Lead Engineer - Security
Key Responsibilities
Client Delivery & Consulting Advisory
-
Lead security discovery workshops with client stakeholders to map out security requirements across all existing and upcoming system interfaces.
-
Translate high-level architectural requirements into actionable security user stories, tasks, and implementation roadmaps for our internal and offshore engineering teams.
-
Evaluate technical tradeoffs between native cloud tools and agnostic platforms to ensure data portability and architectural durability for our clients.
Security Architecture & Documentation
-
Design and document end-to-end cloud security frameworks tailored to client environments.
-
Document existing client controls and packages to put their organization on a clear path toward SOC 2 and HITRUST compliance.
Governance & AI Strategy
-
Establish early-stage governance, security processes, and compliance tracking specifically tailored to Artificial Intelligence.
-
Define long-term maintenance, security guidelines, and architecture health policies for deploying multiple automated agent groups.
Vulnerability, Code Engineering & Risk Management
-
Establish policies for regular code scanning and automated code review workflows using third-party tools.
-
Prioritize and coordinate remediation plans alongside core client development teams.
-
Oversee security preparation for critical next-phase applications, specifically around physician-patient interaction portals.
Success Metrics
-
Delivery Velocity & Technical Enablement: Provision of complete, highly actionable technical work packages and user stories to development teams, ensuring high utilization and smooth project execution.
-
Audit Readiness & Client Trust: Timely and comprehensive compilation of control documentation, resulting in clear paths to SOC 2 and HITRUST validation for our clients.
-
Risk Mitigation: Proactive minimization of security flaws across interfaces through clear architecture reviews and scanning gates.
-
Reusable IP Creation: Successful delivery of repeatable governance policies for agent workflows that can be leveraged across future managed services engagements.
-
Experience: 6 - 12 years of progressive experience across cybersecurity, security engineering, or security architecture domains.
-
Domain Expertise: Proven understanding of cloud-focused API security, identity access management, network security, and data protection.
-
Tools & Operations: Strong experience with vulnerability scanning platforms, code verification tools, and tracking development remediation.
-
Communication: Exceptional written communication skills with explicit experience converting complex cloud landscapes into clean compliance documentation.
-
Healthcare Industry Context: Strong domain experience in Healthcare Technology, HIPAA requirements, or patient/provider data security environments is highly desired.
-
Compliance Frameworks: Active experience preparing technical architectures for SOC 2 and HITRUST audit frameworks.
-
Cloud Architecture: Deep familiarity with cloud ecosystems (specifically Google Cloud Platform / GCP), cloud-native security mechanics, and API integration models.
-
Advanced Certifications: Professional security accreditations (e.g., CISSP, CCSP, or cloud-specific security certifications).
At Ollion , success is built on these core strengths, which guide how we work and grow together:
-
Accountability - Demonstrates ownership and responsibility for actions, decisions, and outcomes.
-
Adaptability: Being adaptable to evolving business needs, unplanned challenges, and embodying a collaborative βall hands on-deckβ mentality when necessary.
-
Ambition - Exhibits drive, initiative, and a commitment to personal and professional growth.
-
Business Acumen - Understands complex business concepts, challenges, and opportunities, applying insights to make informed decisions and support organizational goals.
-
Detail-Oriented - Pays meticulo