Staff Security Engineer
Summary
Staff Security Engineer securing Redox's healthcare interoperability platform that processes over 1.2 billion messages monthly across 12,000+ healthcare systems and 100+ EHRs.
Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.
Job Responsibilities: Own Cloud Security Posture Management including Kubernetes and Container security strategies, admission control, network policies, image integrity, and environment hardening.
Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.
Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
Evaluate and secure infrastructure-as-code across all environments.
Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.
Elevate security standards within Engineering through rigorous design reviews, collaborative pairing, and technical mentorship.
Oversee bug bounty triage and maintain professional engagement with external security researchers.
Required Skills & Experience: 8+ years in security engineering with a track record of Staff-level impact through system architecture, leadership of strategic initiatives, and technical mentorship.
Deep technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.
Expertise in threat modeling for Applications built using Node.js, TypeScript, Python or Go.
Proven track record institutionalizing secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.
Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.
End-to-end accountability for vulnerability management lifecycles, encompassing everything from initial triage to final production remediation.
Ability to operationalize compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.
Exceptional written communication skills with the ability to influence technical roadmaps within a remote, asynchronous organizational culture.
Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.
Our stack - you'll be hands-on with these: AWS, Docker, EKS
Crowdstrike, Jamf, Okta, GuardDuty, Sumologic
Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane
Github Actions, Terraform, Helm, ArgoCD and Atlantis
Postgres, Redis, Kafka
Nice to have in your background: Experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.
Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.
Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.
Go, Node.js, or TypeScript - we're a TypeScript shop and it helps to be comfortable there
VPN administration or enterprise network security experience
Dependency management tooling (Renovate, Dependabot)
About Redox - Take a look here: What We Do Healthcare organizations and technology vendors connect to Redox once, then authorize what data they send to and receive from partners through a centralized hub. Redox's cloud-based platform is vendor and standards-agnostic and enables the secure and efficient exchange of healthcare data. This approach eradicates the need for point-to-point integrations and accelerates the discovery, adoption, and distribution of patient and provider-facing technology solutions. With hundreds of healthcare organizations and technology vendors exchanging data today, Redox represents the largest interoperable network in healthcare. Learn how you can leverage the Redox platform at . Other Stuff About Us Redox is an EEO company. We fully support the diversity of our team. As part of our ongoing work to build more diverse teams at Redox, you will be asked to complete a voluntary EEO survey when applying. This survey is anonymous, we cannot link your application record with your survey responses. We request that you complete this voluntary survey as we run monthly reports for each team which provides data for diversity in terms of gender and ethnic background in our Applicants and our Hired Redoxers. We take this data very seriously and appreciate your willingness and time to complete this step in the process. Successful candidates must be eligible to be employed in the U.S. and must reside & work in the continental U.S. Thank you for your interest in Redox! #LI-TA1