Senior Security Engineer
Redox is on a mission to accelerate healthcareβs transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.
Opportunity & Impact
We are seeking a Senior Security Engineer to take ownership of cloud-native and application security across the Redox platform. This is a high-impact, hands-on IC role where you will move beyond identifying risks to actively hardening our environment, performing code reviews, and translating complex control gaps into engineering proposals that drive production impact.
You will function as a partner to our Engineering teams, embedding security into the SDLC through hands-on work across container security, Kubernetes hardening, and architecture reviews. You'll follow and reinforce our established security standards, helping make the secure path the easy path for the engineers you work with day to day.
As part of a small, senior security team, your day to day work will directly strengthen how we protect data for our customers, with impact concentrated in the systems and teams you own.
We're a fully remote team within the U.S. that operates with radical transparency and a strong bias toward ownership.
Our Engineering Culture & How We Work
Transparency, Ownership & Autonomy
We make room for everyone to be heard, regardless of level. We work openly, normalize not knowing things, and treat "learning out loud" as a feature, not a liability. You'll be expected to bring your real perspective, push back when you see something wrong, and commit fully once a decision is made. As a Senior Engineer, you help cultivate our culture: you model the behavior, you embrace questions, you acknowledge mistakes.
We default to public Slack channels over DMs, post Zoom summaries back in writing, and work async whenever possible. We'd rather expose incomplete thinking in public to get better feedback than protect it in private. That applies to security work too, when you identify a risk or propose a control, you bring it to the table with a recommendation, not just a concern.
We own the systems we maintain, not just the new features on the roadmap. You'll have room to identify platform security work, propose scope, consult on priority, and see it through from design to operationalization. We measure ourselves by the value we deliver, not the process we follow.
Job Responsibilities:
-
Own Cloud Security Posture Management including Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening.
-
Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.
-
Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
-
Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
-
Evaluate and secure infrastructure-as-code across all environments.
-
Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.
-
Contribute to security standards within Engineering through design reviews, collaborative pairing, and mentorship of peers.
-
Support bug bounty triage and maintain professional engagement with external security researchers.
Required Skills & Experience:
-
5+ years in security engineering with a track record of hands-on delivery across system hardening, security engineering projects, and peer mentorship.
-
Strong technical proficiency in Kubernetes security, specific
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels βGet remote developer jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks β continue to the application β