Med-Metrix logo
Med-MetrixPosted 3 weeks ago

Senior Cloud Security Engineer

$150,000–$200,000 year

RemoteUnited States

Full TimeSenior LevelHigh School Or EquivalentLarge

Job Summary

Design and implement secure cloud architecture across AWS and Azure, including identity, network security, encryption, and key management. Build Infrastructure-as-Code, Policy-as-Code, and automated compliance controls while integrating security throughout the DevSecOps lifecycle. Implement Cloud Security Posture Management, Cloud Workload Protection, and CNAPP capabilities to enhance visibility and incident response. Lead technical response to cloud and AI security incidents, including forensic analysis and remediation. Design and secure AI/ML environments, including MLOps pipelines, model security, inference endpoints, and AI governance. Partner with engineering and data science teams to implement secure-by-design controls for regulated data. Mentor junior engineers and champion security best practices across engineering teams. Support technical readiness, evidence collection, and remediation activities for security audits and compliance assessments supporting HIPAA, HITRUST, PCI DSS, SOC 2, and NIST frameworks. Use, protect, and disclose patients' protected health information only in accordance with HIPAA standards.

Required Qualifications

  • High school diploma or equivalent
  • 6+ years of experience in information security
  • 4 years focused on cloud security engineering
  • Deep hands-on expertise in both AWS and Microsoft Azure
  • Native security services including AWS GuardDuty, Security Hub, IAM Identity Center
  • Native security services including Microsoft Defender for Cloud, Sentinel, Entra ID
  • Strong knowledge of IAM
  • Strong knowledge of zero trust architecture
  • Strong knowledge of network security
  • Strong knowledge of encryption
  • Strong knowledge of secrets management
  • Practical experience securing AI/ML systems or LLM-based applications
  • Demonstrable working knowledge of AI security frameworks including OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF
  • Proficiency in at least one scripting/programming language
  • Infrastructure-as-code tooling
  • Experience with container and orchestration security
  • Docker
  • Kubernetes
  • EKS/AKS
  • Solid understanding of DevSecOps practices
  • CI/CD security integration
  • Hands-on experience supporting compliance programs such as HIPAA, HITRUST CSF, PCI DSS, and SOC 2
  • Audit evidence and control implementation
  • Proficiency in Microsoft Office Suite
  • Excellent written and verbal communication skills
  • Strong problem solving and creative skills
  • Ability to exercise sound judgment and make decisions based on accurate and timely analyses
  • High level of integrity and dependability
  • Strong sense of urgency
  • Results oriented
  • Must possess a smart-phone or electronic device capable of downloading applications
  • Use, protect and disclose patients' protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards
  • Understand and comply with Information Security and HIPAA policies and procedures at all times
  • Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties
  • Travel may be required for training, conferences, etc.

Desired Qualifications

  • Experience with Google Cloud Platform (GCP)
  • Experience deploying or securing MLOps platforms including SageMaker, Vertex AI, Azure ML, Databricks, Kubeflow
  • Familiarity with AI-driven security platforms and building custom detections using ML techniques
  • Relevant certifications such as CISSP, CCSP, HCISPP, CCSFP (HITRUST), AWS Security Specialty, Azure Security Engineer (AZ-500), GCP Professional Cloud Security Engineer, or GIAC certifications
  • Prior experience in healthcare, health tech, or revenue cycle management environments handling PHI at scale
  • Experience with red teaming or adversarial testing of AI systems
  • Knowledge of data privacy regulations as they apply to AI training data and model outputs, particularly de-identification standards under HIPAA (Safe Harbor and Expert Determination)
  • Contributions to security communities, open-source tooling, or published research
  • Python preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce