Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Information Security Engineer based in the Uni
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Information Security Engineer based in the United States. This is a senior, hands-on security engineering role focused on protecting cloud-based healthcare SaaS platforms, AI/ML environments, infrastructure, and sensitive customer data. You will design and implement enterprise-grade security controls across cloud, application, identity, endpoint, and AI environments. The role has a particularly strong focus on securing AI and large language model workflows that process protected health information and personally identifiable information. You will collaborate closely with engineering, data science, compliance, legal, and operations teams to embed security throughout the technology lifecycle. The position combines architecture, threat modeling, security automation, incident response, DevSecOps, and regulatory compliance. You will also help shape emerging AI security practices while strengthening defenses against evolving cyber threats. This is an ideal opportunity for a technically strong security professional who enjoys solving complex problems in a highly regulated healthcare technology environment.
Design, implement, and maintain secure architectures across AWS, Azure, and GCP, including infrastructure-as-code and policy-as-code security controls. Deploy and manage cloud security capabilities such as Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls. Operate CSPM/CNAPP platforms to identify cloud misconfigurations, exposed data stores, toxic combinations, and other security risks. Secure containerized and serverless environments, including EKS, ECS, Lambda, image scanning, admission controls, runtime protection, and least-privilege access. Establish strong network segmentation, encryption, centralized key management, secrets management, and secure workload configurations. Partner with AI and data teams to secure model development, training, fine-tuning, inference, and retrieval-augmented generation pipelines handling sensitive data. Apply AI security frameworks and threat-modeling practices to address prompt injection, data poisoning, model exfiltration, insecure outputs, excessive agency, and other AI-specific threats. Implement AI gateways, guardrails, content filtering, validation, rate limiting, and logging controls while supporting responsible enterprise use of generative AI. Evaluate third-party and foundation-model providers, including security controls, data residency, retention, contractual protections, and appropriate coverage for sensitive healthcare data. Secure the machine-learning supply chain through artifact provenance, signed models, dependency scanning, and hardened MLOps environments. Embed security into CI/CD pipelines through SAST, DAST, SCA, secrets scanning, infrastructure-as-code scanning, threat modeling, and secure design reviews. Protect APIs and machine-to-machine integrations using secure authorization standards such as OAuth 2.0, OIDC, mTLS, and scoped service tokens. Manage software supply-chain security, including SBOMs, dependency governance, artifact signing, penetration testing, vulnerability remediation, and bug-bounty processes. Strengthen PHI and PII protection through data classification, tokenization, de-identification, DLP, and appropriate access controls. Manage endpoint and identity security using EDR/XDR, Microsoft Entra ID, Conditional Access, privileged identity management, phishing-resistant MFA, and risk-based authentication. Govern service accounts, workload identities, service principals, AI agent credentials, and other non-human identities through least privilege and short-lived credentials. Monitor and investigate security alerts, coordinate incident response, and work with SOC and managed detection and response partners. Develop SIEM detection content, detection-as-code, log coverage, MITRE ATT&CK mappings, SOAR workflows, and automated response capabilities using Python and PowerShell. Develop incident response runbooks and forensic procedures covering both conventional cyber incidents and AI-specific scenarios such as model misuse, prompt-based data leakage, and compromised AI integrations. Participate in tabletop exercises, purple-team activities, post-incident reviews, and continuous security improvement initiatives. Support HIPAA, HITRUST, SOC 2 Type 2, and NIST-related audits, customer security assessments, evidence collection, risk registers, asset inventories, and remediation tracking. Conduct third-party and vendor risk reviews, with particular attention to AI subprocessors, sensitive-data flows, and emerging technology risks. Partner with compliance and other stakeholders to maintain alignment between technical controls, security policies, regulatory requirements, and responsible AI practices. Contribute to security awareness and training initiatives, including guidance on secure and responsible AI use. Requirements Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience. 5+ years of experience in security engineering or comparable technical security roles. Strong knowledge of cloud-native security across AWS, Azure, and GCP, along with modern SaaS architectures. Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, security automation, and incident response technologies. Practical experience securing containerized and serverless workloads such as EKS and Lambda. Familiarity with healthcare and security frameworks including HIPAA, HITRUST, NIST, and SOC 2. Experience with infrastructure-as-code security using technologies such as Terraform, Ansible, or CloudFormation is preferred. Experience integrating security into DevSecOps environments and CI/CD pipelines, including tools such as Jenkins or Bitbucket, is preferred. Strong scripting capabilities in Python, PowerShell, Bash, or similar languages. Experience with AI/LLM security, AI threat modeling, ML security, or securing AI-enabled applications is highly valuable. Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, GSEC, GCIA, or GCIH are preferred. Strong analytical, troubleshooting, and problem-solving capabilities with exceptional attention to detail. Ability to balance business objectives with appropriate risk mitigation and practical security controls. Excellent written and verbal communication skills, including the ability to explain complex technical and security concepts to non-technical stakeholders. Collaborative and proactive approach, with a demonstrated commitment to continuous improvement. Ability to operate effectively in a regulated healthcare technology environment and manage sensitive information responsibly. Benefits Annual salary range of $140,000–$160,000 , with compensation varying according to geographic market, job-related knowledge, skills, and experience. Remote work opportunity within the United States. Medical, dental, and vision insurance benefits. 401(k) matching. Generous paid time off program. Opportunity to work on advanced cloud, cybersecurity, healthcare, and AI security challenges. Environment focused on continuous professional and technical development. Equal opportunity workplace committed to an inclusive and respectful work environment.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from jobgether (lever) →