House Rx logo
House RxPosted 3 weeks ago

Senior Security Software Engineer

$160,000–$190,000 year

Remote

Part TimeSenior LevelSmallHealthcare Tech

Job Summary

Build and harden internal security-sensitive tooling alongside engineering and operations teams. Dig deeply into engineers' code to review security-sensitive pull requests, especially for systems touching PHI. Design and enforce security gates and guardrails across the SDLC, including automated CI/CD checks, pre-merge review requirements, and policy-as-code. Support application security reviews across platform and internal tooling while reviewing security-relevant Terraform, cloud, firewall, and clinic connectivity changes. Improve visibility into security posture across AWS, GCP, clinic networks, and internal applications. Help prepare engineering teams for HITRUST and customer security expectations. This role sits within Security & IT to support secure code review, production hardening, and cloud/network security coverage as we scale AI-assisted development and clinic connectivity.

Required Qualifications

  • At least 6+ years of software engineering experience implementing and maintaining security-relevant systems in production, including reviewing and raising the bar on other engineers' code
  • Strong programming skills in Python or at least one systems language
  • Experience contributing to cloud security controls
  • Strong understanding of web application security and secure SDLC practices
  • Familiarity with AWS and/or GCP
  • Experience with Terraform or infrastructure-as-code
  • A track record of reviewing PRs and giving clear, practical, and influential security feedback that other engineers act on
  • Working knowledge of authentication, authorization, logging, secrets management, and data protection
  • Strong judgment around sensitive data, especially in healthcare or regulated environments

Desired Qualifications

  • Passion for AI safety and the role security engineering plays in building trustworthy AI systems
  • Healthcare, HIPAA, HITRUST, or SOC 2 experience
  • Experience securing AI-assisted development workflows
  • Experience with Python, TypeScript, Node.js, or similar stacks
  • Experience with Auth0, Okta, Kubernetes, EKS, RDS, or private cloud networking
  • Experience with SAST, SCA, secret scanning, IaC scanning, or software supply chain security

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce