2 Type 2, and NIST-related audits, customer security assessments, evidence collection, risk registers, asset inventories, and remediation tracking.
  • Conduct third-party and vendor risk reviews, with particular attention to AI subprocessors, sensitive-data flows, and emerging technology risks.
  • Partner with compliance and other stakeholders to maintain alignment between technical controls, security policies, regulatory requirements, and responsible AI practices.
  • Contribute to security awareness and training initiatives, including guidance on secure and responsible AI use.
  • Requirements

    • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
    • 5+ years of experience in security engineering or comparable technical security roles.
    • Strong knowledge of cloud-native security across AWS, Azure, and GCP, along with modern SaaS architectures.
    • Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, security automation, and incident response technologies.
    • Practical experience securing containerized and serverless workloads such as EKS and Lambda.
    • Familiarity with healthcare and security frameworks including HIPAA, HITRUST, NIST, and SOC 2.
    • Experience with infrastructure-as-code security using technologies such as Terraform, Ansible, or CloudFormation is preferred.
    • Experience integrating security into DevSecOps environments and CI/CD pipelines, including tools such as Jenkins or Bitbucket, is preferred.
    • Strong scripting capabilities in Python, PowerShell, Bash, or similar languages.
    • Experience with AI/LLM security, AI threat modeling, ML security, or securing AI-enabled applications is highly valuable.
    • Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, GSEC, GCIA, or GCIH are preferred.
    • Strong analytical, troubleshooting, and problem-solving capabilities with exceptional attention to detail.
    • Ability to balance business objectives with appropriate risk mitigation and practical security controls.
    • Excellent written and verbal communication skills, including the ability to explain complex technical and security concepts to non-technical stakeholders.
    • Collaborative and proactive approach, with a demonstrated commitment to continuous improvement.
    • Ability to operate effectively in a regulated healthcare technology environment and manage sensitive information responsibly.
    • Benefits

      • Annual salary range of $140,000–$160,000, with compensation varying according to geographic market, job-related knowledge, skills, and experience.
      • Remote work opportunity within the United States.
      • Medical, dental, and vision insurance benefits.
      • 401(k) matching.
      • Generous paid time off program.
      • Opportunity to work on advanced cloud, cybersecurity, healthcare, and AI security challenges.
      • Environment focused on continuous professional and technical development.
      • Equal opportunity workplace committed to an inclusive and respectful work environment.
How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

Skills mentioned


Recruitment
United States

Jobgether is a Belgium-based, AI-powered remote-work job platform founded in 2020 in Brussels. It aggregates and enriches large volumes of remote and flexible job listings from many employers and matches candidates to roles; it is a job aggregator rather than the hiring employer.

Apply for this job

Use the application link supplied with this listing to apply to jobgether. Check the destination before entering personal information.

Apply Nowopen_in_new