SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Oshi Health is seeking a Senior Security Engineer to build and own the technical security program for a fully remote, SaaS- and cloud-native healthcare platform focused on GI care. As the company's first dedicated security engineer, you will report to the Sr. Director of Security & IT and serve as a hands-on builder rather than a policy administrator.
Key responsibilities include:
**Application & Product Security**: Own threat modeling, secure design reviews, and secure code reviews with focus on authorization and access-control vulnerabilities (IDOR, broken access control, exposed secrets, insecure upload) critical for a member-facing healthcare app and its APIs.
**Security Tooling & CI/CD**: Enforce and tune GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks, with branch protection and CODEOWNERS-enforced human review on security-sensitive code paths.
**Agentic SDLC Architecture**: Design security controls for Oshi's transition to an AI-native software development lifecycle. Define phase-gate criteria for each stage of AI integration, implement deterministic out-of-band controls so agent-written code is never its own security gate, and establish tested "clawback" procedures for risk mitigation.
**Non-Human Identity & Secrets Management**: Build and operate service accounts, scoped tokens, OAuth grants, and machine credentials at scale—covering provisioning, rotation, least-privilege enforcement, and decommissioning across SaaS and AWS infrastructure.
**AWS Security**: Secure the AWS environment including IAM/IC, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS, and Terraform in coordination with DevOps.
**Vendor & AI Integration Security**: Conduct security reviews of AI and third-party vendor integrations before they access PHI, evaluating data flows, retention policies, and data-loss-prevention requirements.
**Detection & Response**: Stand up and tune detection and response capabilities, leveraging AI to build behavioral baselines and anomaly detection for identity, SaaS, AWS, and AI/agent usage logs.
**Compliance**: Support HIPAA Security Rule technical safeguards including encryption at rest, audit controls, activity logging, vulnerability scanning, and asset inventory in partnership with the Sr. Director.
This role is uniquely forward-looking, offering the opportunity to build security foundations from scratch in a fast-paced, AI-native environment where security enables speed safely rather than slowing development out of fear.