Verified current Job

Senior Security Engineer

Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data

Job Remote Full source details
Redoxengine Source published Sep 20, 2026 Verified 6 hours ago
✓ 100% verification score · Source: Redoxengine (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull Time
Work modeRemote / location-flexible

Overview

Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data

Full job description

Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.

Opportunity & Impact We are seeking a Senior Security Engineer to take ownership of cloud-native and application security across the Redox platform. This is a high-impact, hands-on IC role where you will move beyond identifying risks to actively hardening our environment, performing code reviews, and translating complex control gaps into engineering proposals that drive production impact. You will function as a partner to our Engineering teams, embedding security into the SDLC through hands-on work across container security, Kubernetes hardening, and architecture reviews. You'll follow and reinforce our established security standards, helping make the secure path the easy path for the engineers you work with day to day. As part of a small, senior security team, your day to day work will directly strengthen how we protect data for our customers, with impact concentrated in the systems and teams you own. We're a fully remote team within the U.S. that operates with radical transparency and a strong bias toward ownership. Our Engineering Culture & How We Work Transparency, Ownership & Autonomy We make room for everyone to be heard, regardless of level. We work openly, normalize not knowing things, and treat "learning out loud" as a feature, not a liability. You'll be expected to bring your real perspective, push back when you see something wrong, and commit fully once a decision is made. As a Senior Engineer, you help cultivate our culture: you model the behavior, you embrace questions, you acknowledge mistakes. We default to public Slack channels over DMs, post Zoom summaries back in writing, and work async whenever possible. We'd rather expose incomplete thinking in public to get better feedback than protect it in private. That applies to security work too, when you identify a risk or propose a control, you bring it to the table with a recommendation, not just a concern. We own the systems we maintain, not just the new features on the roadmap. You'll have room to identify platform security work, propose scope, consult on priority, and see it through from design to operationalization. We measure ourselves by the value we deliver, not the process we follow.

Own Cloud Security Posture Management including Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening.

Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.

Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.

Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.

Evaluate and secure infrastructure-as-code across all environments.

Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.

Contribute to security standards within Engineering through design reviews, collaborative pairing, and mentorship of peers.

Support bug bounty triage and maintain professional engagement with external security researchers.

5+ years in security engineering with a track record of hands-on delivery across system hardening, security engineering projects, and peer mentorship.

Strong technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.

Experience with threat modeling for applications built using Node.js, TypeScript, Python or Go.

Hands-on experience supporting secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.

Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.

Solid experience across the vulnerability management lifecycle, from initial triage to production remediation.

Ability to apply compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.

Strong written communication skills, with the ability to clearly document decisions and collaborate effectively within a remote, asynchronous organizational culture.

Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.

AWS, Docker, EKS

Crowdstrike, Jamf, Okta, GuardDuty, Sumologic

Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane

Github Actions, Terraform, Helm, ArgoCD and Atlantis

Postgres, Redis, Kafka

Experience securing autonomous agentic loops and tool-calling frameworks. Understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.

Technical familiarity with securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.

Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.

Go, Node.js, or TypeScript (we're a TypeScript shop and it helps to be comfortable there).

VPN administration or enterprise network security experience.

Dependency management tooling (Renovate, Dependabot).

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v2

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Redoxengine (lever) ↗

Browse current Job and Scholarship listings from Redoxengine (lever) →

Related opportunities

Other current verified records you may want to review.

Job

Network Dev Engineer III - AMZ10515557

Amazon Data Services, Inc. - A19 · United States

MULTIPLE POSITIONS AVAILABLE Employer: AMAZON DATA SERVICES, INC. Offered Position: Network Dev Engineer III Job Location: Seattle, Washington Jo...

Job

Supply Chain Manager, Amazon Logistics Strategic Planning

Amazon.com Services LLC · United States

Join Amazon's North America Delivery (AMZL) organization as a Supply Chain Manager, where you will play a crucial role in shaping and optimizing...

Job

Area Manager

Amazon.com Services LLC · United States

Our Worldwide Operations network delivers millions of packages and smiles to Amazon customers every day. We are looking for motivated, customer-f...

Job

Systems Engineer - Controls Fleet, Data Center Capacity Delivery, Controls Fleet

Amazon Data Services, Inc. · United States

AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the people...

Job

Technical CSM III - AMZ10291258

Amazon Web Services, Inc. · United States

MULTIPLE POSITIONS AVAILABLE Employer: AMAZON WEB SERVICES, INC. Offered Position: Technical CSM III Job Location: Seattle, Washington Job Number...

Job

Global Account Manager, Media & Entertainment, Games and Sports

Amazon Web Services, Inc. · United States

AWS is seeking a world class sales professional to manage and grow our global business relationship with one of the largest entertainment and tec...

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books