Staff Security Engineer
Summary
Staff Security Engineer owning cloud-native and application security for a large-scale healthcare data platform, with deep focus on Kubernetes, container security, CI/CD hardening, and translating HITRUST/SOC 2 compliance into engineering controls.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Engineer based in the United States.
This is a high-impact, hands-on security engineering role focused on strengthening cloud-native and application security across a large-scale healthcare data platform. You will partner closely with engineering teams to embed security throughout the software development lifecycle and make secure practices the default. The role offers significant autonomy to shape security standards across Kubernetes, containers, infrastructure, CI/CD, and application architecture. You will translate complex vulnerabilities and compliance requirements into practical technical solutions that improve production security. As a senior individual contributor, your decisions will influence systems and engineering practices across the organization. You’ll join a small, experienced team operating with transparency, ownership, and a strong bias toward meaningful outcomes.
Accountabilities
- Own cloud security posture management, including Kubernetes and container security, admission controls, network policies, image integrity, and environment hardening.
- Manage the complete vulnerability lifecycle, prioritizing remediation according to real-world production exposure and business risk rather than relying solely on finding counts.
- Partner with Platform Engineering to establish secure SDLC and CI/CD practices, with particular focus on artifact integrity, pipeline security, and GitHub Actions safeguards.
- Translate HITRUST and SOC 2 requirements into practical technical configurations, security controls, and operational processes that integrate naturally into engineering workflows.
- Review and harden infrastructure-as-code across environments, including Terraform-based deployments and related cloud infrastructure.
- Lead incident response activities, including forensic investigations, remediation coordination, and blameless post-incident reviews.
- Strengthen engineering security standards through architecture and design reviews, collaborative technical pairing, mentorship, and security guidance.
- Oversee bug bounty triage and maintain constructive relationships with external security researchers.
- Identify and drive security initiatives from initial scope and design through implementation and operationalization, taking ownership of systems rather than focusing only on roadmap features.
- Evaluate emerging security challenges involving AI and agentic systems, and help establish appropriate safeguards as AI capabilities become increasingly integrated into engineering workflows.
- 8+ years of experience in security engineering, with demonstrated Staff-level impact through architecture, strategic initiatives, technical leadership, and mentorship.
- Deep expertise in Kubernetes security, including network policy orchestration, admission control technologies such as Kyverno, and container hardening.
- Strong experience with threat modeling applications built with technologies such as Node.js, TypeScript, Python, or Go.
- Proven ability to establish secure SDLC practices and CI/CD security controls using GitHub Actions, including artifact validation and pipeline integrity.
- Hands-on experience securing infrastructure-as-code, particularly Terraform, and managing enterprise secrets through AWS Secrets Manager, Vault, or comparable platforms.
- End-to-end experience managing vulnerability programs, from initial triage and risk assessment through production remediation and verification.
- Ability to operationalize compliance frameworks such as HITRUST and SOC 2 into pragmatic, engineering-friendly technical controls.
- Excellent written and verbal communication skills, with the ability to influence technical roadmaps and communicate effectively in a remote, asynchronous environment.
- Proficiency with AI tools and techniques, including prompt engineering, multiple large language model platforms, and AI-powered workflow automation.
- Hands-on familiarity with AWS, Docker, EKS, CrowdStrike, Jamf, Okta, GuardDuty, Sumo Logic, Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane, GitHub Actions, Terraform, Helm, ArgoCD, Atlantis, PostgreSQL, Redis, and Kafka is valuable.
- Experience securing autonomous agentic systems, tool-calling frameworks, indirect prompt injection risks, or human-in-the-loop controls is a strong advantage.
- Knowledge of Model Context Protocol security, including context isolation, sandboxing, and identity propagation between LLMs and private data sources, is a plus.
- Familiarity with the NIST AI Risk Management Framework, OWASP Top 10 for LLMs, VPN administration, enterprise network security, or dependency management tools such as Renovate and Dependabot is beneficial.
- Strong TypeScript, Go, or Node.js experience is advantageous.
- Must be eligible to work in the United States and reside and work in the continental U.S.
- Fully remote work within the continental United States.
- Opportunity to work on security infrastructure supporting large-scale healthcare data exchange.
- High degree of autonomy and ownership within a small, senior security team.
- Opportunity to influence engineering architecture, security standards, and technical roadmaps.
- Collaborative, transparent, and asynchronous working environment.
- Exposure to modern cloud-native technologies, Kubernetes, infrastructure automation, and emerging AI security challenges.
- Mission-driven environment focused on protecting sensitive healthcare data and enabling secure technology innovation.
- Commitment to diversity, inclusion, and an open engineering culture.
Requirements
Benefits
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company