Senior Cloud Security Engineer
COMPANY OVERVIEW: HealthMark Group is a leading provider of health IT solutions for healthcare providers across the country. By leveraging technology to reimagine the business of healthcare, HealthMark transforms administrative processes into seamless digital solutions. From HealthMark’ s proprietary MedRelease platform for Release of Information, the company is pioneering an efficient, compliant, and patient-centric approach to support the entire spectrum of the patient information journey. HealthMark Group was founded in 2006 with corporate headquarters in Dallas, TX, and has been named to both the Dallas 100 and the Inc. 5000 for multiple years in a row as one of the fastest-growing companies in the region and the country.
We are a mid‑sized company in a transformation phase: modernizing legacy systems, building new products, and automating workflows that used to require rooms full of people. If you want to build things that matter (not just maintain them), this is a good time to join.
Position: Senior Cloud Security Engineer
Location: Remote
Role Overview:
The senior cloud security engineer is responsible for designing, implementing, and maintaining security controls for HealthMark Group developed applications and corporate systems, with a focus on the AWS cloud environment, including the platforms supporting our medical imaging business. They define AWS security guardrails appropriate for a highly-regulated environment containing Protected Health Information (PHI) and which must adhere to security regulations and frameworks such as HIPAA, HITRUST, and SOC 2. They serve as a leader in the Security Operations team, providing mentorship and guidance to fellow security engineers.
Primary Roles and Responsibilities :
- Design and build enterprise-grade security controls utilizing native AWS services to safeguard PHI across all cloud environments.
- Design and maintain the secure multi-account AWS architecture — account structure, organizational units, guardrails, and baseline configuration — so that new accounts and workloads inherit required PHI protections by default.
- Author, review, and maintain secure-by-default Terraform or AWS CloudFormation templates, integrating policy-as-code tools (e.g., OPA, Checkov, Rego) to programmatically enforce HIPAA, HITRUST, and SOC 2 controls before deployment.
- Align and enforce strict data-at-rest and data-in-transit encryption strategies utilizing AWS KMS, ensuring cryptographic standards satisfy HITRUST and HIPAA mandates for PHI.
- Design and enforce strict least-privilege access models, complex IAM policies, Service Control Policies (SCPs), and AWS Organizations boundaries to strictly control access to sensitive healthcare workloads.
- Embed security testing, container scanning, and secrets management (AWS Secrets Manager) directly into CI/CD pipelines, creating automated evidence-collection workflows for continuous SOC 2 and HITRUST audit readiness.
- Collaborate with application development and cloud operations teams to triage, investigate, and remediate vulnerabilities and findings from application and cloud security tooling, such as SAST, DAST, and CSPM.
- Develop custom detection rules using AWS CloudTrail, Amazon CloudWatch telemetry, and enterprise SIEM tool to monitor system activities to detect and respond to threats and incidents.
- Serve as the senior escalation point for cloud security incidents, leading investigation and containment in AWS environment in partnership with our Managed Detection and Response provider, Cloud Operations team, and Managed Services Provider. Drive post-incident root cause analysis and control improvements.
- Support third-party risk assessment and security certification processes through evidence collection and response to security questionnaires.
- Evaluate and document cloud security exceptions and compensating controls, partnering with GRC to ensure risk acceptance decisions are appropriately assessed, approved, and t
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels →Get remote developer jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks — continue to the application ↗