Redoxengine
Redoxengine

Staff Security Engineer

engineeringfull-timeRemote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
healthcare
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.

Job Responsibilities:

  • Own Cloud Security Posture Management including Kubernetes and Container security strategies, admission control, network policies, image integrity, and environment hardening.

  • Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.

  • Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.

  • Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.

  • Evaluate and secure infrastructure-as-code across all environments.

  • Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.

  • Elevate security standards within Engineering through rigorous design reviews, collaborative pairing, and technical mentorship.

  • Oversee bug bounty triage and maintain professional engagement with external security researchers.

Required Skills & Experience:

  • 8+ years in security engineering with a track record of Staff-level impact through system architecture, leadership of strategic initiatives, and technical mentorship.

  • Deep technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.

  • Expertise in threat modeling for Applications built using Node.js, TypeScript, Python or Go.

  • Proven track record institutionalizing secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.

  • Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.

  • End-to-end accountability for vulnerability management lifecycles, encompassing everything from initial triage to final production remediation.

  • Ability to operationalize compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.

  • Exceptional written communication skills with the ability to influence technical roadmaps within a remote, asynchronous organizational culture.

  • Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.

Our stack - you'll be hands-on with these:

  • AWS, Docker, EKS

  • Crowdstrike, Jamf, Okta, GuardDuty, Sumologic

  • Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane

  • Github Actions, Terraform, Helm, ArgoCD and Atlantis

  • Postgres, Redis, Kafka

Nice to have in your background:

  • Experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.

  • Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.

  • Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.

  • Go, Node.js, or TypeScript - we're a TypeScript shop and it helps to be comfortable there

  • VPN administration or enterprise network security experience

  • Dependency management tooling (Renovate, Dependabot)

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Staff Security Engineer at Redoxengine — Remote