Senior Security Engineer
New
R
RedoxHealth Tech
We're a fully remote team within the U.S.Full-TimeSenior
Salary$165,000 - $190,000 a year
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- AWSNode.jsPythonKubernetesTypeScriptGoTerraformGitHub Actions
Requirements
- 5+ years in security engineering with a track record of hands-on delivery across system hardening, security engineering projects, and peer mentorship.
- Strong technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.
- Experience with threat modeling for applications built using Node.js, TypeScript, Python or Go.
- Hands-on experience supporting secure SDLC practices and CI/CD safeguards using GitHub Actions.
- Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.
- Solid experience across the vulnerability management lifecycle.
- Ability to apply compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls.
- Strong written communication skills for documentation and collaboration in a remote, asynchronous culture.
- Proficiency in AI tools and techniques, including prompt engineering and automating workflows using AI.
Responsibilities
- Own Cloud Security Posture Management including Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening.
- Manage comprehensive vulnerability lifecycles, prioritizing remediation based on production exposure.
- Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
- Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
- Evaluate and secure infrastructure-as-code across all environments.
- Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.
- Contribute to security standards within Engineering through design reviews, collaborative pairing, and mentorship of peers.
- Support bug bounty triage and maintain professional engagement with external security researchers.
View Full Description & ApplyYou'll be redirected to the employer's site