Senior Security Engineer
RemoteUnited States or Canada
Job Summary
Own AxisCare Engineering's security program as an individual contributor, continuously improving standards and strengthening systems to close gaps with engineers. Manage engineering's share of SOC 2 Type II compliance, including control design, evidence collection, audit prep, and gap remediation, while charting the path toward HITRUST certification. Threat-model the PHP/React modular monolith on AWS, raising the bar on IAM policies, VPC design, secrets management, and container security. Tune security scanning programs to cut false positives and ensure findings drive developer action. Assess and mitigate risks inherent in AI products, including prompt injection and data leakage, by setting guardrails for AI-assisted development workflows. Strengthen detection and response capabilities through logging, alerting, and incident response playbooks, while coordinating penetration tests and tracking remediation. Keep security policies clear and current, training developers on secure practices without burying them in process.
Required Qualifications
- 5+ years in application security, infrastructure security, or security engineering at a SaaS company
- Hands-on experience with AWS security (IAM, VPC, Security Groups, KMS, CloudTrail, GuardDuty)
- Experience owning or heavily contributing to the engineering side of SOC 2 Type II compliance
- Familiarity with container security (Docker, Kubernetes) and infrastructure-as-code (Terraform)
- Solid grasp of web application security fundamentals (OWASP Top 10, secure SDLC)
- Experience securing AI/ML systems or LLM-powered products
- Concrete examples of how you've used AI to improve your own security work: automating compliance tasks, speeding up threat analysis, building detection rules faster, or something we haven't thought of
- Able to work remotely from the Eastern, Central, or Mountain time zones
- Qualified to work in the United States or Canada
Desired Qualifications
- Experience building or maintaining HIPAA-compliant or HITRUST-certified environments
- CISSP, OSCP, or AWS Security Specialty certification
- Background in penetration testing or red team work
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.