Cybersecurity Engineer – AWS & Healthcare Compliance
AdaptX is searching for a Cybersecurity Engineer to join our team. This person will have 3–5 years of
experience securing cloud infrastructure in AWS, ideally within a healthcare or highly regulated
environment. The ideal candidate combines hands-on technical security engineering skills with a strong
understanding of SOC 2 compliance frameworks and healthcare data protection requirements
(HIPAA/HITRUST). This person will play a key role in protecting patient data, maintaining audit readiness,
and hardening our cloud environment against evolving threats. They will thrive in a fast-paced, startup
environment.
Key Responsibilities:
- Design, implement, and maintain security controls across AWS infrastructure (IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, WAF, etc.)
- Monitor cloud environments for security events, misconfigurations, and anomalous activity; respond to and remediate incidents
- Support and maintain SOC 2 Type II compliance efforts, including control mapping, evidence collection, and audit coordination
- Ensure infrastructure and application security practices align with HIPAA and other healthcare regulatory requirements
- Conduct vulnerability assessments, penetration test coordination, and remediation tracking
- Implement and manage security automation (Infrastructure as Code security scanning, CI/CD pipeline security gates)
- Perform risk assessments on new AWS services, third-party integrations, and vendor relationships (especially those touching PHI)
- Develop and maintain security policies, procedures, and incident response playbooks
- Collaborate with engineering, DevOps, and compliance teams to embed security into the SDLC
- Support internal and external audits (SOC 2, HITRUST, HIPAA risk assessments)
- Manage secrets, encryption key lifecycle, and access control reviews
- Stay current on emerging threats, AWS security services, and regulatory changes affecting healthcare data